#workers.dev spam

8 messages · Page 1 of 1 (latest)

storm dragon
#

My workers are receiving a lot of spam lately on the workers.dev routes. Should they be disabled or is there a better way to handle it?

rigid merlin
#

Disabling is the best way.

#

It is because bots scrape the certification issue list so they see the ones issued to your dev domain

storm dragon
#

Ok, thanks. That was my guess. I could not see the FQDN in the TLS certificate. But maybe I looked in the wrong place.

storm dragon
#

The TLS certificate does not contain the FQDN. So somebody thought about this but then something happend.

untold swift
storm dragon
#

Yes, that is my conclusion too. So, the FQDN is not in the public certificate. But then there is an ordering process... Maybe the theory is a wild goosechase but somehow bots are finding the FQDN for my workers.