Post by TomSut » Wed May 03, 2023 6:03 pm

Noticed an unusually large amount of people online in the back end of Opencart yesterday, had a look a the IP addresses and it's coming from amazonaws.com in Singapore. It's a new IP address every 30 seconds looking up a product tag. It's never the same IP address twice. Some of the IP addresses just this second are 13.213.124.120 or 52.77.191.219 or 13.213.241.3 or 18.140.93.4 I've got 1000s of them from just one day. It can't be any benefit to me having this using up my bandwidth. Any Idea how to stop it?

New member

Posts

Joined
Wed Nov 01, 2017 10:41 pm

Post by Johnathan » Wed May 03, 2023 9:26 pm

Check to see if they have a particular user agent. If so, you should be able to block it based on that.

Otherwise, you may have to use some blocking service like Cloudflare or Bitninja. They may be able to automatically detect it, but you may have to look into rate limiting, or something that blocks visitors specifically looking for whatever the bots are looking for.

Image Image Image Image Image


User avatar
Administrator

Posts

Joined
Fri Dec 18, 2009 3:08 am


Post by johnp » Thu May 04, 2023 12:30 am

TomSut wrote:
Wed May 03, 2023 6:03 pm
Noticed an unusually large amount of people online in the back end of Opencart yesterday, had a look a the IP addresses and it's coming from amazonaws.com in Singapore. It's a new IP address every 30 seconds looking up a product tag. It's never the same IP address twice. Some of the IP addresses just this second are 13.213.124.120 or 52.77.191.219 or 13.213.241.3 or 18.140.93.4 I've got 1000s of them from just one day. It can't be any benefit to me having this using up my bandwidth. Any Idea how to stop it?
Try sticking Cidram on. It blocks traffic from known bad sources. You can also enable a captcha on it. Although not a total solution it is IMO a valuable extra layer of protection.

https://github.com/CIDRAM/CIDRAM

Also consider sticking a firewall on like Ninja Firewall:

https://nintechnet.com/ninjafirewall/pro-edition

Opencart 1.5.6.5/OC Bootstrap Pro/VQMOD lover, user and geek.
Affordable Service £££ - Opencart Installs, Fixing, Development and Upgrades
Plus Ecommerce, Marketing, Mailing List Management and More
FREE Guidance and Advice at https://www.ecommerce-help.co.uk


User avatar
Active Member

Posts

Joined
Fri Mar 25, 2011 10:25 am
Location - Surrey, UK

Post by Elinahav » Thu Jun 26, 2025 5:33 pm

I’ve seen sudden spikes of random IPs from amazonaws hit my sites before, and it’s super annoying, especially when it eats up server resources like that. In my case, I started by adding rate limits and blocking whole IP ranges related to AWS in my firewall, but the real pain is they always switch IPs so quick. Sometimes even captchas barely help, but anything that slows the flood is worth a try.

Newbie

Posts

Joined
Sat Apr 06, 2024 4:38 pm

Post by johnp » Thu Jun 26, 2025 6:01 pm

Cidram will do the job:

https://github.com/CIDRAM/CIDRAM

Opencart 1.5.6.5/OC Bootstrap Pro/VQMOD lover, user and geek.
Affordable Service £££ - Opencart Installs, Fixing, Development and Upgrades
Plus Ecommerce, Marketing, Mailing List Management and More
FREE Guidance and Advice at https://www.ecommerce-help.co.uk


User avatar
Active Member

Posts

Joined
Fri Mar 25, 2011 10:25 am
Location - Surrey, UK
Who is online

Users browsing this forum: No registered users and 10 guests