3 ms·
I really wasn't bragging about load. Of course 5k requests is nothing. It was mostly to emphasize that those 5k requests would bring at least 5k pieces of malwa
by Test0129 4y ago
I really wasn't bragging about load. Of course 5k requests is nothing. It was mostly to emphasize that those 5k requests would bring at least 5k pieces of malware if I didn't spend the time to stop them.
The guide was missing this which I think cheapens the guide a little to me because security can be a large portion of the cost of a SaaS service you might pay for.
- horsawlarway 4y ago> It was mostly to emphasize that those 5k requests would bring at least 5k pieces of malware if I didn't spend the time to stop them. I feel like this is confusion on your part - do you have a service/port that they are actually making real requests against where there is risk? Ex: Password based ssh access, or something like phpmyadmin running and exposed? Basically - if they're just hitting ssh on port 22... as long as your auth is cert based (or better yet, just not exposed publicly at all) who cares? If they're requesting random paths for wordpress admin sites or something like phpmyadmin... again - who cares? You really don't have to do anything unless you're running those services. I agree you should keep an eye on the logs - but mostly this isn't as big an issue as people tend to make it out to be. Proper auth on your services (ex: keycloak behind mfa) means the risk is just really, really low - and you really aren't worth the serious effort it takes. Basically - A malicious request is NOT equivalent to malware. They can make lots of malicious requests - in practice, all of them just fail.