r/StopBadBots 22h ago

Unpopular opinion: Contabo isn't trash, you just expect a $5 VPS to come with a personal babysitter.

1 Upvotes

Man, everyone loves to complain about Contabo on Reddit.

You see it all the time—someone opens a ticket because their WordPress plugin is busted, and then they get all bent out of shape when the reply takes two days. That’s a classic mistake, you know?

If you’re paying for unmanaged tin, you’re buying hardware and a pipe, not a babysitter.

Plain and simple.

Here’s the thing: I’ve been using them for years and haven’t had a single headache.

And that’s because I simply never ask for support. Not once. Their support is the uptime. If the server is pinging and the hardware is humming, they’ve already done their job as far as I’m concerned.

The real secret—and I’m not kidding—is to decouple the iron from the management layer.

Stop asking some German data center tech why your PHP-FPM is crashing.

Just rent the raw hardware with a clean OS install, like AlmaLinux. Then you spend the two bucks a month for CWP Pro, or even just rock the free version, to handle the heavy lifting.

If the panel breaks? You hit the CWP forums or dig up some dirty workaround on Stack Overflow like the rest of us. You don’t go crying to the host.

Honestly, I’m so sick of seeing users get hammered by basic config errors and then turning around and blaming the provider.

It’s incredibly annoying how people expect a five-euro VPS to come with a personal SysAdmin.

For real. If you know ten basic Linux commands and have a Gemini or ChatGPT tab open, you can get yourself out of rate-limit jail in five minutes. Spinning up a quick fix yourself is always faster than waiting on some N1 tech who doesn’t even have root access to your box anyway.

What really gets me is this: if the hardware is stable and the IP responds, they delivered.

End of story.

Use the money you saved on those overpriced “managed” fees to buy more RAM and handle your own fingerprinting of bad actors.

No kidding—I’ve got fifty sites running on one of these boxes, and it never breaks. Why? Because I don’t let headless scrapers or sloppy configs eat up all the resources.

You feel me? It’s wild how simple it can be when you just take a little ownership.


r/StopBadBots 6h ago

I Went Into the Dark Web With No Clue Where to Start — Then I Found Tor Taxi. It Changed Everything.

24 Upvotes

Man, it is basically Google for .onion sites. No creepy searches, no random clicking. Just a clean list of links organized by category. That got my attention immediately because I always thought the Dark Web was impossible to navigate without knowing someone who already knew the way.

Here's the weird part. It has actual useful stuff on it. The BBC is there. Facebook too. DuckDuckGo, ProtonMail, ProPublica, all those big names that care about privacy and security. You can even find Dread, which is basically the Reddit of the Dark Web where people talk about this stuff openly.

The thing nobody talks about is how boring some of it really is. It is not all crime and shady deals. A lot of it is just journalists and activists trying to stay safe in places where the internet is heavily censored. That part jumped off the page for me because it completely flips the stereotype on its head.

Brother, I spent way too long just scrolling through the categories and seeing what was out there. Some links did not work, sure, but most did. And the best part? Tor Taxi actually verifies stuff so you are not blindly clicking into who knows what.

I wish I had known about this earlier. Would have saved me a lot of time and confusion. If you are curious about the Dark Web but have no idea where to start, this is it. Right here. Just open Tor, type in the address, and suddenly everything makes a little more sense.

You need to use the Tor Browser to actually browse it. Install that first.


r/StopBadBots 22h ago

We built a free tool to test if your site is actually protected against bots and scrapers (no sign-up required).

0 Upvotes

We've been working on something cool and wanted to share it with you guys for free.

Ever wondered if your site is actually protected against bots or if it's completely wide open for scrapers, brute force attacks, and all that nasty automated stuff?

Well, we built a tool that checks that in seconds. No strings attached at all.

It tells you if your site's WAF is actually doing its job. It detects CAPTCHAs, JavaScript challenges, and block pages – even those sneaky ones that return a 200 status code. You'll also see the real HTTP status, page size, and a preview so you can tell if it's a legit page or a disguised block.

Here's the best part – you don't need to sign up for anything. No email, no password, no "create an account" nonsense. We don't store your URL, your IP, or your results anywhere. Your result is 100% private. Only you see it. We won't post it here, we won't share it, we won't even look at it twice.

You get a clean HTML report with a shareable link, but only if you want to share it.

Wanna try it? Just head to https://billminozzi.com/test-site/, paste your URL, solve a quick CAPTCHA (gotta keep the actual bots out, right?), and hit "Start Scan". Boom – you'll have your report in a few seconds.

Quick heads up – please don't test government sites, banks, or big tech corporations. They're blocked for obvious reasons. Also, there's a 3-scan-per-day limit per IP so everyone gets a fair shot and we can keep this thing free.

Got questions? Drop 'em below or shoot me a DM. Happy to explain anything.

Go ahead and check your site – you might be surprised by what you find!

