3 ms·
I think you misunderstood about his scripts; his primary source of data is from acquiring the domain the malicious scripts were hosted on and he wrote scripts t
by foolmeonce 6y ago
I think you misunderstood about his scripts; his primary source of data is from acquiring the domain the malicious scripts were hosted on and he wrote scripts to summarize the server logs of his previously malicious CDN.
He knows the script URL and referrer URL of each attempt to invoke the malicious scripts. The URLs of the scripts seem to include the token to configure them to the attacker.
He visited sites in the referrers and looked them up in search only to do tests to convince himself that the pages are clean and the servers aren't conditionally returning the malicious content, etc.