5 ms·
Get a letsencrypt cert, I always get a massive wave of vulnerability probers after renewing.
by hamdingers 2mo ago
Get a letsencrypt cert, I always get a massive wave of vulnerability probers after renewing.
- esseph 2mo agoBecause your certificate shows up in the global chain, which triggers all kinds of automated things including bots
- mmh0000 2mo agoIt's all TLS certs, because they show up in the Transparency Log[1] You can watch a live stream of it here: https://bencevans.io/security/certificate-stream https://bencevans.io/security/certificate-stream [1] https://en.wikipedia.org/wiki/Certificate_Transparency https://en.wikipedia.org/wiki/Certificate_Transparency
- doubled112 2mo agoI use subdomains and a wildcard cert to partly obfuscate this.
- RulerOf 2mo agoI do the same, but I switched from cert-per-subdomain a couple of years ago. They're either using Passive DNS logs or a historical dataset.
- unethical_ban 2mo agoWhen I stood up some sites last year, I used codenames for the subdomains thinking I was obfuscating a little. I didn't know about the transparency logs until months later.
- martyvis 2mo agoTIL about Certificate Transparency (they didn't teach that in security school)
- bigbuppo 2mo agoYeah... you have to remember to setup and fully secure the site before LE certs are issued or you're going to have a bad time. Learned that the hard way when I popped a couple dozen wordpress sites in one go.
- technion 2mo agoOn one hand yes, but on the other hand just configuring your server to refuse connections by IP address rather than server name seemed to drop roughly half the bots I ever see.