You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何防范反SEO攻击?解决零停留Bot导致的高跳出率问题

解决方案:拦截恶意Bot并修复SEO跳出率问题

Got it, let's tackle this bot issue that's tanking your SEO. First, the core problem with your current .htaccess rules is that most malicious bots don't send a Referer header at all—so your referrer-targeted rules won't catch them. Plus, redirecting to another site isn't the most effective block; returning a 403 Forbidden response is clearer and avoids wasting resources. Let's break down fixes for both your PHP and ASP.NET environments, plus extra steps to recover your SEO.

1. 改进PHP站点的.htaccess规则

Replace your existing code with this condensed, more effective version. It targets suspicious referrers, known bot user agents, and adds basic rate limiting to catch rapid-fire 0-second visits:

RewriteEngine On

# Block all suspicious referrers you listed (condensed regex)
RewriteCond %{HTTP_REFERER} ^https?://([^.]+\.)*(uptime-as|uptime-us|uptime-eu|hulfingtonpost|apanews|adcash|aliexpress|bestwebsitesawards|buttons-for-website|bycontext|cenokos|cenoval|cityadspix|darodar|econom|edakgfvwql|gobongo|ilovevitaly|iskalko|jollygame|luxup|max-start|o-o-6-o-o|o-o-8-o-o|priceg|savetubevideo|screentoolkit|semalt|seoexperimenty|slftsdybbg|socialseet|superiends|vodkoved|websites-reviews|websocial|ykecwqlixx|simpleshare-buttons)\.(com|net|info|org|ru|co) [NC]
RewriteRule ^ - [F,L]

# Block bots with empty/fake user agents or known malicious identifiers
RewriteCond %{HTTP_USER_AGENT} ^$ [OR]
RewriteCond %{HTTP_USER_AGENT} (bot|crawler|spider|scraper|curl|wget|python|java|libwww-perl) [NC,OR]
RewriteCond %{HTTP_USER_AGENT} (semalt|ilovevitaly|darodar|screentoolkit) [NC]
RewriteRule ^ - [F,L]

# Basic rate limiting to catch rapid 0-second visits (adjust values for your traffic)
# Blocks IPs making 5+ requests in 10 seconds
RewriteCond %{REMOTE_ADDR} ^(.*)$
RewriteCond %{ENV:REQTIME_%1} !^$
RewriteCond %{ENV:REQTIME_%1} >%{TIME}10
RewriteRule ^ - [F,L]
RewriteCond %{REMOTE_ADDR} ^(.*)$
RewriteRule ^ - [E=REQTIME_%1:%{TIME}]

2. 配置ASP.NET站点的web.config规则

Since ASP.NET runs on IIS (which ignores .htaccess), you need to add equivalent blocking rules to web.config. Here's the code:

<configuration>
  <system.webServer>
    <rewrite>
      <rules>
        <!-- Block suspicious referrers -->
        <rule name="Block Bad Referrers" stopProcessing="true">
          <match url=".*" />
          <conditions>
            <add input="{HTTP_REFERER}" pattern="^https?://([^.]+\.)*(uptime-as|uptime-us|uptime-eu|hulfingtonpost|apanews|adcash|aliexpress|bestwebsitesawards|buttons-for-website|bycontext|cenokos|cenoval|cityadspix|darodar|econom|edakgfvwql|gobongo|ilovevitaly|iskalko|jollygame|luxup|max-start|o-o-6-o-o|o-o-8-o-o|priceg|savetubevideo|screentoolkit|semalt|seoexperimenty|slftsdybbg|socialseet|superiends|vodkoved|websites-reviews|websocial|ykecwqlixx|simpleshare-buttons)\.(com|net|info|org|ru|co)" ignoreCase="true" />
          </conditions>
          <action type="CustomResponse" statusCode="403" statusReason="Forbidden" statusDescription="Access Denied" />
        </rule>

        <!-- Block malicious/empty user agents -->
        <rule name="Block Bad User Agents" stopProcessing="true">
          <match url=".*" />
          <conditions logicalGrouping="MatchAny">
            <add input="{HTTP_USER_AGENT}" pattern="^$" ignoreCase="true" />
            <add input="{HTTP_USER_AGENT}" pattern="bot|crawler|spider|scraper|curl|wget|python|java|libwww-perl" ignoreCase="true" />
            <add input="{HTTP_USER_AGENT}" pattern="semalt|ilovevitaly|darodar|screentoolkit" ignoreCase="true" />
          </conditions>
          <action type="CustomResponse" statusCode="403" statusReason="Forbidden" statusDescription="Access Denied" />
        </rule>
      </rules>
    </rewrite>
  </system.webServer>
</configuration>

For more robust rate limiting in IIS, install the official IIS Rate Limiting module—it’s more reliable than rewrite-rule-based limits.

3. 额外措施修复SEO并强化防护

  • Google Search Console Cleanup: Go to Settings > Crawl Stats to identify malicious bot IPs/user agents, then add them to the Blocked Resources list. Use the URL Inspection Tool to confirm your pages aren’t flagged for suspicious traffic.
  • CDN Bot Management: If you use a CDN (Cloudflare, AWS CloudFront), enable their built-in bot detection features—they use machine learning to auto-block malicious bots without manual rule updates.
  • Server-Side Logging: Add code to log IPs, user agents, and request timestamps on both PHP and ASP.NET sides. This helps you spot new bots that slip through your current rules.
  • Google Analytics Exclusions: Filter out known bot IPs/user agents in Analytics to get accurate bounce rate data, so you can verify when the issue is resolved.

内容的提问来源于stack exchange,提问作者Bengi Besceli

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 04:15:16