• Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
  • Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!

test please delete

Collapse
This is a sticky topic.
X
X
  •  
  • Filter
  • Time
  • Show
Clear All
new posts

    I visit ripe.net and enter the miscreant's IP address as shown in the logs...

    Code:
    organisation:    ORG-[redacted]-RIPE
    org-name:        businesscom2
    org-type:        OTHER
    address:         Yerevan
    address:         Armenia
    e-mail:          [redacted]@bcsatellite.net
    It appears to belong to a cable and satellite company in Armenia

    Comment


      An examination of my WordPress installation shows nothing untoward, and the database appears to contain no other nasties.

      Also, no other edits or posts have been made to the site that aren't from an IP address I use.

      I conclude, after once again checking with the debugging proxy, that I have eradicated the problem.

      But...

      how did they get in?

      Comment


        i hate it when you get snow in your boots

        Comment


          Off to wordpress.org and check the documentation.

          Sure enough, my cookie is all that is needed to log in as me.

          And how would somebody else get my cookie?

          Comment


            Repeat after me: XSS

            Or, to give it its full title, a cross-site scripting vulnerability.

            Comment


              Morning DS

              Comment


                At some point, I had visited a site which contained a XSS thingy which was able to steal a copy of my WordPress cookie and send it to the evil Armenian. He then modified one of my posts to embed hidden nastiness in my site (and, as it happened, in one of the most popular articles on my site).

                Comment


                  Originally posted by NickFitz View Post
                  Morning DS
                  morning nickfitz. and your website is?

                  Comment


                    right. time for some breakfast. marmite on toast and another cup of coffee.

                    Comment


                      Now I'm sure you're all saying "Right, porn" at this stage... but recent research by Google showed that much of this stuff is on normal sites too.

                      Take that site that you found in a search that had some seven-years-out-of-date, never-updated information.

                      Once upon a time, that page had a counter at the bottom - one of those things you used to see that said


                      You are visitor
                      0000NaN
                      Counter supplied by cute-web-counter.net

                      Comment

                      Working...
                      X