Hey, that's not my server!
ID: ad323767-bb84-5afe-8316-b3b537a45500
STIX ID: report--ad323767-bb84-5afe-8316-b3b537a45500
Feed Name: Censys Blog
Date Published: 2025-03-11
Date Updated: 2026-04-27
Author: Jean Pierre Ruiz Ocampo; Mark Ellzey; Senior Security Researcher
This Censys report explains that CDNs and transparent proxies can serve legitimate TLS certificates on bare IP addresses when clients send a null SNI, allowing unrelated hosts to appear legitimate. The author demonstrates how an attacker or misconfigured proxy can forward traffic to CDN infrastructure (preserving TLS handshakes) and documents an analysis searching Akamai certificates on non-Akamai hosts, finding roughly 7,000 instances of 1:1 proxying—behavior that can be a benign quirk of the Internet or a tactic used to mask malicious infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
