playground.shen.id
Unsolicited traffic, live

Background radiation

The time between this site's TLS certificate being validated and the first request from someone who was never told it exists, measured from this machine's own access log.

This hostname was never published, linked or submitted anywhere. It became public the instant its certificate was issued, because every certificate a public CA signs is written to Certificate Transparency logs: append-only, publicly auditable records that exist so mis-issued certificates can be detected. CT is a security feature, and a good one.

The second-order effect is that the logs double as a live directory of every new name on the internet. Anyone can stream them, and some of the people streaming them scan each new hostname within seconds, hunting for exposed credentials, admin panels and unpatched software before the owner has finished setting up.

Everything below is that traffic arriving at this box, as it happens. A request qualifies as uninvited on either of two grounds: it asks for a path nothing here links to, or the client identifies itself as software rather than a browser. A browser loading a real page is neither, so you are not in this feed.

Exposure statistics

Uninvited requests nobody was sent here by a link
Distinct networks unique networks that have touched this box, after masking
Requests seen every request, invited or not, since the service started
First contact waiting for the first probe

Live probe feed

connecting

Waiting for the first snapshot.

    Addresses are truncated to a /24 (IPv4) or /48 (IPv6) before they are ever stored, so nothing here points at a person. Crawlers that name themselves — search engines, AI scrapers, monitoring services — show up asking for real pages, which is why you will see successful requests alongside the 404s.

    What the uninvited asked for

    Top user-agents