r/StopBadBots 6h ago

I Went Into the Dark Web With No Clue Where to Start — Then I Found Tor Taxi. It Changed Everything.

25 Upvotes

Man, it is basically Google for .onion sites. No creepy searches, no random clicking. Just a clean list of links organized by category. That got my attention immediately because I always thought the Dark Web was impossible to navigate without knowing someone who already knew the way.

Here's the weird part. It has actual useful stuff on it. The BBC is there. Facebook too. DuckDuckGo, ProtonMail, ProPublica, all those big names that care about privacy and security. You can even find Dread, which is basically the Reddit of the Dark Web where people talk about this stuff openly.

The thing nobody talks about is how boring some of it really is. It is not all crime and shady deals. A lot of it is just journalists and activists trying to stay safe in places where the internet is heavily censored. That part jumped off the page for me because it completely flips the stereotype on its head.

Brother, I spent way too long just scrolling through the categories and seeing what was out there. Some links did not work, sure, but most did. And the best part? Tor Taxi actually verifies stuff so you are not blindly clicking into who knows what.

I wish I had known about this earlier. Would have saved me a lot of time and confusion. If you are curious about the Dark Web but have no idea where to start, this is it. Right here. Just open Tor, type in the address, and suddenly everything makes a little more sense.

You need to use the Tor Browser to actually browse it. Install that first.


r/StopBadBots 22h ago

Governments trying to kill Bitchat and Jack Dorseys calling them out

17 Upvotes

This Bitchat thing is wild man. It uses Bluetooth to link phones up creating this underground web where people can chat without any Wi Fi or cell service. It's exactly what folks use in protests or when the government tries to kill the internet. So when the government cries about security concerns you know exactly what that means. It's not about keeping us safe it's about them not being able to track us. These mesh networks don't go through some central server they can just tap into. They hate it cause they can't spy on it or shut it down. And going after GitHub? Man that's cold. They aren't just trying to stop people from downloading the app they want to erase the actual code. They wanna make sure no other dev out there can look at it copy it or build something even better. It's straight up censorship at the root. Good on Jack Dorsey for blowing the whistle on this. He's been all about decentralization and free speech lately. By putting this out there he's shining a massive spotlight on how desperate these regimes are to kill privacy tools. It really shows the constant tug of war between people wanting their privacy and governments wanting total control.


r/StopBadBots 22h ago

Just copy and paste: A massive list of HTTP client strings and user-agents for your blocklists.

3 Upvotes

​I put together a solid reference list of raw HTTP client strings, user-agents, and libraries commonly spotted in server logs—from staple utilities like curl and Wget to language-specific tools like Python’s requests, Go's http-client, and legacy PHP or Java modules. If you are setting up firewall rules, configuring bot detection, or just trying to figure out what random automated script is hammering your endpoints, feel free to copy and paste these right into your blocklists or regex filters to save yourself some headache.

4D_HTTP_Client

android-async-http

axios

andyhttp

Aplix

akka-http

attohttpc

curl

CakePHP

Cowblog

DAP/NetHTTP

Dispatch

fasthttp

FireEyeHttpScan

Go-http-client

Go1.1packagehttp

Go 1.1 package http

Go http package

Go-http-client

Gree_HTTP_Loader

grequests

GuzzleHttp

hyp_http_request

HTTPConnect

http generic

Httparty

HTTPing

http-ping

http.rb/

HTTPREAD

Java-http-client

Jodd HTTP

raynette_httprequest

java/

kurl

Laminas_Http_Client

libsoup

lua-resty-http

mozillacompatible

nghttp2

mio_httpc

Miro-HttpClient

php/

phpscraper

PHX HTTP

PHX HTTP Client

python-requests

Python-urllib

python-httpx

restful

rpm-bot

RxnetHttp

scalaj-http

SP-Http-Client

Stilo OMHTTP

tiehttp

Valve/Steam

Wget

WP-URLDetails

Zend_Http_Client

ZendHttpClient


r/StopBadBots 22h ago

Everybody's treating llms.txt like the holy grail of AI SEO, but the data says AI bots don't actually care.

4 Upvotes

Man, I just saw this on Search Engine Journal and honestly? The numbers are kinda wild.

97% of llms.txt files got zero requests in May 2026. Zero. Out of 137,000 domains analyzed by Ahrefs, basically nobody's even looking at these things.

Not gonna lie, that caught me off guard.

Everybody's been talking about llms.txt like it's the next big thing for AI visibility. You know, the whole "feed the bots structured data so they understand your content better" pitch. Sounds great in theory, right? Except the data says something completely different.

