2 ms·
The objective here is to give script kiddies and other spray-and-pray attackers the finger.
by ryan-c 2y ago
The objective here is to give script kiddies and other spray-and-pray attackers the finger.
- phoronixrly 2y agoHow does it do that though? You light up in a skid's Internet-wide scan for let's say Redis. They try and fail to dump anything from it so they proceed and run a vulnerability scanner on your host (skids gonna skid)... It proceeds to discover IDK... a trivial SQLi you coded like a dumbass...
- rvba 2y agoThey try to run some other attack on you. For something you dont have. If more servers use the tool, they waste attacker's time. A bit like herd immunity
- anyfoo 2y agoIt’s literally an arms race. You make it more expensive for attackers to progress. Yes, security through obscurity is bad on its own, but it’s not necessarily useless as an additional measure. For a similar concept, look at the delay you get after entering a password wrong to a login prompt: That technically does not add any barrier whatsoever, but it does make it much harder for an attacker to brute force the password.