Dear Azure IP address,
-
Dear Azure IP address,
please stop requesting a.php and other php files. The Mastodon BSD Cafe domain won't serve them, you're just wasting power and polluting the planet.
Thank you,
Stefano -
Dear Azure IP address,
please stop requesting a.php and other php files. The Mastodon BSD Cafe domain won't serve them, you're just wasting power and polluting the planet.
Thank you,
Stefano@stefano that's exactly what someone using a.php to serve secrets would say.
-
Dear Azure IP address,
please stop requesting a.php and other php files. The Mastodon BSD Cafe domain won't serve them, you're just wasting power and polluting the planet.
Thank you,
Stefano@stefano I've seen this stupid crap. wtf! really.
-
@stefano that's exactly what someone using a.php to serve secrets would say.
@mms of course 😆
-
Dear Azure IP address,
please stop requesting a.php and other php files. The Mastodon BSD Cafe domain won't serve them, you're just wasting power and polluting the planet.
Thank you,
Stefano@stefano For a long while I've added IP's requesting *.php files (along with a bunch of other suspicious things) to a pf table I block.
-
Dear Azure IP address,
please stop requesting a.php and other php files. The Mastodon BSD Cafe domain won't serve them, you're just wasting power and polluting the planet.
Thank you,
Stefano@stefano I bet they are requesting .env and .conf too.
-
Dear Azure IP address,
please stop requesting a.php and other php files. The Mastodon BSD Cafe domain won't serve them, you're just wasting power and polluting the planet.
Thank you,
Stefano@stefano i have a rule for crowdsec and block everybody requesting php on my static blog
-
@stefano I've seen this stupid crap. wtf! really.
@indyradio @stefano it's a vulnerability scanner. There's a lot of broken php out there, and someone is looking for low hanging fruit. If you don't run php, putting a fail2ban rule in for requests for php files is a pretty reasonable thing to do. It's on my todo list.
-
@indyradio @stefano it's a vulnerability scanner. There's a lot of broken php out there, and someone is looking for low hanging fruit. If you don't run php, putting a fail2ban rule in for requests for php files is a pretty reasonable thing to do. It's on my todo list.
@overeducatedredneck @stefano
I hate that. I also have some ancient php running behind a reverse proxy. The dickheads try to abrogate the proxy. They are not scanning the internet as a favor to you, as you well know. -
@overeducatedredneck @stefano
I hate that. I also have some ancient php running behind a reverse proxy. The dickheads try to abrogate the proxy. They are not scanning the internet as a favor to you, as you well know.@indyradio @stefano They're usually looking for a few different products: old wordpress, old phpmyadmin and a few other things. If there's one or more you don't use, add those paths to trigger the autoblock.
And yeah, as someone who does defensive infosec, they aren't trying to make the world a better place.
-
@indyradio @stefano They're usually looking for a few different products: old wordpress, old phpmyadmin and a few other things. If there's one or more you don't use, add those paths to trigger the autoblock.
And yeah, as someone who does defensive infosec, they aren't trying to make the world a better place.
@overeducatedredneck @stefano I should do that, I've been doing it manually.
-
@stefano I bet they are requesting .env and .conf too.