Expanded DNSArchive to also add web headers, CMS versions, links , css files, etc.
You can now search for it here (in beta):
https://t.co/rCGTnOGpHD
Ex:
All sites using PHP/5.2:
https://t.co/Zcv3HUNdBa
And you can still do DNS specific search here:
https://t.co/moYeBHcQWI
Feedback welcome!
Have you noticed this "?slince_golden=test" requests on your logs?
It is for a WordPress Backdoor. We wrote a small summary about it here:
https://t.co/amKL6NL0is
Seeing it on your logs too?
Application layer DDoS attacks mimic user traffic to exhaust resources. Learn how to detect and defend against them. #CyberSecurity#DDoS#WebSecurity
https://t.co/NfjhRbenrn
Protocol DDoS attacks exploit network vulnerabilities to disrupt services. Learn how to protect your systems. #DDoS#CyberSecurity#NetworkProtection
https://t.co/RcvJtcEP6M
Volumetric DDoS attacks flood bandwidth with traffic, disrupting services. Learn how to defend against them. #DDoS#CyberSecurity#WebProtection
https://t.co/afuKGXsgQo
Understanding DDoS attacks and how to mitigate them is key to protecting your website. Explore strategies and solutions. #CyberSecurity#DDoS
https://t.co/MfbO0gVndT
Arbitrary Code Execution (ACE) allows attackers to run malicious code. Learn how to prevent this critical threat! #CyberSecurity#InfoSec#CodeExecution
https://t.co/4o6GZo2ewW
SQL Injection (SQLi) is a major security risk. Learn its types, impacts & prevention tips with secure coding & WAFs. #CyberSecurity#SQLi#WebSecurity#DataProtection
https://t.co/XnkeoMREPz
Protect your domain emails from phishing & spoofing! Learn SPF, DKIM, DMARC & more for email security. Start now: https://t.co/TetCxNehWE #CyberSecurity#EmailSecurity#TechTips
Learn how registries, registrars, and DNS power the internet. Gain insights and take control of your domain. #DNS#DomainManagement#TechTips
https://t.co/b6wVuNcZCY
WAFs and CDNs safeguard against protocol DDoS attacks by filtering traffic and dispersing loads. Learn how they protect your site. #DDoS#WebSecurity#CDN
https://t.co/puOFO9QjA3
Via our Honeypot feature you can now sinkhole the IP automatically via the WAF. You can also be sneaky and customize the responses so the bad actor doesn't know they've been blocked, allowing them to continue their tactics with no impact to you.
These scans are fingerprinting your application, looking for things that exist that could be exploitable. We would consider these strong indicators of malicious intent. Needless to say, there is no need to allow them to continue.