4 ms·
Every server with port 80/443 open has thousands of hits a day from random boxes looking for wordpress login pages. The only new thing is that they're pretendin
by yabones 2mo ago
Every server with port 80/443 open has thousands of hits a day from random boxes looking for wordpress login pages. The only new thing is that they're pretending to be a different type of annoying bot. There's a new layer of sophistication and subterfuge, but it's the same junk traffic we've always dealt with.
- gavinhking 2mo agoAnother interesting thing here is the paths they're targeting, many are for newish AI coding tools
- thedougd 2mo agoPeople or their agents must be accidentally committing or publishing their repository level secrets and configs with enough regularity that it’s worth scanning.
- gavinhking 2mo agoTotally. I'm sure this campaign was inspired by sloppy vibe coding
- lw18511811620 2mo ago[flagged]
- hluska 2mo agoThere are a few novel ones but I’ve been seeing most of them in my logs for longer than generative AI has existed. This isn’t remotely new, the vector is just getting bigger.
- drewnick 2mo agoThink about how many webmaster and business owners' egos are stroked by all the traffic they are getting, when in actuality they are often just serving thousands of bots.
- andai 2mo agoI was insulted recently reading about the apparently thousands of hits per second the rest of you guys are getting. Even the bots are shunning me!
- 0xdeadbeefbabe 2mo agoI don't even have a domain name and I'm getting lots of hits.
- xplt 2mo agoOld and busted: serverless New hotness: DNS-less
- 0xdeadbeefbabe 2mo agoYeah it's even superior to smol web in some circles. It's not that much longer than a phone number.
- inigyou 2mo agoAh yes my phone number is 2602 1337 ABCD CAFE 3542 77FF FE12 3456 See? It's quite short.
- voidUpdate 2mo agoSome people still use ipv4
- jasonjayr 2mo agoI recently brought up a website on a never-before-seen .com domain. Within about 10 mins of bringing it up with a SSL certificate, Anthropic came knocking on the door requesting the front page. (Almost certainty due to them watching the Public Certificate Transparency logs)
- TZubiri 2mo agoOpening port 80 and realizing the world is an anarchic warzone is a canonic rite of initiation for otherwise innocent backend devs and sysadmins.
- manapause 2mo agoThis is so true. Every junior sysadmin I have trained over the years (including myself) has had a “are we being attacked?!” moment when tasked with WAF report analysis, monitoring fail2ban logs, etc. Monitoring WAN traffic really gets the paranoia juices flowing.
- iwontberude 2mo agoI remember when you could stand up a website and no bots would scrape it or scan it. It was a lovely time. No one had firewalls or antivirus and things were working fine until the worms and viruses started coming. You could be confident that your guests were real, so much so we had guest counters on many public sites.
- dylan604 2mo agoRemember when you had to submit a request for google to scan your site?
- TZubiri 2mo agoYou still can. Just build your website yourself as deep in the stack as you can instead of piling up 50 abstractions on top of each other. Some decisions like having your page be accessible by IP can only happen if you use technology like generic http servers (like apache or nginx) from the 2000s instead of implementing the lower stacks and actually thinking about whether that makes sense for a second. If when you build a website or a backend, your server responds to requests by IP address (for example), you are building a bottom 90% product, and considering most software markets are super top-heavy, (say 1% win), that's ngmi land.
- iwontberude 2mo ago
- Colegno 2mo agoI am always surprised that its considered legal. IMO that's the same as going on the street door by door and checking if one is left open to steal everything inside the house...
- sethops1 2mo agoUnauthorized access is not legal, it's just not enforced in the slightest.
- xena 2mo agoIllegal and actively enforced are different things. Report it to the hosting company originating the abuse and they usually don't care.
- inigyou 2mo agoYou can also make up fake reports to the hosting companies that do care, to terminate their customers at random.
- fultonn 2mo agoThat sort of vulnerability scanning is at best legally dubious, and almost certainly illegal under CFAA and similar state statues when there's clear criminal intent. That's why the 2022 DOJ guidance regarding non-prosecution good faith security research was such a big deal at the time. > IMO that's the same as going on the street door by door and checking if one is left open to steal everything inside the house... From experience: this does happen regularly in some neighborhoods of some cities in the US, and even that isn't always an enforcement priority. So lack of enforcement on the internet, where most the perpetrators probably aren't even in a jurisdiction with an extradition treaty, isn't exactly surprising.
