Live data from Hacker News

When internal hostnames are leaked to the clown

rachelbythebay.com

1–10 of 265 posts

Re: When internal hostnames are leaked to the clown

#8

I don’t understand. How could a GCP server access the private NAS? I agree the web UI should never be monitored using sentry. I can see why they would want it, but at the very least should be opt in.

It said knocking, not accessing

also

> you notice that you've started getting requests coming to your server on the "outside world" with that same hostname.

Re: When internal hostnames are leaked to the clown

#10
This highlights a huge problem with LetsEncrypt and CT logs. Which is that the Internet is a bad place, with bad people looking to take advantage of you. If you use LetsEncrypt for ssl certs (which you should), that hostname gets published to the world, and that server immediately gets pummeled by requests for all sorts of fresh install pages, like wp-admin or phpmyadmin, from attackers.
Post reply on HN