Download the PHP package abigah/bot-cop without Composer

On this page you can find all versions of the php package abigah/bot-cop. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package bot-cop

Bot Cop - Statamic Addon

Tired of those bots cluttering your server logs, looking for Wordpress vulnerabilies? There's a reason you are using Statamic, you don't need to provide valuable server resources to these bots.

Sure, you can setup fail2ban everywhere and accidentally lock yourself out of your server. Or... you can use Bot Cop to watch 404 traffic and integrate with Cloudflare or Laravel Forge to prevent the bot from getting to your server in the first place.

Features

This addon integrates with:

Now with Laravel's built-in rate-limiting to catch the poorly configured spiders.

How to Install

You can install this addon via Composer:

How to Use

The following Environment Variables are mandatory for the addon to operate. Add this to your project.

If you aren't using Cloudflare or Forge, remove that option. You can just use Logging but that wouldn't be very helpful.

Add your Cloudflare information. (Requires Cloudflare Proxying turned on in DNS)

  1. Create an Account API Token. On your Cloudflare dashboard, go to Manage Account > Account API Tokens and Create Token. Give it two privileges, Account.Account Filter Lists.Read and Account.Account Filter Lists.Edit

  2. On your Cloudflare dashboard, go to Manage Account > Configurations > Lists Create a new list
  3. You then need to create the Rule to tell Cloudflare what to do with the IPs on the list. Head to your project's domain and go to Security > Security Rules and Create a Rule. Call it whatever you want. Choose IP Source Address - is in list - botcop. Select the action you want to take (Managed Challenge is fine), then save it.
  4. Add your API token, Account ID and List Id to the following .env variables. They are the UUIDs found in the URL when looking at the list. https://dash.cloudflare.com/waasofu9qgfqtc0h97gl5o2amt1tn0ts/configurations/lists/bxwtz2gmte7115m3vamy8yq7ly2m4i1i

Add your Laravel Forge information.

If you aren't using Cloudflare or Proxying, you can use Laravel Forge's API to work with UFW.

Note: If you use Cloudflare Proxy or another firewall that acts as a proxy and changes the IP address, UFW will not see the real IP. So Bot Cop will add it to the firewall but it won't actually deny the right IP. I personally run the Cloudflare and Forge options. I just feel more powerful banning the IP from both.

  1. Head to https://forge.laravel.com/user-profile/api and create a token. Copy and paste it into the following .env variable. IT IS VERY LONG. LEAVE IT ON ONE LINE.

  2. Choose the server your project is on and grab the server ID. Add it to this .env variable. If you have multiple servers hosting the site, you'll want to add the server ID to each individual .env file. https://forge.laravel.com/servers/0000000/sites

Ensure the scheduler is setup (the Statamic one)

As long as the scheduler is setup, IPs will be unbanned after an hour (customizable). If you don't set it up, you'll have to remove the IPs manually. We default to running the removal command every 30 minutes to prevent issues with rate-limiting. https://statamic.dev/scheduling#

Optional Configuration

Some things to watch for...

Rate-limiting

If you are using Glide, the request isn't always clearly an image. You'll want to make sure your asset container's public directory is not rate-limited. To prevent the server from doing all the work when a bot is misconfigured, the rate-limiter engages (if true, default behavior) before the 404 check. We are also now checking the allowed IP and allowed path lists ahead of the 404 check to ensure the rate-limiting isn't triggered on an allowed IP or livewire updates.

Cloudflare only allows 1 custom list on the free plan.

It can handle 10000 IPs so you should be okay as long as you are treating the bans as temporary. This addon doesn't use WAF due to requiring the Enterprise Plan, but if you want us to, reach out. If you have multiple domains you want to protect, you can. Read on...

Multiple Projects

There are a number of options in the config file that you can override. If you use this addon in multiple projects, you can setup the Cloudflare and Forge Rule Names so each project will add and remove the IPs with that name filter. However, It won't allow you to add the same IP address if it is already in the list, so you may end up removing it even though the bot may be trying to hit the second. The first 404 on the other site will add it back though. it could have some interesting race conditions in the logs but it shouldn't cause a problem.

Statamic Multisite / Other sites on the same server

Once an IP is added to the list, it is unable to see any other sites using the same IP list (Cloudflare) or on the same server (Laravel Forge). This addon is live on a multisite with over 30 URLs and works great.

Temporary Bans vs Permanent

Most jailing of bots and spiders is done temporarily. If you want to use the same IP list or firewall to ban an IP permanently, give it a different name or comment than the config file and it won't automatically remove it.

Can I add to the allowed list?

Of course, you can publish the config or give us a PR. I'm also working on a Control Panel dashboard to make it something that can be done there to prevent having to deploy. Note that when you publish the config, you won't get our updates to it so you may want to hold off until we solidify all the variables.

Hex escapes in the blocked list

The \x00–\x15 entries catch the hex escapes that exploit probes put in a URL, whether they send them raw or percent-encoded (%5Cx00). Blocked paths are checked against both the raw and the URL-decoded path, so %2Eenv counts as .env too.

Earlier versions listed these as bare x00–x15, which also matched ordinary filenames like hero-1920x1080.jpg or the apple-touch-icon-120x120.png iPhones request on their own, and banned real visitors whenever one of those 404'd. If you published the config, add the backslash to those entries.

Can I add to the blocked list?

For sure, you can publish the config or give us a PR. I'm also working on a Control Panel dashboard to make it something that can be done there to prevent having to deploy. Note that when you publish the config, you won't get our updates to it so you may want to hold off until we solidify all the variables.

I'm using a different firewall or proxy, will you support it?

Maybe. You can do a PR or if you want to work with us to do it, let me know and I'll see what I can do.

I found a bug / security issue

For security related issues, email [email protected]. For other issues, put them into the issues board in Github. Don't put your tokens or anything in there please.


All versions of bot-cop with dependencies

PHP Build Version
Package Version
Requires statamic/cms Version ^5.0 || ^6.0
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package abigah/bot-cop contains the following files

Loading the files please wait ...