"Behind Cloudflare so I don't need a firewall"
Your origin IP leaks — old DNS records, mail headers, SSL cert logs (crt.sh). Once found, attackers hit your IP direct and bypass Cloudflare entirely.
Lock the origin to only accept Cloudflare:
— ufw default deny incoming
— allow only Cloudflare's IP ranges on 443
— pull the list from their published ranges, script a cron to refresh
Now direct hits get dropped at the door. Try it tonight.
Root Access Daily
@RootAccessDaily
"Behind Cloudflare so I don't need a firewall"
Этот пост опубликован в Telegram-канале Root Access Daily. Подписаться можно по ссылке: @RootAccessDaily.