- linkregister 2mo ago[dead]
- inigyou 2mo ago
- deaton 2mo agoMost servers with port 25565 open get hits from either Minecraft griefer bots, or from a bot that looks for that port and warns anyone on that server about the risks of leaving that port open. It doesn't take a huge scale operation to spam every IPv4 address in the world, there are only 2^32 of them, and even then many of those addresses are reserved.
- inigyou 2mo agoThere's just two or three such operations btw.
- cpburns2009 2mo agoExactly this. It's no different from a bot pretending to be Googlebot. I've tried reporting abusive IPs to various foreign hosts, but nothing every comes to it. I've settled for just blacklisting excessively abusive IP ranges.
- tommica 2mo agoWhat is your way of detecting them? Just cat your way through your logs?
- sgc 2mo agofail2ban
- cpburns2009 2mo agoAlmost lol: grep, sort and uniq. If I notice someone is hammering my employer's ecommerce site, I'll block them. It isn't required often so I've been reluctant to spend the time setting up fail2ban.
- tommica 2mo agoIs it a multi-server setup? If so, do you ssh into each machine and look at the logs?
- cpburns2009 2mo agoIt's 3 servers so it's not too much hassle to ssh into them and check it manually.
- what 2mo agoGoogle (and other “legitimate” scrapers) publish the ip ranges they crawl from, anyone claiming to be googlebot (or whatever) but not in the ip range can safely be black holed.
- deleted 2mo ago[deleted]
- somat 2mo agoYeah, It started bothering me enough that I recently put together a system where when a application detects a bad actor(a bot enumerating too fast, a random scan for vulnerabilities, etc) it notifies the firewall. Right now I am just shutting them down, But have plans for a honeypot/tarpit system, something real slow that takes up all their time. Something like "have fun at 300 baud"
- ThePinion 2mo agoI'm doing the same thing. Set up a honeypot API and having it log everything anything tries to access outside that home page. Collected 15,000 hits in a week from 300 unique IPs doing the usual WordPress and .env scans. I'm just collecting the data now to be used to secure some of my upcoming projects, but I would absolutely also like to take it in a direction where it sends the bots into an infinite slow loop, or preferably something that burns as many tokens as possible for them. I don't really care about the morality of that. I'm a big fan of fighting fire with fire.
- infinite_spin 2mo ago> something real slow that takes up all their time Not to throw water on your plan, but the bots I've written intentionally run very slow with respect to each target. When done in parallel, across a wide range of targets, it doesn't slow down the effort at all.
- imglorp 2mo agoServe them a zip bomb? LLM poison text?
- bigbuppo 2mo ago[dead]
- dvduval 2mo agoI don’t really have a reason to use WordPress anymore. I’m about halfway through switching my site over to something else that I can control with github and AI. Now these boats are mostly getting static files unless there’s a reason to show something else and even then the footprint is very small. There’s just not that much to hack.
- ruperthair 2mo agoI've done the same by scraping the HTML/JS/CSS off our own Wordpress site and sticking it in S3 (behind CloudFront, of course). It was a mild hassle at the time, but would take seconds with today's LLMs. It was a great decision and has been no hassle since, as we didn't really need a CMS, it was just the default for the person who did our design.
- newHempter 2mo agoDefinitely gotten worse from where I'm standing — you used to be able to just filter on the UA string and move on, now you can't even trust that. Same junk traffic, but harder to sweep away.
- ryukoposting 2mo agoIf I had a nickel for every time my blog gets a reuqest probing some wordpress exploit, I'd have paid off my student loans years ago.
- Frieren 2mo agoNumbers say that the number of attacks are increasing: https://radar.cloudflare.com/security/application-layer?dateRange=52w https://radar.cloudflare.com/security/application-layer?date...
- GoblinSlayer 2mo agoWhere do you think all the AI investment goes? They expand AI data centers.
- Izmaki 2mo agoYes, probably, and when a new web-related CVE drops the number of attacks targeted that CVE increases too. It's just the new orange...