I’ve got plenty of unidentified traffic now couple of days. This time I had finnish speaking friends mostly from Kazakhstan and Netherlands. Something like Custom-AsyncHttpClient was quite easy to block, but there was others too, whos user agent wasn`t too easy to filter. Sure, they create an error code, and grep using that data is trivial.
But they have IP and I do geo-blocking. I’m kind of missing web-server level blocking, but because those aren’t making that much load (WordPress would be another story) I’m way too lazy to build up a reverse proxy. But I was wondering could we get one log more: countries? There is MaxMind in use so could we use it a bit wider? That would make blocking few steps easier.