# Our own additions to the bad-user-agents list — merged into the # http-bad-ua parser by bin/gen-bad-ua.py after Mitchell Krogza's list # (data/bad_user_agents.regex.txt, MIT, replaced whole by # bin/update-data.sh; this file is ours and survives an update). # One entry per line, in the same shape: a regex fragment, \b anchors, # escaped spaces. For clients seen on our own hosts and not upstream # yet — none at the moment: wp2shell (the REST-batch WordPress exploit # tool of 2026-08) is upstream already, and the exploit tools that # deserve an INSTANT ban are named in parsers/http-scanner-ua.yaml.