what could be the reason for an amazon ip in my nginx access.log file?

3.88.16.48 - - [11/Nov/2023:19:20:07 -0300] "GET / HTTP/1.1" 200 615 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36"

https://www.abuseipdb.com/check/3.88.16.48

  • multidollar@alien.topB
    link
    fedilink
    English
    arrow-up
    1
    ·
    10 months ago

    I once had a Senior Infrastructure Engineer looking at the logs of our public VPN host. A VPN host that is open to the world on 0.0.0.0/0 because that’s the requirement we had. This Engineer saw thousands of failed login attempts to the VPN; things like admin/admin admin/password1 etc. Regular internet crap, a bot will scrape the web page and try its luck then move on.

    This person then decided to initiate security breach procedure and immediately shut down the VPN, because “we’d been hacked!”.

    There’s a lot of noise on the internet. The challenge is working out the best way to isolate your resources just enough and block anything that doesn’t need access. This is why things like Web Application Firewalls exist.