following up on my previous post:

it turns out that, like anything else weird in infrastructure, it was DNS

I registered mydomain.com as my primary router’s domain, re-ran the experiment with a fresh 128 char subdomain, and I received zero scans on the new domain.

Now my question is, who’s making that one query that leaks my domain name? Is it Apache on startup?

One solution is to resolve all my subdomains on /etc/hosts so it never has to leave the box, but I’m curious what a more experienced net admin would suggest.

  • non_burglar@lemmy.world
    link
    fedilink
    English
    arrow-up
    5
    ·
    11 hours ago

    We would need to know your DNS query path and whether you are querying from inside or outside your private IP space. If you are querying against public servers, then that is completely public.

    I registered mydomain.com as my primary router’s domain

    Routers don’t typically deal with dns except to forward requests upstream or hand out server addresses as dhcp options. Can you elaborate what you mean by your “primary router’s domain”?