- 9 Posts
- 58 Comments
I love this! Super fun!
I so want to see how you depict Yggdrassyl, though, the very first and only distro released by Linus himself
BonkTheAnnoyed@lemmy.blahaj.zoneOPto
Selfhosted@lemmy.world•How are people discovering random subdomains on my server?English
81·17 days agoWell, the good news is that I at least think I’m doing all the right things.
I’ll spin up a new VM tomorrow and start from scratch.
BonkTheAnnoyed@lemmy.blahaj.zoneOPto
Selfhosted@lemmy.world•How are people discovering random subdomains on my server?English
4·17 days agoIt’s literally just a VM hosting Apache and nothing else.
BonkTheAnnoyed@lemmy.blahaj.zoneOPto
Selfhosted@lemmy.world•How are people discovering random subdomains on my server?English
4·17 days agoI mean, it could be… I’ll try it with a 128 char base 52 name and see what happens
BonkTheAnnoyed@lemmy.blahaj.zoneOPto
Selfhosted@lemmy.world•How are people discovering random subdomains on my server?English
2·17 days agoYes, exactly. Super weird, shouldn’t happen. I wonder if I have a compromised box somewhere…
BonkTheAnnoyed@lemmy.blahaj.zoneOPto
Selfhosted@lemmy.world•How are people discovering random subdomains on my server?English
13·17 days agoThe random name is not in the public log. Someone else suggested that earlier. I checked CRT.sh and while my primary domain is there, the random one isn’t.
BonkTheAnnoyed@lemmy.blahaj.zoneOPto
Selfhosted@lemmy.world•How are people discovering random subdomains on my server?English
4·17 days agoPrevious experiments, yes, I sent a request. The random one, no.
BonkTheAnnoyed@lemmy.blahaj.zoneOPto
Selfhosted@lemmy.world•How are people discovering random subdomains on my server?English
3·17 days agoAs expected, it doesn’t show up. I had a couple of other subdomains configured before I switched to wildcard, but nothing matches the random one
BonkTheAnnoyed@lemmy.blahaj.zoneOPto
Selfhosted@lemmy.world•How are people discovering random subdomains on my server?English
19·17 days agoWill do!
BonkTheAnnoyed@lemmy.blahaj.zoneOPto
Selfhosted@lemmy.world•How are people discovering random subdomains on my server?English
9·17 days agoShows up by name in the apache other_hosts…log, so yes
BonkTheAnnoyed@lemmy.blahaj.zoneOPto
Selfhosted@lemmy.world•How are people discovering random subdomains on my server?English
5·17 days agoNope, but that’s a good suggestion. I set this one up brand new for the experiment.
BonkTheAnnoyed@lemmy.blahaj.zoneOPto
Selfhosted@lemmy.world•How are people discovering random subdomains on my server?English
13·17 days agoMostly from AWS or the like, with occasional Chinese and Russian origins.
The scans look like requests to various WordPress endpoints, JavaScript files associated with known vulnerabilities etc
BonkTheAnnoyed@lemmy.blahaj.zoneOPto
Selfhosted@lemmy.world•How are people discovering random subdomains on my server?English
2·17 days agoEven with a wildcard cert?
BonkTheAnnoyed@lemmy.blahaj.zoneOPto
Selfhosted@lemmy.world•How are people discovering random subdomains on my server?English
6·17 days agoYeah, this is interesting, I’ll dig more into this direction.
But the randomly generated subdomain has never seen a DNS registrar.
I do have *.mydomain.com registered though…hmmm
BonkTheAnnoyed@lemmy.blahaj.zoneOPto
Selfhosted@lemmy.world•How are people discovering random subdomains on my server?English
3·17 days agoNope
BonkTheAnnoyed@lemmy.blahaj.zoneOPto
Selfhosted@lemmy.world•How are people discovering random subdomains on my server?English
12·17 days agoI don’t have any subdomains registered with DNS.
I attempted
dig axfr example.com @ns1.example.comreturned zone transfer DENIED
BonkTheAnnoyed@lemmy.blahaj.zoneOPto
Selfhosted@lemmy.world•How are people discovering random subdomains on my server?English
3·17 days agoYep. They show up in the other_hosts…log
BonkTheAnnoyed@lemmy.blahaj.zoneOPto
Selfhosted@lemmy.world•How are people discovering random subdomains on my server?English
3·17 days agoI don’t think so? I have a letsencrypt wildcard cert, and reference that in the relevant .conf
BonkTheAnnoyed@lemmy.blahaj.zoneto
Technology@lemmy.world•200 million records exposed in massive Pornhub data breach — here’s what we know so farEnglish
251·20 days agoRelease the pornhub files!


That’s handy – thanks!