Congratulations,
Dumbass

> cat /var/log/your-failures.log_

A very special round of applause for 172.71.151.152 for their valiant — and entirely unsuccessful — attempt to compromise our systems. We truly couldn't have done it without you. Well, actually we could. We did. You failed.

We Might Not Know Where You Live, But...

Did you think you were anonymous? That's adorable. Here's what we know about you:

IP Address 172.71.151.152
Country United States
Region Washington
City Seattle
ISP / Org Unknown
Timezone Unknown
Coordinates 47.6109, -122.3303

Your Digital Fingerprint

Nice browser you've got there. It'd be a shame if someone… logged it.

Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:133.0) Gecko/20100101 Firefox/133.0
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36

Your Hall of Shame

Every single one of your pathetic attempts, lovingly preserved for posterity. Spoiler alert: they all failed.

Attack Breakdown

16
Server-Side Request Forgery
16
Total Failed Attempts

Detailed Activity Log

# Timestamp Attack Type Method Target URI Detail
1 2026-03-27T08:26:15Z Server-Side Request Forgery GET /blog/honeypots-explained ssrf [HEADER][HTTP_X_FORWARDED_FOR] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
2 2026-03-27T08:26:18Z Server-Side Request Forgery GET /blog/honeypots-explained ssrf [HEADER][HTTP_X_FORWARDED_FOR] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
3 2026-03-27T08:26:25Z Server-Side Request Forgery GET /blog/honeypots-explained ssrf [HEADER][HTTP_X_FORWARDED_FOR] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
4 2026-03-28T08:50:56Z Server-Side Request Forgery GET /blog/honeypots-explained ssrf [HEADER][HTTP_X_FORWARDED_FOR] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
5 2026-03-31T08:44:29Z Server-Side Request Forgery GET /blog/honeypots-explained ssrf [HEADER][HTTP_X_FORWARDED_FOR] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
6 2026-03-31T08:44:32Z Server-Side Request Forgery GET /blog/honeypots-explained ssrf [HEADER][HTTP_X_FORWARDED_FOR] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
7 2026-03-31T08:44:36Z Server-Side Request Forgery GET /blog/honeypots-explained ssrf [HEADER][HTTP_X_FORWARDED_FOR] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
8 2026-04-01T08:56:12Z Server-Side Request Forgery GET /blog/honeypots-explained ssrf [HEADER][HTTP_X_FORWARDED_FOR] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
9 2026-04-01T08:56:15Z Server-Side Request Forgery GET /blog/honeypots-explained ssrf [HEADER][HTTP_X_FORWARDED_FOR] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
10 2026-04-02T08:56:23Z Server-Side Request Forgery GET /blog/honeypots-explained ssrf [HEADER][HTTP_X_FORWARDED_FOR] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
11 2026-04-03T08:43:00Z Server-Side Request Forgery GET /blog/honeypots-explained ssrf [HEADER][HTTP_X_FORWARDED_FOR] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
12 2026-04-05T09:08:58Z Server-Side Request Forgery GET /blog/honeypots-explained ssrf [HEADER][HTTP_X_FORWARDED_FOR] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
13 2026-04-05T09:09:00Z Server-Side Request Forgery GET /blog/honeypots-explained ssrf [HEADER][HTTP_X_FORWARDED_FOR] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
14 2026-04-08T06:14:20Z Server-Side Request Forgery GET /blog/honeypots-explained ssrf [HEADER][HTTP_X_FORWARDED_FOR] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
15 2026-04-09T16:41:56Z Server-Side Request Forgery GET /blog/honeypots-explained ssrf [HEADER][HTTP_X_FORWARDED_FOR] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i
16 2026-06-13T14:37:38Z Server-Side Request Forgery GET /blog/honeypots-explained ssrf [HEADER][HTTP_X_FORWARDED_FOR] matched /(?:127\.0\.0\.[01]|0\.0\.0\.0|localhost|::1|\[::1\])/i

In Summary

You came. You saw. You got absolutely owned by a hedgehog.

Every request you made was detected, logged, and laughed at. Our WAF didn't even break a sweat. Maybe next time try something more challenging — like reading a book on operational security.

Pro tip: If you're going to hack a cybersecurity company, maybe don't use the same IP address for every single request. Just a thought.