Congratulations,
Dumbass

> cat /var/log/your-failures.log_

A very special round of applause for 104.28.201.73 for their valiant — and entirely unsuccessful — attempt to compromise our systems. We truly couldn't have done it without you. Well, actually we could. We did. You failed.

We Might Not Know Where You Live, But...

Did you think you were anonymous? That's adorable. Here's what we know about you:

IP Address 104.28.201.73
Geolocation data unavailable — but don't worry, we're still watching.

Your Digital Fingerprint

Nice browser you've got there. It'd be a shame if someone… logged it.

Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/64.0.3282.119 Safari/537.36
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36
Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36

Your Hall of Shame

Every single one of your pathetic attempts, lovingly preserved for posterity. Spoiler alert: they all failed.

Attack Breakdown

1
General Fuzzing / Forced Browsing
40
Server-Side Request Forgery
41
Total Failed Attempts

Detailed Activity Log

# Timestamp Attack Type Method Target URI Detail
1 2026-06-27T18:49:44Z General Fuzzing / Forced Browsing GET /uploads/crest-pentest-logo.avif Forced browsing attempt: /uploads/crest-pentest-logo.avif
2 2026-07-26T23:24:05Z Server-Side Request Forgery GET /blog/configuring-ufw-on-ubuntu-for-a-web-server-a-step-by-step-guide ssrf [HEADER][HTTP_USER_AGENT] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
3 2026-07-29T07:34:05Z Server-Side Request Forgery GET /blog/wifi-penetration-testing-of-companies ssrf [HEADER][HTTP_USER_AGENT] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
4 2026-07-30T23:03:39Z Server-Side Request Forgery GET /blog/this-week-in-cybersecurity-13-september-2024 ssrf [HEADER][HTTP_USER_AGENT] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
5 2026-08-05T04:22:54Z Server-Side Request Forgery GET /blog/anatomy-of-a-breach-panama-papers ssrf [HEADER][HTTP_USER_AGENT] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
6 2026-08-10T02:54:44Z Server-Side Request Forgery GET /blog/anatomy-of-a-breach-mariposa-botnet ssrf [HEADER][HTTP_USER_AGENT] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
7 2026-08-10T04:26:21Z Server-Side Request Forgery GET /blog/anatomy-of-a-breach-twitch ssrf [HEADER][HTTP_USER_AGENT] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
8 2026-08-10T09:19:17Z Server-Side Request Forgery GET /blog/metasploit-deep-dive-exploitation-framework ssrf [HEADER][HTTP_USER_AGENT] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
9 2026-08-13T02:34:24Z Server-Side Request Forgery GET /blog/difference-between-a-penetration-test-and-a-vulnerability-scan ssrf [HEADER][HTTP_USER_AGENT] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
10 2026-08-15T03:15:15Z Server-Side Request Forgery GET /blog/sector-under-the-microscope-aerial-uav-security ssrf [HEADER][HTTP_USER_AGENT] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
11 2026-08-17T07:10:40Z Server-Side Request Forgery GET /blog/anatomy-of-a-breach-imperva ssrf [HEADER][HTTP_USER_AGENT] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
12 2026-08-18T02:20:06Z Server-Side Request Forgery GET /blog/anatomy-of-a-breach-credential-stuffing-epidemic ssrf [HEADER][HTTP_USER_AGENT] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
13 2026-08-18T05:35:47Z Server-Side Request Forgery GET /blog/understanding-pass-the-hash-attack-how-hackers-exploit-password-vulnerabilities ssrf [HEADER][HTTP_USER_AGENT] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
14 2026-08-18T07:37:10Z Server-Side Request Forgery GET /blog/muddywater ssrf [HEADER][HTTP_USER_AGENT] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
15 2026-08-18T17:04:40Z Server-Side Request Forgery GET /blog/penetration-testing-vs-red-teaming-differences ssrf [HEADER][HTTP_USER_AGENT] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
16 2026-08-19T09:59:27Z Server-Side Request Forgery GET /blog/anatomy-of-a-breach-hbo-hack ssrf [HEADER][HTTP_USER_AGENT] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
17 2026-08-20T05:01:10Z Server-Side Request Forgery GET /blog/anatomy-of-a-breach-stuxnet ssrf [HEADER][HTTP_USER_AGENT] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
18 2026-08-20T07:14:05Z Server-Side Request Forgery GET /blog/anatomy-of-a-breach-capital-one ssrf [HEADER][HTTP_USER_AGENT] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
