XF 2.3 60,000 requests a day on new forum

josh_b_and_b

New member
I setup a new forum, and getting over 60,000 requests per day. The first day was 300,000 requests.

They're all going to this path:
/misc/style-variation

Anyone ever seen spam like this before with XenForo?


1727890284027.webp
 
Last edited:
100% ddos attack!
they use fake google, bing, facebook, amazon, alibaba cloud system. if your site is online, just leave it as it is. it will help to index faster
 
View attachment 312618


i am seeing this exact thing now.

LOG: https://ragezone.com/bytespider.txt

Code:
111.225.148.66 - - [17/Oct/2024:14:55:44 +0100] "GET /misc/style-variation?t=1728939665%2C6b1ac370e7c1480f7fcb3ef58722c011&variation=default HTTP/1.1" 303 0 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)"
111.225.148.47 - - [17/Oct/2024:14:55:44 +0100] "GET /misc/style-variation?t=1728941227%2C8ed6d7ac5a46100e036b391578ad8c94&variation=default HTTP/1.1" 303 0 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)"
110.249.202.79 - - [17/Oct/2024:14:55:46 +0100] "GET /misc/style-variation?t=1728962928%2Cf7dbd729c0b87a2935f5ab9ac4c7394f&variation=alternate HTTP/1.1" 303 0 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)"
110.249.202.56 - - [17/Oct/2024:14:55:46 +0100] "GET /misc/style-variation?t=1728936434%2C3e60b0a43fe388dc4bd9045318fbbb56&variation=alternate HTTP/1.1" 303 0 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)"
110.249.202.100 - - [17/Oct/2024:14:55:47 +0100] "GET /misc/style-variation?t=1728957042%2Ca4e85bd07246266c8eb8375312b3c9a9&variation=alternate HTTP/1.1" 303 0 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)"
110.249.202.45 - - [17/Oct/2024:14:55:50 +0100] "GET /misc/style-variation?t=1729009691%2Cd1fb89a9aa7d8dd9da908c4d4937c548&variation=default HTTP/1.1" 303 0 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)"
110.249.202.156 - - [17/Oct/2024:14:55:51 +0100] "GET /misc/style-variation?t=1728970157%2Ce88d5150f98a4744408e7fa557f2bad0&variation=default HTTP/1.1" 303 0 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)"
110.249.202.141 - - [17/Oct/2024:14:55:52 +0100] "GET /misc/style-variation?t=1728960834%2C6bf8d8377d42744af04a990a37cb8021&variation=alternate HTTP/1.1" 303 0 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)"
111.225.148.58 - - [17/Oct/2024:14:55:50 +0100] "GET /misc/style-variation?t=1728987133%2C3c6eca697c7bba28b6044fb4275b409c&variation=default HTTP/1.1" 303 0 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)"
110.249.201.43 - - [17/Oct/2024:14:55:53 +0100] "GET /misc/style-variation?t=1728984551%2C692bef8d6839f18c0c5541a4cc693c32&variation=alternate HTTP/1.1" 303 0 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)"
111.225.149.115 - - [17/Oct/2024:14:55:53 +0100] "GET /misc/style-variation?t=1728994893%2Cf08df2f2342ec22560ba11f7ca5ac03c&variation=default HTTP/1.1" 303 0 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)"
111.225.149.48 - - [17/Oct/2024:14:55:56 +0100] "GET /misc/style-variation?t=1728979049%2Ca3bcbdb2008f7773efea958eef87f419&variation=alternate HTTP/1.1" 303 0 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)"
110.249.201.120 - - [17/Oct/2024:14:55:56 +0100] "GET /misc/style-variation?t=1728967898%2C7cb6eb9d6f1d8d3b277934786150d554&variation=alternate HTTP/1.1" 303 0 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)"
111.225.148.73 - - [17/Oct/2024:14:55:57 +0100] "GET /misc/style-variation?t=1729008581%2Cb5c2357a2ec08e3b1a3f686232396ece&variation=default HTTP/1.1" 303 0 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)"
111.225.149.54 - - [17/Oct/2024:14:55:57 +0100] "GET /misc/style-variation?t=1728929777%2Cd390088c36271a16bb0f0b535c2b0be4&variation=default HTTP/1.1" 303 0 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)"
110.249.202.61 - - [17/Oct/2024:14:55:59 +0100] "GET /misc/style-variation?t=1728934659%2Cd50f326ebb74ef85c32db8223db46d78&variation=alternate HTTP/1.1" 303 0 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)"
111.225.149.68 - - [17/Oct/2024:14:55:59 +0100] "GET /misc/style-variation?t=1728994819%2Cbb7b92bc402d0bddbaa2c1eceb28dff3&variation=default HTTP/1.1" 303 0 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)"
111.225.148.60 - - [17/Oct/2024:14:56:00 +0100] "GET /misc/style-variation?t=1728952603%2Cf9ef9f56050cd73f48051ee2e5f9fdb8&variation=default HTTP/1.1" 303 0 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)"
111.225.149.143 - - [17/Oct/2024:14:56:00 +0100] "GET /misc/style-variation?t=1728965761%2C5df0a7adbb8c0ec086e10533cab92d85&variation=default HTTP/1.1" 303 0 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)"
 
Last edited:
View attachment 312618


i am seeing this exact thing now.

