No domain, nothing hosted
[Note: the compromised third-party domain shown in this video was redacted from this page after publication; the site operator is a victim, not the attacker.] A web server with no domain name and nothing hosted attracted scanners targeting four unrelated product ecosystems within two hours of starting. One scanner's User-Agent was a URL identifying the WordPress site it was hunting.
No domain name, nothing hosted. The first scanner arrived twenty-nine minutes and eight seconds later.
No DNS record, no published service — effectively invisible. The access log disagrees.
Twenty-seven requests by eleven fifty-three UTC, every one a four-oh-four.
Four hits on a Hikvision camera endpoint. Two on the WordPress admin install page. One request used method MMQP — an MQTT broker handshake sent to a web port. Four product ecosystems, one bare IP.
Two lines with a URL as their User-Agent, pointing at a compromised site whose name is redacted here. Different Cloudflare nodes, one hour forty-four minutes apart.
Scanners don’t need to discover an address first. Every reachable IP gets probed by product category. No DNS name is not a security posture.
An unregistered IP is not a firewall. Restrict what you don’t want touched.
#linux#security#webserver#nginx#honeypot
❯ An unregistered IP is not a firewall. Restrict what you don't want touched.