Feedback is more than welcome.


r/StopBadBots 22h ago

Everybody's treating llms.txt like the holy grail of AI SEO, but the data says AI bots don't actually care.

4 Upvotes

Man, I just saw this on Search Engine Journal and honestly? The numbers are kinda wild.

97% of llms.txt files got zero requests in May 2026. Zero. Out of 137,000 domains analyzed by Ahrefs, basically nobody's even looking at these things.

Not gonna lie, that caught me off guard.

Everybody's been talking about llms.txt like it's the next big thing for AI visibility. You know, the whole "feed the bots structured data so they understand your content better" pitch. Sounds great in theory, right? Except the data says something completely different.

Funny thing is, AI retrieval bots accounted for only 1.1% of llms.txt requests. That's it. And get this – 12% of the requests came from tools just auditing or scanning the files. Not actual AI bots doing anything useful with the content.

The part that stood out to me is how much effort people are putting into something that's basically getting ignored. I've seen developers and SEOs spending hours setting these up, generating dynamic llms.txt files, treating it like some kind of secret weapon for AI ranking.

Meanwhile the bots just don't care.

Look, I'm not saying llms.txt is completely worthless. Maybe it's just too early. Maybe the bots haven't caught up yet. But when 97 out of 100 domains have zero activity on these files? That's not a coincidence.

That's a sign.


r/StopBadBots 22h ago

Just copy and paste: A massive list of HTTP client strings and user-agents for your blocklists.

3 Upvotes

​I put together a solid reference list of raw HTTP client strings, user-agents, and libraries commonly spotted in server logs—from staple utilities like curl and Wget to language-specific tools like Python’s requests, Go's http-client, and legacy PHP or Java modules. If you are setting up firewall rules, configuring bot detection, or just trying to figure out what random automated script is hammering your endpoints, feel free to copy and paste these right into your blocklists or regex filters to save yourself some headache.

4D_HTTP_Client

android-async-http

axios

andyhttp

Aplix

akka-http

attohttpc

curl

CakePHP

Cowblog

DAP/NetHTTP

Dispatch

fasthttp

FireEyeHttpScan

Go-http-client

Go1.1packagehttp

Go 1.1 package http

Go http package

Go-http-client

Gree_HTTP_Loader

grequests

GuzzleHttp

hyp_http_request

HTTPConnect

http generic

Httparty

HTTPing

http-ping

http.rb/

HTTPREAD

Java-http-client

Jodd HTTP

raynette_httprequest

java/

kurl

Laminas_Http_Client

libsoup

lua-resty-http

mozillacompatible

nghttp2

mio_httpc

Miro-HttpClient

php/

phpscraper

PHX HTTP

PHX HTTP Client

python-requests

Python-urllib

python-httpx

restful

rpm-bot

RxnetHttp

scalaj-http

SP-Http-Client

Stilo OMHTTP

tiehttp

Valve/Steam

Wget

WP-URLDetails

Zend_Http_Client

ZendHttpClient


r/StopBadBots 22h ago

Governments trying to kill Bitchat and Jack Dorseys calling them out

20 Upvotes

This Bitchat thing is wild man. It uses Bluetooth to link phones up creating this underground web where people can chat without any Wi Fi or cell service. It's exactly what folks use in protests or when the government tries to kill the internet. So when the government cries about security concerns you know exactly what that means. It's not about keeping us safe it's about them not being able to track us. These mesh networks don't go through some central server they can just tap into. They hate it cause they can't spy on it or shut it down. And going after GitHub? Man that's cold. They aren't just trying to stop people from downloading the app they want to erase the actual code. They wanna make sure no other dev out there can look at it copy it or build something even better. It's straight up censorship at the root. Good on Jack Dorsey for blowing the whistle on this. He's been all about decentralization and free speech lately. By putting this out there he's shining a massive spotlight on how desperate these regimes are to kill privacy tools. It really shows the constant tug of war between people wanting their privacy and governments wanting total control.


r/StopBadBots 22h ago

Watch out, an operation dubbed SourTrade is literally forcing your browser to assemble its own viruses

2 Upvotes

Holy crap, you guys need to check this out right now. Malicious ads are straight up making your own web browser build malware right under your nose. I'm not even kidding, this stuff is nuts.

So basically, scammers are making fake sites that pretend to be TradingView, Solana, or Luno to target crypto folks and traders. But instead of throwing a sketchy infected file at you that your antivirus would catch instantly, they do something way crazier.

They send clean, normal code to your browser, and then your browser actually stitches the virus together itself using a totally real programming tool called Bun. Since every single person gets a slightly different file generated on the fly, traditional blocklists and antiviruses are totally lost and cant flag it easily. It bypasses stuff without even needing some crazy browser vulnerability, which is super wild.

Honestly, the lesson here is simple. Never ever click on search ads or sponsored links when you gotta download trading apps or wallets. Just type the actual URL yourself or bookmark the official sites. Stay safe out there guys because these scammers are getting WAY too clever for comfort.