3 ms·
From my experience are these contents only provided once per IP and then you're getting filtered to not get any content again, to prevent 'easy' detection of th
by recentdarkness 13y ago
From my experience are these contents only provided once per IP and then you're getting filtered to not get any content again, to prevent 'easy' detection of this.
You simply get blacklisted after the first serving
- deefour 13y agoI've seen this sort of thing from the Darkleech apache module[1]. It also won't show the malicious Javascript to any IP that appears in the `last` log. It looks like php.net uses Apache too[2]. The easiest way I've seen to find the module (they come with a variety of names) is to do something like strings /path/to/modules/* | grep -i blacklist [1] http://malwaremustdie.blogspot.com/2013/03/the-evil-came-back-darkleechs-apache.html http://malwaremustdie.blogspot.com/2013/03/the-evil-came-bac... [2] http://builtwith.com/php.net http://builtwith.com/php.net
- muraiki 13y agoYeah, I ran across malware once that only injected JS for visitors from certain referrers, such as Google search. I believe the intention was so that when someone would tell me, "Hey, you have a bunch of weird links on your site" I would go to it directly and not see a problem. IIRC the .htaccess had been modified.