←back to thread

545 points mmh0000 | 1 comments | | HN request time: 0.001s | source
Show context
VladVladikoff ◴[] No.43573068[source]
Wait a sec… if the TLS handshakes look different, would it be possible to have an nginx level filter for traffic that claims to be a web browser (eg chrome user agent), yet really is a python/php script? Because this would account for the vast majority of malicious bot traffic, and I would love to just block it.
replies(4): >>43573098 #>>43573360 #>>43574581 #>>43574731 #
1. jrochkind1 ◴[] No.43574731[source]
Well, I think that's what OP is meant to avoid you doing, exactly.