【问题标题】:Varnish Cache with PHP Captcha for Anti-Site-Scraping AlgorithmVarnish Cache 与 PHP Captcha 用于反站点抓取算法
【发布时间】:2011-04-28 08:53:20
【问题描述】:

我有 Varnish 缓存与 PHP Captcha 一起使用,但我没有
了解我如何设置触发限制。

在每小时(或每分钟)如此多的请求限制之后
验证码输入已发送。

我可以正常工作,但想了解如何更改请求/秒限制。

代码来自:
http://drcarter.info/2010/04/how-fighting-against-scraping-using-varnish-vcl-inline-c-memcached/

这段代码对我说了什么?

if (rc == MEMCACHED_SUCCESS) {
uint64_t intval;
rc= memcached_increment(memc, key, strlen(key), (uint64_t)1, &intval);

if (rc != MEMCACHED_SUCCESS)
  rc= memcached_set(memc, key, strlen(key), "1", 1, (time_t)60, (uint32_t)0);
else
  if (intval>30) {
    VRT_SetHdr(sp, HDR_REQ, "\013X-Scraping:", "1", vrt_magic_string_end);
    syslog(LOG_INFO, "Scraping detected from %s",VRT_IP_string(sp, VRT_r_client_ip(sp)));
    if (intval<300)
      rc= memcached_set(memc, key, strlen(key), "500", 3, (time_t)3600, (uint32_t)0);
  }

您的建议将不胜感激。

谢谢!

【问题讨论】:

    标签: php caching captcha varnish


    【解决方案1】:

    请原谅我没有评论我的代码:)

    所以有了评论,我想你会明白的。

    if (rc == MEMCACHED_SUCCESS) {
    //if connected to memcache
    uint64_t intval;
    //trying to increment the "ip address" key (+1)
    rc= memcached_increment(memc, key, strlen(key), (uint64_t)1, &intval);
    
    if (rc != MEMCACHED_SUCCESS)
      //if increment fail, then it is the first time that we see this address
      //init the value at 1 for 60 seconds
      rc= memcached_set(memc, key, strlen(key), "1", 1, (time_t)60, (uint32_t)0);
    else
      //if increment success, then verifying the value, if more than 30 (30 reqs/minute)
      //blacklist the ipaddress (setting the value arbitrary at 500 for 1 hour)
      if (intval>30) {
        VRT_SetHdr(sp, HDR_REQ, "\013X-Scraping:", "1", vrt_magic_string_end);
        syslog(LOG_INFO, "Scraping detected from %s",VRT_IP_string(sp, VRT_r_client_ip(sp)));
        if (intval<300)
          rc= memcached_set(memc, key, strlen(key), "500", 3, (time_t)3600, (uint32_t)0);
      }
    

    【讨论】:

      【解决方案2】:

      代码适用于这个流程:

      try to increment the key identifying the client and return the value in intval
      if it fails set the key with an expiration of 60 seconds
      else
        if the number of call (intval) is less than 30
          it set an header X-Scraping (which will be use later to deny access: this part is not in the part of the code you have pasted)
      

      因此,如果您想更改 res/s,您可以进行 > 30 测试或将密钥到期更改为 60 以外的其他值。

      【讨论】:

        猜你喜欢
        • 2011-12-17
        • 1970-01-01
        • 2011-11-05
        • 1970-01-01
        • 2019-08-27
        • 1970-01-01
        • 2015-02-09
        • 1970-01-01
        相关资源
        最近更新 更多