"we caught one" god. Luxurious.

Once again, I strongly advise you to set up fail2ban so that anyone you serve a 404 catches at least a full day ban, and if you don't care about talking to other people's services, do your best to fully block the IP ranges associated with all the major hosting companies.

https://exple.tive.org/blarg/2025/10/21/raised-shields/

https://infosec.exchange/@foobardevs/116246141464905287

@mhoye i just checked the logs for a website i run (that gets ~9k pageviews/mo and ~1k MAU), grepping for all 404s - it seems like the vast majority of them are iphones requesting the /apple-touch-icon.png path (and variations thereof). there are also a bunch of "Chrome Privacy Preserving Prefetch Proxy" requesting /.well-known/traffic-advice and various bots trying to get robots.txt. there are definitely some credential scraper/vulnerability finder bots too, but the majority of the 404s I serve are to actual users, so if i implemented this advice i'd block a pretty big chunk of my userbase