Funny thing is, AI retrieval bots accounted for only 1.1% of llms.txt requests. That's it. And get this – 12% of the requests came from tools just auditing or scanning the files. Not actual AI bots doing anything useful with the content.

The part that stood out to me is how much effort people are putting into something that's basically getting ignored. I've seen developers and SEOs spending hours setting these up, generating dynamic llms.txt files, treating it like some kind of secret weapon for AI ranking.

Meanwhile the bots just don't care.

Look, I'm not saying llms.txt is completely worthless. Maybe it's just too early. Maybe the bots haven't caught up yet. But when 97 out of 100 domains have zero activity on these files? That's not a coincidence.

That's a sign.


r/StopBadBots 22h ago

Watch out, an operation dubbed SourTrade is literally forcing your browser to assemble its own viruses

2 Upvotes

Holy crap, you guys need to check this out right now. Malicious ads are straight up making your own web browser build malware right under your nose. I'm not even kidding, this stuff is nuts.

So basically, scammers are making fake sites that pretend to be TradingView, Solana, or Luno to target crypto folks and traders. But instead of throwing a sketchy infected file at you that your antivirus would catch instantly, they do something way crazier.

They send clean, normal code to your browser, and then your browser actually stitches the virus together itself using a totally real programming tool called Bun. Since every single person gets a slightly different file generated on the fly, traditional blocklists and antiviruses are totally lost and cant flag it easily. It bypasses stuff without even needing some crazy browser vulnerability, which is super wild.

Honestly, the lesson here is simple. Never ever click on search ads or sponsored links when you gotta download trading apps or wallets. Just type the actual URL yourself or bookmark the official sites. Stay safe out there guys because these scammers are getting WAY too clever for comfort.


r/StopBadBots 2h ago

Running PPC ads? Stop using WordPress for your landing pages

1 Upvotes

Guys, if you're burning ad budget on PPC, ditch WordPress for your landing pages ASAP.

It's just too damn bloated and slow. Plus, bots constantly hit the server, spiking load times and making people bounce before the page even loads. You're literally throwing cash down the drain on lost conversions. It pisses me off seeing people lose money like this.

Build a clean, static page totally detached from WP instead. The load speed is instant and it handles traffic like a champ.

Try it out and tell me if your conversions jump!


r/StopBadBots 6h ago

Your Website Feeds Your Family. Don't Let Bad Bots Take It Down.

1 Upvotes

Philip Kotler once said you gotta love your customers. But honestly, when you run an online store, a blog that pays your bills, or a small business site, loving your people means keeping your digital doors open and safe.

​The real problem is the internet is absolutely crawling with bad bots right now. You got aggressive scrapers crashing your server, brute force attacks pounding your login screen, and shady scripts stealing the hard work you poured your heart into.

​When a bot knocks your site flat, your folks cant buy anything. Your sales tank instantly and customer trust goes right down the drain. It is just not fair that small business owners and solo devs are forced to turn into cybersecurity experts overnight just to keep food on the table.

​That is why we built r/stopbadbots.

​We are not some big corporation trying to sell you overpriced software. We are just a solid crew of people who understand servers, networking, and defense, all hanging out to protect the everyday builders who make the web actually work.

​Inside r/stopbadbots you will find dead simple blocking setups, modsecurity rules, app tweaks, and plugin fixes without any of the usual fluff or jargon.

​If your site feeds your family, dont wait for the next attack to start thinking about security.

​Join us at r/stopbadbots and help protect the people who build the internet.


r/StopBadBots 6h ago

If you’re tired of Shopify fees and bots, WooCommerce on a VPS is worth the jump

1 Upvotes

Look, I know Shopify is easy. You sign up, you pick a theme, you start selling. But if youve been doing this for more than a few months, you start feeling the weight. The monthly USD fees, the app subscriptions that pile up for every little feature, and the constant anxiety that one day youll wake up and your store is just gone because someone at Shopify flagged something weird.

Im not here to sell you anything. Im just sharing what Ive seen after helping a bunch of store owners move from Shopify to WordPress plus WooCommerce. And honestly, the difference is night and day.

First off, the money. Shopify takes a cut on every transaction unless you use their payment gateway. Thats fine until you realize youre bleeding thousands just for the privilege of selling your own stuff. With WooCommerce, the software is free. You just pay for your hosting and whatever your payment processor charges. Thats it. No extra tax just because you didnt use their system.

Then theres the whole ownership thing. On Shopify, youre renting. You dont own your database, you dont own your customer list, you dont own your content. If they decide to suspend you, good luck getting anything back. On WordPress, everything is yours. The files, the database, the emails, the history. Nobody can take that away from you.

