Two scanners in one request
Ten requests arrived carrying a repository directory, a colon, a port number and then the path of an internal service - a cluster manager on one port, a dashboard login on another. As a request it is meaningless: a port in the middle of a path is just text. Two probe lists were concatenated instead of being tried separately, which means the tool was never checked against a single response. It is a small window into how much scanning runs completely unattended.
This request cannot possibly work, and it still arrived ten times.
It is tempting to picture a person behind a scan, watching what comes back and deciding what to try next.
Four distinct paths, ten requests. Each begins with a repository directory, then a colon, then a port number, then the path of an internal service. A cluster manager on one, a dashboard login on another.
That address is nonsense. A port number belongs before the path, not inside it. As written, it is just a filename containing a colon.
Two probe lists were joined together instead of being tried one after the other. Nobody looked at a single reply, or the mistake would have been obvious immediately.
Most of what reaches you was never aimed. It is a list being replayed, and you are on the list because you answer.
Assume the scan is automatic. Assume nobody read the reply.
#linux#security#selfhosted#infosec#sysadmin
❯ Assume the scan is automatic. Assume nobody read the reply.