Greetings all,
I wanted to share a solution I recently identified to resolve the low latency attacks on OPAC.
I had fail2ban rules, robots.txt in place, but had been getting more and more bots of late switching IPs before bans
can take place. Perhaps they could be ddos, either way it was grinding koha to a
halt.
I had also installed nginx for rate and connection limiting with no success.
I had to remove OPAC from public interaction to restricted IPs.
I recently identified this apache-shared-opac-antibot.conf in Koha 24.11 which is disabled by default.
I enabled it for my OPAC virtual host and it worked like a charm.
It has been 5 days now of successful working.
I believe this is an effort by Mr. David Cook
I wanted to share this information because I had not been able to find this as a formal solution to this problem. Maybe because it has not been applied by many people.
Thanks a lot and best regards.
Naveen Ali,
I T Manager
Engr Abul Kalam Library,
NED University of Engg & Technology,
Karachi, Pakistan.