Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


sleemanj

1514 posts

Uber Geek
+1 received by user: 315


#267883 16-Feb-2020 13:28
Send private message

I got an error notification from one of my sites this morning, looking into it was rather odd why that error would occur, and started doing some digging.

 

Some cursory log searching revealed that a returning customer had triggered this error when they were doing a bit of door-handle rattling.  Swapping numbers in the URL to things they didn't have permission to, and what looks like naive searching for SQL injection potential.

 

They were not successful and they certainly did nothing to hide who they were or what they were doing.

 

As I was writing up a report to pass onto the owner's of the site to judge the threat level for the purchase this user had made, I did some googling and the person is supposedly an employee of one of NZ's large telecommunications companies, and both this current order and one some time ago are from the same IP on that company's network (which has a rather dodgy sounding reverse dns), of course that doesn't mean they "did it from work" but it's not a great look.

 

Obviously this, and all my other sites are continuously under a barrage of attempts at exploit like everybody else and on the one hand they didn't do anything that the site shouldn't be able to fend off, but on the other hand this being a local and actual human trying their luck, and potentially associated with their employer, I dunno, it just kinda annoys me more than it perhaps should.  If nothing else it's wasted an hour of my Sunday investigating it.

 

How do others feel about this sort of thing?





---
James Sleeman
I sell lots of stuff for electronic enthusiasts...


Create new topic

This is a filtered page: currently showing replies marked as answers. Click here to see full discussion.

sleemanj

1514 posts

Uber Geek
+1 received by user: 315


  #2421842 16-Feb-2020 15:45
Send private message

skewt:

 

Its also possible they were just searching for vulnerabilities which they would have passed on to the site owner so I wouldn't jump to conclusions that they had bad intentions

 

 

 

 

Certainly possible.  The leetspeak in their reverse DNS gives me pause for thought though.

 

Eh, I've passed my report to the site owner in their hands now, maybe I'll suggest they include a little "thank you" note for "testing" their website ;-)

 

 





---
James Sleeman
I sell lots of stuff for electronic enthusiasts...


Create new topic








Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.