www.habrahabr.ru zadefaysili ... After the site was returned to normal, the defacer told how he did it, but his post was immediately removed.
In that post, he hinted at the site:
“PS Gentlemen web developers. Be careful.
PPS [img src = " habrahabr.ru/logout?.jpeg "] in a post razloginivaet the user. GET - it is bad.
PPPS Quotes in the [youtube] tag are not filtered. You can write arbitrary attributes -> execute JS-code. "
“A quick analysis showed the following: the attack can be classified as“ intelligent, ”the web service is attacked by requests to generate a random image and looks like:
')
/ captchaa / eckete2rxn2o2gjq for leprosorium.ru
/ captcha / 534nnkcno8mrew2r for dirty.ru
With such an attack, there is no need to generate a large amount of traffic; it is enough to “keep” the web service overloaded.
Obviously, some new player in the same field decided to pin down the "oldies".
As an assumption: recently Bokarev began to actively promote his project netlore.ru, which is the direct competitors of Bashu and Derty
www.telnews.ru/news/detail.php?ID=16200
If he had the audacity to make a book out of other people's jokes, it would be logical now to bang "sources."
Source: https://habr.com/ru/post/288126/
All Articles