New cloud server hit by unsolicited packets in under 4 seconds, experiment reveals
A developer rented a $6 cloud server in Frankfurt and recorded the first unsolicited network packet arriving just 3.77 seconds after the listener went live. Within 75 minutes, the server had logged 1,212 connection events from 84 IP addresses across 15 ports, with the first request targeting a known credential file path within five minutes. The experiment also exposed how different ways of counting the same traffic produce conflicting and misleading conclusions. Ranking by raw event count made SMB appear dominant, while ranking by distinct IPs falsely suggested Postgres attracted the most attackers — both findings were skewed by single operators. Only counting distinct networks yielded a reliable result: HTTPS, HTTP, and SSH drew the broadest range of independent actors.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in