GREPWISE

No domain, nothing hosted

[Note: the compromised third-party domain shown in this video was redacted from this page after publication; the site operator is a victim, not the attacker.] A web server with no domain name and nothing hosted attracted scanners targeting four unrelated product ecosystems within two hours of starting. One scanner's User-Agent was a URL identifying the WordPress site it was hunting.

No domain name, nothing hosted. The first scanner arrived twenty-nine minutes and eight seconds later.

No DNS record, no published service — effectively invisible. The access log disagrees.

Twenty-seven requests by eleven fifty-three UTC, every one a four-oh-four.

Four hits on a Hikvision camera endpoint. Two on the WordPress admin install page. One request used method MMQP — an MQTT broker handshake sent to a web port. Four product ecosystems, one bare IP.

Two lines with a URL as their User-Agent, pointing at a compromised site whose name is redacted here. Different Cloudflare nodes, one hour forty-four minutes apart.

Scanners don’t need to discover an address first. Every reachable IP gets probed by product category. No DNS name is not a security posture.

An unregistered IP is not a firewall. Restrict what you don’t want touched.

#linux#security#webserver#nginx#honeypot

❯ An unregistered IP is not a firewall. Restrict what you don't want touched.

cd ..