Hacker News new | past | comments | ask | show | jobs | submit login

Authorised parties have prior knowledge of the subdomains where the apps reside.

Everyone else hitting the IPs directly (presumably coming from mass IP scans) will be met with a honeypot vhost returning nothing.

An example can be found in the nginx manual with the catch-all approach: https://nginx.org/en/docs/http/server_names.html#miscellaneo...




Fantastic, didn’t know that was possible




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: