Je suis ultra choqué ! Ils se prennent pour Google ou quoi ?
- 3 posts
- 5 comments
I recently started seeing a bunch of probably malicious requests (probing for wordpress plugins on my lemmy host) coming from Cloudflare IP addresses. I do use Cloudflare for my nameservers, but the records are set to DNS only (not Proxy).
These requests all come from a Cloudflare IPv4, with 2a06:98c0:3600::103 as the X-Forwarded-For header, which VirusTotal also attributes to Cloudflare. There is nothing else in the X-Forwarded-For chain.
Does anyone know what is going on or have any hypothesis ?
Et le blog a même un flux RSS : https://sansdependances.fr/rss.xml
No Stupid Questions@lemmy.world•Is there a site where I can upload about 600gb to 1tb worth of files for free or on the cheap side and reliant? As a backup incase hardware problems?bypcouy@lemmy.pierre-couy.fr
12 daysI’m uploading my encrypted backups to backblaze
Fediverse@lemmy.world•Tesseract dev injects malicious code into browser to illegally DDOS the dbzer0 instancebypcouy@lemmy.pierre-couy.frEnglish
2 monthsYeah, I could see a credential stealer being smuggled into an alternative frontend…
Fediverse@lemmy.world•Tesseract dev injects malicious code into browser to illegally DDOS the dbzer0 instancebypcouy@lemmy.pierre-couy.frEnglish
2 monthsI did not follow this drama, and I don’t know about this list everyone is mentioning. Is this something that hides specific users posts and comments from the Tesseract UI ?
Fediverse@lemmy.world•Tesseract dev injects malicious code into browser to illegally DDOS the dbzer0 instancebypcouy@lemmy.pierre-couy.frEnglish
2 months“Apparently only three people who aren’t me actually want a place that’s not just a circle-jerk of rage and hate.”
I think this is the best part of their message






I got a bunch of them : 104.23.166.79 , 141.101.76.149 , 108.162.238.148 (this one gave me
waild-fedi-reachwith an unreachable URL as its user agent, and hit legit paths on my lemmy), 104.23.170.65 , 172.71.182.22 , 104.23.172.96 , 172.71.182.234. It’s only 2 hits/day, but this seems weird. What’s weird as well is that all it does is keep trying to hit/wp-content/plugins/woocommerce/readme.txton the same couple of subdomains (except for that one waild-fedi-reach user agent)