4 ms·
my guess is internal tool that wasn't expected to be exposed publicly. additionally, i didn't realize there are tools to automatically discover unreferenced su
by davidchang 2y ago
my guess is internal tool that wasn't expected to be exposed publicly.
additionally, i didn't realize there are tools to automatically discover unreferenced subdomains like this. i would have just assumed security by obscurity
- ndriscoll 2y agoPresumably it's from certificate transparency logs. That's one reason I do not use TLS for my personal hosting.
- VTimofeenko 2y agoLet's Encrypt allows issuing wildcards which is what quite a number of folks use for self-hosted services
- duggan 2y agoIf one person learns this lesson it's good. If it's on the public Internet, best to expect it will be found. Stick it behind an auth wall of some sort. I've put internal sites behind AWS ALB's plugged into an OIDC provider[1] (Google), which works well. 1: https://docs.aws.amazon.com/elasticloadbalancing/latest/application/listener-authenticate-users.html https://docs.aws.amazon.com/elasticloadbalancing/latest/appl...