4 ms·
> If you're counting blocked attempts in logs, you're counting attempts that were never going to succeed. By your own logic, if the problematic traffic shares
by fivea 5y ago
> If you're counting blocked attempts in logs, you're counting attempts that were never going to succeed.
By your own logic, if the problematic traffic shares the same geographic origin and you only happen to spot failed attempts, blocking all traffic from the same geographic origin would also block potentially successful attempts.
And I agree with the OP: there's an awful lot of malicious traffic sharing a common geographical origin. If you ever felt curious, just launch a cheap VM and setup a web server to listen to traffic and log any connection attempt. You don't even need to host a site. In no time you'll start to see your VM being hit by all sorts of web scrapers and security vulnerability scanners.