Skip Navigation
Jump
Attempting to understand what happened when a strange login page shows up on a subdomain I host, and I would like some input/suggestions
  • Here’s what I think happened: Everything you see is something you did.

    The subdomain you host points to your IP … or at least it did. Your ADSL IP address has changed and your domain is now pointing at someone else’s IP as their ADSL has claimed it.

    Ping the subdomain and see the IP address. Now go to https://whatismyipaddress.com/ and see what your IP address is. They’re different now, right?

    2
  • Jump
    Exposing self-hosted services to internet for self-use only
  • Getting an obscure domain name doesn’t matter as attackers go straight to the IP address. If you have a certificate on your secret domain name, they have your domain the moment they hit port 443.

    Don’t use “security through obscurity”; instead just secure your services or host a VPN.

    1