Self-Hosted JA4 to combat AI bots
2 points
1 hour ago
| 1 comment
| blog.miloslavhomer.cz
| HN
Bender
43 minutes ago
[-]
This is a good write-up. Is your blog running JA4 right now?
reply
ArcHound
39 minutes ago
[-]
Hello again! Yes it is. If you have an exotic client, I'm here for it :D
reply
Bender
30 minutes ago
[-]
Nice. I was more curious of the clients using HTTP/2.0 HTTP Protocol, what percentage of them is JA4 detecting as bots that spoof all the other headers a browser sends? That is the missing piece in my blog write-up as I don't do SSL fingerprinting. I am trying to see what percentage are getting through my very crude methods.
reply
ArcHound
14 minutes ago
[-]
I'll get back to you on this, I'll need to parse some logs. I should have at least ALPNs
reply