Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Can you elaborate a bit on how you set things up and introduced some security?


Authorised parties have prior knowledge of the subdomains where the apps reside.

Everyone else hitting the IPs directly (presumably coming from mass IP scans) will be met with a honeypot vhost returning nothing.

An example can be found in the nginx manual with the catch-all approach: https://nginx.org/en/docs/http/server_names.html#miscellaneo...


Fantastic, didn’t know that was possible




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: