Skip to content

Anubis Protection

Beginning with LiteSpeed Web Server 6.4, Anubis is available as an additional method of defense against bots and automated attacks, alongside the existing CAPTCHA protection.

Warning

Anubis is currently available in the v6.4.0RC1 test build. Be sure to test on a non-production server before deploying.

Anubis can be used on its own or together with CAPTCHA verification. When both are enabled, Anubis checks the request first, and CAPTCHA verification follows.

Upgrade to LSWS v6.4.0RC1

To upgrade an existing v6.3.x installation to the v6.4.0RC1 test build, run the following command:

/usr/local/lsws/admin/misc/lsup.sh -f -v 6.4.0RC1

Install Anubis

Anubis is a proof-of-work challenge that filters out automated traffic before it reaches your site. It runs as a backend service that handles all Anubis-related requests.

To install the service, run the following setup script:

/usr/local/lsws/admin/misc/setup_anubis.sh

This installs the anubis@lsanubis.service service, which acts as the backend for Anubis requests.

The service listens on 127.0.0.1:8923 by default. Confirm that it is running and listening before you continue:

systemctl is-active anubis@lsanubis.service
ss -lnt | grep 8923

If Anubis is running, the service will report active and indicate that the backend is listening on 127.0.0.1:8923:

active LISTEN 0 4096 127.0.0.1:8923 0.0.0.0:*

Warning

If the backend service is not running, LiteSpeed Web Server serves traffic without Anubis protection rather than returning an error. It is good practice to confirm that the service is active before relying on it.

Enable Anubis

Use the LsAnubis directive to turn Anubis on or off. It can be set at the Apache server level or the virtual-host level:

LsAnubis on|off

For example, to enable Anubis, add the following to your Apache server or virtual-host configuration:

<IfModule LiteSpeed>
LsAnubis on
</IfModule>

If you prefer, you can use the WebAdmin Console. Navigate to Configuration > Server > Security > Anubis Proof-of-Work and set Enable Anubis to On.

To enable Anubis with cPanel, use one of the two methods described above: the directive or the WebAdmin Console.

Combine Anubis with CAPTCHA

Anubis can be used together with CAPTCHA verification (reCAPTCHA, hCaptcha, or ALTCHA). When both are active, Anubis evaluates the request first, and CAPTCHA verification is applied afterward.

Verify Anubis is working

At the default debug level, Anubis writes nothing to the server error log, so a successful setup looks identical to one that is doing nothing. Verify from the response headers instead.

Send a test request

Request a protected page and look for the Anubis cookies:

curl -sI -A "Mozilla/5.0" https://example.com/ | grep -i anubis

A protected site returns two techaro.lol-anubis-* cookies:

set-cookie: techaro.lol-anubis-auth=; Path=/; Max-Age=0; Secure; SameSite=None
set-cookie: techaro.lol-anubis-cookie-verification=01a0916c-32f6-7472-bbc5-940a1feaa0ec; Path=/; Secure; SameSite=None

Drop the -I to see the challenge page itself, which is titled Making sure you're not a bot!.

Warning

Run the test from a machine outside your server. Requests from the server itself, from Cloudflare, from QUIC.cloud, and from any address in your Trusted ACL skip Anubis silently.

Note

The challenge is served with status 200, not 403. The status code alone tells you nothing—check for the cookies.

The -A "Mozilla/5.0" option matters. Anubis challenges browser user agents; requests from curl and wget using their own default user agent are passed through untouched to avoid breaking automation.

Troubleshooting

If no cookies are returned, work through the following in order:

Test from an external machine

Do not test from the server itself or from any trusted IP addresses.

Set a browser user agent

Verify that -A "Mozilla/5.0" is added to the curl command to set a browser user agent.

Confirm the backend service is running

Run the following:

systemctl is-active anubis@lsanubis.service

If it is not active, start the service with the following command:

systemctl start anubis@lsanubis.service

Check the server-level setting

In the WebAdmin Console, navigate to Configuration > Server > Security > Anubis Proof-of-Work and confirm that Enable Anubis is not set to Disabled.

Check the virtual-host setting

Confirm that LsAnubis on is set for the virtual host you are testing, and restart LiteSpeed Web Server after adding it.