LOG: https://ragezone.com/bytespider.txt

Code:
111.225.148.66 - - [17/Oct/2024:14:55:44 +0100] "GET /misc/style-variation?t=1728939665%2C6b1ac370e7c1480f7fcb3ef58722c011&variation=default HTTP/1.1" 303 0 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)"
111.225.148.47 - - [17/Oct/2024:14:55:44 +0100] "GET /misc/style-variation?t=1728941227%2C8ed6d7ac5a46100e036b391578ad8c94&variation=default HTTP/1.1" 303 0 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)"
110.249.202.79 - - [17/Oct/2024:14:55:46 +0100] "GET /misc/style-variation?t=1728962928%2Cf7dbd729c0b87a2935f5ab9ac4c7394f&variation=alternate HTTP/1.1" 303 0 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)"
110.249.202.56 - - [17/Oct/2024:14:55:46 +0100] "GET /misc/style-variation?t=1728936434%2C3e60b0a43fe388dc4bd9045318fbbb56&variation=alternate HTTP/1.1" 303 0 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)"
110.249.202.100 - - [17/Oct/2024:14:55:47 +0100] "GET /misc/style-variation?t=1728957042%2Ca4e85bd07246266c8eb8375312b3c9a9&variation=alternate HTTP/1.1" 303 0 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)"
110.249.202.45 - - [17/Oct/2024:14:55:50 +0100] "GET /misc/style-variation?t=1729009691%2Cd1fb89a9aa7d8dd9da908c4d4937c548&variation=default HTTP/1.1" 303 0 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)"
110.249.202.156 - - [17/Oct/2024:14:55:51 +0100] "GET /misc/style-variation?t=1728970157%2Ce88d5150f98a4744408e7fa557f2bad0&variation=default HTTP/1.1" 303 0 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)"
110.249.202.141 - - [17/Oct/2024:14:55:52 +0100] "GET /misc/style-variation?t=1728960834%2C6bf8d8377d42744af04a990a37cb8021&variation=alternate HTTP/1.1" 303 0 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)"
111.225.148.58 - - [17/Oct/2024:14:55:50 +0100] "GET /misc/style-variation?t=1728987133%2C3c6eca697c7bba28b6044fb4275b409c&variation=default HTTP/1.1" 303 0 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)"
110.249.201.43 - - [17/Oct/2024:14:55:53 +0100] "GET /misc/style-variation?t=1728984551%2C692bef8d6839f18c0c5541a4cc693c32&variation=alternate HTTP/1.1" 303 0 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)"
111.225.149.115 - - [17/Oct/2024:14:55:53 +0100] "GET /misc/style-variation?t=1728994893%2Cf08df2f2342ec22560ba11f7ca5ac03c&variation=default HTTP/1.1" 303 0 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)"
111.225.149.48 - - [17/Oct/2024:14:55:56 +0100] "GET /misc/style-variation?t=1728979049%2Ca3bcbdb2008f7773efea958eef87f419&variation=alternate HTTP/1.1" 303 0 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)"
110.249.201.120 - - [17/Oct/2024:14:55:56 +0100] "GET /misc/style-variation?t=1728967898%2C7cb6eb9d6f1d8d3b277934786150d554&variation=alternate HTTP/1.1" 303 0 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)"
111.225.148.73 - - [17/Oct/2024:14:55:57 +0100] "GET /misc/style-variation?t=1729008581%2Cb5c2357a2ec08e3b1a3f686232396ece&variation=default HTTP/1.1" 303 0 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)"
111.225.149.54 - - [17/Oct/2024:14:55:57 +0100] "GET /misc/style-variation?t=1728929777%2Cd390088c36271a16bb0f0b535c2b0be4&variation=default HTTP/1.1" 303 0 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)"
110.249.202.61 - - [17/Oct/2024:14:55:59 +0100] "GET /misc/style-variation?t=1728934659%2Cd50f326ebb74ef85c32db8223db46d78&variation=alternate HTTP/1.1" 303 0 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)"
111.225.149.68 - - [17/Oct/2024:14:55:59 +0100] "GET /misc/style-variation?t=1728994819%2Cbb7b92bc402d0bddbaa2c1eceb28dff3&variation=default HTTP/1.1" 303 0 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)"
111.225.148.60 - - [17/Oct/2024:14:56:00 +0100] "GET /misc/style-variation?t=1728952603%2Cf9ef9f56050cd73f48051ee2e5f9fdb8&variation=default HTTP/1.1" 303 0 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)"
111.225.149.143 - - [17/Oct/2024:14:56:00 +0100] "GET /misc/style-variation?t=1728965761%2C5df0a7adbb8c0ec086e10533cab92d85&variation=default HTTP/1.1" 303 0 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)"
ByteSpider is a f@#!ing c*@#
 
I have never in my 15 years as a webmaster seen Google use bogus user-agents. Do you have any proof of this? I'm interested in learning more.
Google frequently crawl with standard user agents to make sure you're not cloaking (serving different content to Googlebot than users will see). Has been a thing for some time.

