Rubicund wrote:
nasomi wrote:
The web server is behind cloudflare and the game servers are all behind vps's protected by magic transit. The issue is the attacker is finding the true ip of the server somehow, allowing them to attack it directly. This is not something additional hardware can mitigate or manage, as by the time the attack traffic is at the front door, it's to late. Which means something, somewhere is not being protected. It's just a matter of finding out what that is. And I will find it eventually.
Hopefully not exposed certificates

Master Opsec!
Good luck Nas - I know you'll find it and I am betting it's something simple that was overlooked.
^^It's either this, he's exposing the cert like you mentioned, or the attacker has the DNS records which some companies track/keep and you can lookup and/or buy. I'm leaning towards the second, that someone got ahold of the webserver IP through a third-party. Not too hard to do or purchase.