19 2026-08-20T08:25:35Z Server-Side Request Forgery GET /blog/salt-typhoon ssrf [HEADER][HTTP_USER_AGENT] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
20 2026-08-21T19:25:08Z Server-Side Request Forgery GET /blog/apt12-the-prcs-cyber-operative ssrf [HEADER][HTTP_USER_AGENT] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
21 2026-08-21T23:17:54Z Server-Side Request Forgery GET /our-team/ ssrf [HEADER][HTTP_USER_AGENT] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
22 2026-08-23T00:51:33Z Server-Side Request Forgery GET /our-team/ ssrf [HEADER][HTTP_USER_AGENT] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
23 2026-08-23T00:51:35Z Server-Side Request Forgery GET /our-team/ ssrf [HEADER][HTTP_USER_AGENT] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
24 2026-08-23T07:12:48Z Server-Side Request Forgery GET /blog/what-are-tarpits ssrf [HEADER][HTTP_USER_AGENT] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
25 2026-08-23T15:28:37Z Server-Side Request Forgery GET /blog/anatomy-of-a-breach-dyn-mirai ssrf [HEADER][HTTP_USER_AGENT] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
26 2026-08-23T22:42:15Z Server-Side Request Forgery GET /our-team/ ssrf [HEADER][HTTP_USER_AGENT] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
27 2026-08-24T03:45:47Z Server-Side Request Forgery GET /blog/anatomy-of-a-breach-diginotar-ca ssrf [HEADER][HTTP_USER_AGENT] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
28 2026-08-26T02:06:23Z Server-Side Request Forgery GET /our-team/ ssrf [HEADER][HTTP_USER_AGENT] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
29 2026-08-26T02:06:24Z Server-Side Request Forgery GET /our-team/ ssrf [HEADER][HTTP_USER_AGENT] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
30 2026-08-27T12:22:48Z Server-Side Request Forgery GET /blog/anatomy-of-a-breach-linkedin ssrf [HEADER][HTTP_USER_AGENT] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
31 2026-08-27T23:37:50Z Server-Side Request Forgery GET /our-team/ ssrf [HEADER][HTTP_USER_AGENT] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
32 2026-08-28T10:05:39Z Server-Side Request Forgery GET /blog/from-the-hacker-desk-lift-reconnaissance-platform ssrf [HEADER][HTTP_USER_AGENT] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
33 2026-08-29T00:08:52Z Server-Side Request Forgery GET /our-team/ ssrf [HEADER][HTTP_USER_AGENT] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
34 2026-08-29T00:08:53Z Server-Side Request Forgery GET /our-team/ ssrf [HEADER][HTTP_USER_AGENT] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
35 2026-09-05T00:45:00Z Server-Side Request Forgery GET /services/penetration-testing/automotive-penetration-testing/ ssrf [HEADER][HTTP_USER_AGENT] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
36 2026-09-07T11:50:21Z Server-Side Request Forgery GET /blog/anatomy-of-a-breach-2024-year-review ssrf [HEADER][HTTP_USER_AGENT] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
37 2026-09-07T21:19:34Z Server-Side Request Forgery GET /blog/privilege-escalation-explained ssrf [HEADER][HTTP_USER_AGENT] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
38 2026-09-08T01:13:50Z Server-Side Request Forgery GET /services/penetration-testing/automotive-penetration-testing/ ssrf [HEADER][HTTP_USER_AGENT] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
39 2026-09-08T19:42:38Z Server-Side Request Forgery GET /blog/snowden-nsa-leak-deep-dive ssrf [HEADER][HTTP_USER_AGENT] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
40 2026-09-09T07:46:52Z Server-Side Request Forgery GET /blog/anatomy-of-a-breach-operation-aurora ssrf [HEADER][HTTP_USER_AGENT] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
41 2026-09-09T09:40:01Z Server-Side Request Forgery GET /blog/anatomy-of-a-breach-operation-aurora ssrf [HEADER][HTTP_USER_AGENT] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i

In Summary

You came. You saw. You got absolutely owned by a hedgehog.

Every request you made was detected, logged, and laughed at. Our WAF didn't even break a sweat. Maybe next time try something more challenging — like reading a book on operational security.

Pro tip: If you're going to hack a cybersecurity company, maybe don't use the same IP address for every single request. Just a thought.