You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
safe1ine
changed the title
[建议] 在443端口默认使用自签名SSL证书,防止IP泄露
[SUGGESTION] Use a self-signed SSL certificate on port 443 by default to prevent IP leakage.
Jul 9, 2024
背景与遇到的问题
如果WAF部署在Cloudflare等CDN产品之后,并希望隐藏自己的IP以此防止针对性的DDOS攻击,那么现在雷池443端口的SSL证书可能会泄露WAF所在服务器的IP。例如被censys扫描到证书。
建议的解决方案
在443端口默认使用自签名SSL证书,防止IP泄露
The text was updated successfully, but these errors were encountered: