3 ms·
Ok, true. Some clarification is necessary. We get hit everyday by 1-2 intrusion attacks as well as a few DDOS a month...and the intrusion attacks are mostly fr
by globile 9y ago
Ok, true. Some clarification is necessary.
We get hit everyday by 1-2 intrusion attacks as well as a few DDOS a month...and the intrusion attacks are mostly from anonymised address or singled-out ISP IPs...but of the ones that come from Cloud based organisations, 80% or more is Hetzner.
We've never seen attacks from AWS/Google Cloud/Rackspace, etc... but Hetzner shows up in our logs a lot.
- mschuster91 9y ago> but of the ones that come from Cloud based organisations, 80% or more is Hetzner. Probably because people renting servers from Hetzner, OVH and friends run them once and keep them running without upgrading the OS and software which means they will get pwned (and a pwned hexacore server with 1 or 10Gbit gives you pretty good resources compared to an AWS micro instance)... while AWS disincentivizes you from doing so. In addition AWS tries to enforce security with its heavy reliance on security rules, which adds another layer of security - after all no one can hack your mysqld when it's not exposed to the Internet...