Gary Sellani lists at
Mon Jul 24 12:09:39 UTC 2017

I just detect the use agent and return 444, but every attempt to get a file will show up in your access.log.

I get two or three jorgee "sessions" a day. They tend not to use the domain name but reference your server by IP, so there might be some better blocking scheme. 

The Jorgee malware scanner is creating a lot of activity on my site. I 
would like to rate-limit its connections to nginx based on the 
User-Agent, since blocking all IP addresses with iptables seems 
impossible. Is their a quick way of doing this ?

Thank you in advance ,


Etienne Robillard
tkadm30 at

