Earlier quoted context omitted.
>You're spending time trying to annoy attackers that you should probably just ignore. s/ignore/block at firewall-level/ To me this article is of relevance nonetheless because It inspires me for messing with AI trainers by crafting an html page ZIP bomb full of ZIP-bomb-like embedded attachments (stylesheets, images, etc).
I use fail2ban for this. I know what my servers run (and it's never PHP, Python microsoft/AD sharepoint etc, because I don't have services in these languages or systems) so I simply fail2ban everything that matches these broad items. Access "wp-admin"? Ban. Try "cron.php" ban. Looking for "phpmyadmin"? ban. It works reasonably well. These bots can switch to other IPs, or try again after the jailtime is lifted (20 min…
By the way, I have mine set to block for 12 hours, and some still come back. I suppose what I should look into is some sort of progressive extension to the delay.