From testing, I see a lot of traffic from Tor exit nodes. Apparently, these nodes are brute forcing SSH servers and trying to forward their exit node traffic through exposed SSH servers over the internet.
We should implement the Tor exit node list (https://check.torproject.org/torbulkexitlist) and have an option to block traffic from here. Additionally, we should add a flag to the DB if it is a tor exit node.
The connection depicted also accessed pornographic content (on a popular, legal pornographic website), but I am not going to share the HTTP response from that.
Issue Summary
From testing, I see a lot of traffic from Tor exit nodes. Apparently, these nodes are brute forcing SSH servers and trying to forward their exit node traffic through exposed SSH servers over the internet.
We should implement the Tor exit node list (https://check.torproject.org/torbulkexitlist) and have an option to block traffic from here. Additionally, we should add a flag to the DB if it is a tor exit node.