Apropos of defense. In my last blog post, I mentioned that poisoned URLs got the bots that evaded the rest of my defenses.
Thing is, if I blocked poisoned URLs, like I did during the big wave the other day, the chart would look very different.
Like the attached image.
Poisoned URLs are by far the most effective ruleset I have. The only reason they don't show up on @iocaine's daily charts is because I wanted to see the others, so I ordered these last.
If I were going for best performance, I'd put this first, and would perhaps simply disconnect them with Caddy, without serving them anything. I don't do that, because I'm collecting logs and metrics. It makes me feel warm and fuzzy that they fail so miserably.
What I'm trying to say here is: serve them garbage. Serve them poisoned URLs. And even when they come back with real browsers, they will be hitting the poisoned URLs, and you'll be able to tell them to sit on a cactus.