WordPress : Beaucoup d’attaque par injection aujourd’hui ( wordfence_logHuman=11111111111111′ UNION SELECT ).

J’ai donc bloquer les IP :

91.189.41.165 (Sweden) / 96.125.162.13 (United States) . Cela change des Russes …

Les attaques : 

  • 91.189.41.165 (Sweden)     Blocked for SQL Injection in query string: wordfence_logHuman=11111111111111′ UNION SELECT CHAR(45,120,49,45,81,45),CHAR(45,120,50,45,81,45),CHAR(45,120,51,45,81
  • 96.125.162.13 (United States)     Blocked for SQL Injection in query string: wordfence_logHuman=11111111111111′ UNION SELECT CHAR(45,120,49,45,81,45),CHAR(45,120,50,45,81,45),CHAR(45,120,51,45,81

Mise à jours du 26/12/2018 :

  • décembre 26, 2018 7:50   72.1.219.230 (Canada)     Blocked for SQL Injection in query string: wordfence_logHuman=11111111111111″ UNION SELECT CHAR(45,120,49,45,81,45),CHAR(45,120,50,45,81,45),CHAR(45,120,51,45,81
  • décembre 26, 2018 7:44   173.249.53.80 (Germany)     Blocked for SQL Injection in query string: wordfence_logHuman=11111111111111″ UNION SELECT CHAR(45,120,49,45,81,45),CHAR(45,120,50,45,81,45),CHAR(45,120,51,45,81
  • décembre 26, 2018 7:38   173.212.196.158 (Germany)     Blocked for SQL Injection in query string: hid=657FB0DBB2C8282D149D6F927F316FF0″ or (1,2)=(select*from(select name_const(CHAR(111,108,111,108,111,1

Mise à jours du 03/01/2019 :

  • janvier 2, 2019 11:42 213.251.182.111 (France)     Blocked for SQL Injection in query string: pg=rec99999″ union select unhex(hex(version()))
  • janvier 2, 2019 9:50 83.222.27.75 (Russian Federation)     Blocked for SQL Injection in query string: lang=de99999″ union select unhex(hex(version()))
  • janvier 2, 2019 9:45   103.251.25.60 (India)     Blocked for SQL Injection in query string: lang=de1111111111111″ UNION SELECT CHAR(45,120,49,45,81,45),CHAR(45,120,50,45,81,45),

Le site de Nice-Matin est une usine à Malware

En fait si on suit les rebonds pour arriver au Malware :

Etape n°1 : Nice Matin : https://www.nicematin.com .

Etape n°2 : https://caribiancpm.com/ .

Etape n°3 : https://advertisingfeed.com/ .

Etape n°4 :  http://update.flash.com.ih0jvagfs9j24trgaenzoq5svbduua.space/ : Malware aléatoire …

Merci Nice-Matin !

Quand je regarde tous les domaines sur la pages d’accueil :

  • nicematin.com
  • nougat.net
  • pulpix.com
  • rubicomproject.com
  • facebook.com
  • googletagservices.com
  • googleanalitycs.com
  • daylimotion.com
  • buzzfeed.com
  • outbrain.com
  • googlesindication.com
  • aticdn.com
  • acpm.fr
  • dmcdm.net
  • adsafeprotected.com
  • doubleclick.net
  • privacy-center.org
  • charbeat.net
  • laplacemedia.com
  • alooma.com

C’est sans fin … Misère, un vrai bordel.

Une bonne raison pour ne pas proposer du Javascript et pour bloquer le Javascript

Lien

Le lien : https://www.01net.com/actualites/un-code-javascript-suffit-pour-savoir-quels-sites-web-vous-visitez-1572207.html .

Des chercheurs ont montré que l’on pouvait espionner la navigation d’un Internaute en observant l’utilisation de la mémoire cache. A l’heure actuelle, il n’existe aucun moyen pour parer ce type d’attaque.