
The Attack from Within
I created an aggregator for brute force login attacks across a number of websites I own. As the site approaches two years, the leaderboard is dominated by Digital Ocean IP addresses. If you have a single IP address with over 100K attacks being issued from it, you'd think a circuit breaker would trip somewhere in the monitoring stack.
The Irony? Each of the sites reporting they were being brute forced are ALSO hosted on Digital Ocean Droplets!! The firewall rules of the attacked droplets only allow port 443 access through CloudFlare meaning this is not happening on internal IP addresses. Hence, the title of this post The Attack from Within!