3 ms·
Yes, sitewide SSL. The site is [redacted]. Affected files are: https://[redacted].s3.amazonaws.com/js/scripts_2017-05-28-17-17-45_www.min.js.gz https://[redac
by benp84 9y ago
Yes, sitewide SSL. The site is [redacted].
Affected files are:
https://[redacted].s3.amazonaws.com/js/scripts_2017-05-28-17-17-45_www.min.js.gz https://[redacted].s3.amazonaws.com/js/scripts_2017-05-28-17...
https://[redacted].s3.amazonaws.com/js/scripts_2017-05-28-18-01-25_www.min.js.gz https://[redacted].s3.amazonaws.com/js/scripts_2017-05-28-18...
According to "last modified" timestamps, the first was modified 7 minutes after upload, the second 2.4 days later.
- JBReefer 9y agoIt sounds like something automated broke into your s3 account, added it mindlessly to .js files, and moved on.
- benp84 9y agoThat's my impression too, because no one would manually add plain text JS to a .gz file, but wouldn't that imply that someone has broken into so many AWS accounts that they needed a script to hack them all!?
- JBReefer 9y agoI hope not, but that may be occurring. I would check your access history/see what users have touched it, and I would certainly contact Amazon.