I just tried to add a couple pictures to a page using TTG Publisher and I get an error “Can’t update this collection. Unable to perform action GetSetupforTemplate. The page sent an action that was not available.” Any ideas? I’m concerned because…
FYI the last few months my little static photography site has been getting hammered by bots. First major episode was last summer - I started getting nasty emails from my hosting provider about my site “using too many resources” which seemed nonsense to me since literally it’s a bunch of galleries built with Backlight and nothing else. When I went and looked at site and server info, what I saw were a whole lot of versions of ClaudeBot crawling over and over again. (small SEO consultants all seem to use the opensource Claudebot code base.) I tried a lot of things, ended up signing up for the free Cloudflare service - set up a bunch of rules, and things settled down.
Two weeks ago, I started getting nasty emails again from my hosting provider. This time it looked very different, and L2 support got on the phone with me and we figured out that the site was being repeatedly crawled by malicious bots looking for vulnerabilities. Every time they hit a block from Cloudflare or from rules I’d set up on the host, they spawned a new one. I blocked a bunch of the IP addresses with WAF rules and then watched the volume of activity stay the same - new IP addresses. (When I ran IT Ops for a major US federal agency, we battled this problem of smart bots in many different forms from foreign bad actors who periodically tried to take us down, but there’s crawler code out there for 12 year olds to download that does pretty sophisticated tricks.) Most of the malicious crawlers were coming from Microsoft Cloud hosts in Brazil, Italy, and the US; a call to a friend at MSFT Cloud Services with some info and suddenly that all stopped. I can still see (at Cloudflare) a lot of attempts to get into my site (bizarrely Brazil tops the list), but for the moment all the work has successfully stopped the madness.
Something about my little static photography site makes bad dudes think there’s an opportunity of some sort if they can just find the vulnerability, and I wonder if it’s something related to how Backlight is coded and created. The good news is, they’ve found no vulnerabilities because the site hasn’t been taken over.
I wonder if all the CloudFlare and WAF stuff is blocking TTG Publisher.