Hacker News new | ask | show | jobs
by meowface 4280 days ago
Correct.

Many automated scripts script kiddies use to DDoS will do a basic check for subdomains like "direct.domain.com" and "direct-connect.domain.com" if the target domain is behind Cloudflare, and the scripts are naive and immediately assume that's the server's real IP.

Setting it to the IP of a site they dislike is also a popular choice.