 
Google frequently crawl with standard user agents to make sure you're not cloaking (serving different content to Googlebot than users will see). Has been a thing for some time.

I've used many link cloakers for campaigns in the past but have never seen Google hit like this under any user agent.
 
someone is after you! they use dark seo to get you down. enemy should be close
too many tiktokers.


203.208.207.250,.crawl.bytedance.com.

220.243.135.0/24,.crawl.bytedance.com.

220.243.136.0/24,.crawl.bytedance.com.

110.249.201.0/24,.crawl.bytedance.com.

110.249.202.0/24,.crawl.bytedance.com.

111.225.148.0/24,.crawl.bytedance.com.

111.225.149.0/24,.crawl.bytedance.com.

220.243.188.0/24,.crawl.bytedance.com.

220.243.189.0/24,.crawl.bytedance.com.

60.8.123.0/24,.crawl.bytedance.com.

60.8.151.0/24,.crawl.bytedance.com.

ranges
 
Last edited:
Google does deploy stealth bots to check for cloaked content, but I've never seen (nor heard) of them doing it with much more than small samplings (hundreds versus thousands+). I haven't bothered to try to fingerprint these in years (not worth the effort).
 
someone is after you! they use dark seo to get you down. enemy should be close
Please stop spreading misinformation. It doesn't help the OP, it hurts. Thanks.

Explanation:
First, you said it was a DDoS. No, it had all the signs of a crawling campaign, not a DDoS. 60K in a day is not even close to a DDoS. Now you're saying its "dark seo", without the least bit of evidence, citing an enemy. And again, no signs this is what it is.

Crawlers hitting websites in large numbers is normal - with 40% to 70% of traffic (depending on niche) of all traffic being web crawlers.

To all...
Bytedance is an AI crawler (by TikTok as previously noted by @MentaL ) and a poorly coded one. It does fetch robots.txt, but does not appear to respect it, and also does not respect the crawl-delay directive. Cloudflare's AI blocking, from what I can see in my logs, sometimes blocks it, but not always. Based on my research, they are scraping at very high rates in an attempt to catchup in the AI market. I recommend blocking them along with other AI bots.
 
Please stop spreading misinformation. It doesn't help the OP, it hurts. Thanks.

Explanation:
First, you said it was a DDoS. No, it had all the signs of a crawling campaign, not a DDoS. 60K in a day is not even close to a DDoS. Now you're saying its "dark seo", without the least bit of evidence, citing an enemy. And again, no signs this is what it is.

Crawlers hitting websites in large numbers is normal - with 40% to 70% of traffic (depending on niche) of all traffic being web crawlers.

To all...
Bytedance is an AI crawler (by TikTok as previously noted by @MentaL ) and a poorly coded one. It does fetch robots.txt, but does not appear to respect it, and also does not respect the crawl-delay directive. Cloudflare's AI blocking, from what I can see in my logs, sometimes blocks it, but not always. Based on my research, they are scraping at very high rates in an attempt to catchup in the AI market. I recommend blocking them along with other AI bots.

I never said DDOS attack, this user did;


I never said DARK SEO, this user did;


Head Scratch What GIF by The Steve Wilkos Show


What I did was state I am seeing the same as op in regards to /misc/style-variation being accessed in bunches, I can validate this with:


My follow up to the dark seo comment was as follows;


I also recall this:


You seem touchy.
 
I will be real with you. The past two weeks I've not stopped. I'm into bodybuilding, prepping for debut, came off a surgery and off a cut into bulk. I'm redoing my house, painting, deco, moving all rooms,. I'm managing a house hold doing laundry, dishes, whilst working and all this **** and beating myself up daily. I am exhausted lol.
 
Man, I think I'm overworked. You know whos fault this is? my daughters. Too much painting and other nonsense. I am going to bow out because I am way too tired.
I will be real with you. The past two weeks I've not stopped. I'm into bodybuilding, prepping for debut, came off a surgery and off a cut into bulk. I'm redoing my house, painting, deco, moving all rooms,. I'm managing a house hold doing laundry, dishes, whilst working and all this **** and beating myself up daily. I am exhausted lol.
When the man morphs into his username...

Its a beautiful thing to watch.

Or maybe he always was? Thats why he capitalised the first and last letter??


🤯🤯🤯🤯🤯

Take some time for yourself buddy. Burnouts ain't no good for anybody!
 
Back
Top Bottom