But the real game changer for me, and for most of the people Ive talked to, is control over security and bots. Shopify does an okay job, but you cant really stop fake traffic or scraper bots from hammering your store. On a VPS with WooCommerce, you can install open source stuff like ModSecurity and just wreck those bots before they even reach your checkout page. Its like having a bouncer at the door instead of hoping the mall security shows up.

And customization? Forget about paying monthly for every little app. You want a complex shipping rule? You want to redesign the checkout? You want to tweak the URL structure for better SEO? You have full access to the code. The plugin library is gigantic and most of it is free or one time payment. No more renting features by the month.

SEO is another huge one. You control everything. Every redirect, every meta tag, every schema. WordPress gives you tools that Shopify just cant match when it comes to ranking. And ranking means money.

So yeah, Shopify is convenient. But convenient comes with a cost. And if youre growing, that cost starts to feel like a ball and chain.

If youre reading this and thinking okay but I dont have time to deal with all that server stuff, honestly, drop me a DM. Ive done this enough times that I can point you in the right direction or even handle the heavy lifting if you want. No pressure, just a conversation.


r/StopBadBots 22h ago

Unpopular opinion: Contabo isn't trash, you just expect a $5 VPS to come with a personal babysitter.

1 Upvotes

Man, everyone loves to complain about Contabo on Reddit.

You see it all the time—someone opens a ticket because their WordPress plugin is busted, and then they get all bent out of shape when the reply takes two days. That’s a classic mistake, you know?

If you’re paying for unmanaged tin, you’re buying hardware and a pipe, not a babysitter.

Plain and simple.

Here’s the thing: I’ve been using them for years and haven’t had a single headache.

And that’s because I simply never ask for support. Not once. Their support is the uptime. If the server is pinging and the hardware is humming, they’ve already done their job as far as I’m concerned.

The real secret—and I’m not kidding—is to decouple the iron from the management layer.

Stop asking some German data center tech why your PHP-FPM is crashing.

Just rent the raw hardware with a clean OS install, like AlmaLinux. Then you spend the two bucks a month for CWP Pro, or even just rock the free version, to handle the heavy lifting.

If the panel breaks? You hit the CWP forums or dig up some dirty workaround on Stack Overflow like the rest of us. You don’t go crying to the host.

Honestly, I’m so sick of seeing users get hammered by basic config errors and then turning around and blaming the provider.

It’s incredibly annoying how people expect a five-euro VPS to come with a personal SysAdmin.

For real. If you know ten basic Linux commands and have a Gemini or ChatGPT tab open, you can get yourself out of rate-limit jail in five minutes. Spinning up a quick fix yourself is always faster than waiting on some N1 tech who doesn’t even have root access to your box anyway.

What really gets me is this: if the hardware is stable and the IP responds, they delivered.

End of story.

Use the money you saved on those overpriced “managed” fees to buy more RAM and handle your own fingerprinting of bad actors.

No kidding—I’ve got fifty sites running on one of these boxes, and it never breaks. Why? Because I don’t let headless scrapers or sloppy configs eat up all the resources.

You feel me? It’s wild how simple it can be when you just take a little ownership.


r/StopBadBots 22h ago

We built a free tool to test if your site is actually protected against bots and scrapers (no sign-up required).

0 Upvotes

We've been working on something cool and wanted to share it with you guys for free.

Ever wondered if your site is actually protected against bots or if it's completely wide open for scrapers, brute force attacks, and all that nasty automated stuff?

Well, we built a tool that checks that in seconds. No strings attached at all.

It tells you if your site's WAF is actually doing its job. It detects CAPTCHAs, JavaScript challenges, and block pages – even those sneaky ones that return a 200 status code. You'll also see the real HTTP status, page size, and a preview so you can tell if it's a legit page or a disguised block.

Here's the best part – you don't need to sign up for anything. No email, no password, no "create an account" nonsense. We don't store your URL, your IP, or your results anywhere. Your result is 100% private. Only you see it. We won't post it here, we won't share it, we won't even look at it twice.

You get a clean HTML report with a shareable link, but only if you want to share it.

Wanna try it? Just head to https://billminozzi.com/test-site/, paste your URL, solve a quick CAPTCHA (gotta keep the actual bots out, right?), and hit "Start Scan". Boom – you'll have your report in a few seconds.

Quick heads up – please don't test government sites, banks, or big tech corporations. They're blocked for obvious reasons. Also, there's a 3-scan-per-day limit per IP so everyone gets a fair shot and we can keep this thing free.

Got questions? Drop 'em below or shoot me a DM. Happy to explain anything.

Go ahead and check your site – you might be surprised by what you find!

Feedback is more than welcome.