GREPWISE

The scanner that announces its own address

Seventy-nine requests in one week arrived with a url in the client name field instead of a client name, and the url points at the setup page of a content management system on somebody else's site. The scan is running from a machine that was taken over during its own installation and never cleaned up, and a misconfigured tool leaks that address into every request it sends. The site name is masked here because the operator is a victim, not the attacker.

Seventy-nine requests this week arrived carrying the address of the machine that sent them.

Every request names the client that made it. Browsers put their version there. Tools put their name. It is the one field nobody validates.

These seventy-nine did not put a name there. They put a link, and it points at the setup page of a content management system on a completely unrelated site.

We have masked which site, because whoever runs it is a victim here, not the attacker.

That is the whole story in one field. A site was taken over while it was still being installed, never finished, never cleaned up, and now scans strangers on somebody else’s behalf. The tool doing it leaks the address of its own host in every request it sends.

Half-finished installs do not sit still and wait for you. They get adopted.

Finish the install. An unfinished setup page is an open door.

#linux#security#selfhosted#infosec#sysadmin

❯ Finish the install. An unfinished setup page is an open door.

cd ..