I have seen many scan entries on nginx while sharing links on Teams recently. At first I thought its some type of brute force. Even abuseipdb reports categorize it as web attack.

all 3 comments

sorted by: hot top controversial new old
[–] 1 point 9 hours ago

I've built a system for sharing confidential files to customers so that we get to know where they get downloaded to and alerted if something is fetched to more than one location. Had to deal with MS 'preview' accesses in that context. Any wild guesses what triggers my return 444 clause 😁

  • source
  • [–] 11 points 3 days ago* (1 child)

    I don't know any of the technical details behind, but what I've noticed there's at least couple things that seem to happen when you send a link in teams;

    1. Microsoft defender scans that linked site and tries to figure out whether it may be "harmful"
    2. Attempts to scrape the site, render, screenshot it and embed a picture of the site contents to show to the recipient
    3. Replaces the link with defender link that forwards the user to the website

    That link safety thing is probably quite intrusive when scanning the destination webpage

  • source
  • hideshow 1 child comment