If you've noticed that the Mastodon stampede DDoS is back, hammering your servers even though you have applied countermeasures -- that's because they CHANGED THEIR FUCKING USER AGENT for no good reason and without telling anybody.
**2024-07-31 23:39:18:** http.rb/5.2.0 (Mastodon/4.3.0-nightly.2024-07-25; +https://mastodon.social/) **2024-08-01 03:41:26:** Mastodon/4.3.0-nightly.2024-08-01 (http.rb/5.2.0; +https://mastodon.social/)
Ok, yes, technically the plans were on display in a toilet with a sign on the door saying "Beware of the Leopard".
Could anyone have possibly have predicted that this would be a problem? I guess we may never know.
Prepend "^Mastodon\/|" to your regexps.
Sigh.
Previously, previously, previously.