Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Detect that a site got hacked (having a list of known payloads that are put on hacked websites) #551

Open
kazet opened this issue Sep 28, 2023 · 4 comments

Comments

@kazet
Copy link
Member

kazet commented Sep 28, 2023

No description provided.

@RasenRhino
Copy link
Contributor

just to be clear, you want to compare it with payloads like, say OWASP Cheat Sheets? like you somewhat scrape the site to see that right?

@kazet
Copy link
Member Author

kazet commented Mar 22, 2024

I am not sure whether OWASP cheat cheets are a good direction. I was rather thinking of detecting victims of e.g. https://www.bleepingcomputer.com/news/security/new-balada-injector-campaign-infects-6-700-wordpress-sites/ or https://github.com/projectdiscovery/nuclei-templates/blob/3fcda12c44c235e09586fd929c37fa60fbe28f71/http/miscellaneous/defacement-detect.yaml#L4

@RasenRhino
Copy link
Contributor

so why not add this nuclei template ?

@kazet
Copy link
Member Author

kazet commented Mar 31, 2024

I think this template has two drawbacks:

  • it performs a significant number of HTTP requests,
  • it has a significant risk of FPs (e.g. any occurence of TangoDown causes the template to match).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants
@kazet @RasenRhino and others