#fuckcloudflare

7 posts· Last used Jul 25

RE: https://infosec.exchange/@nyanbinary/116890396714552353 Somewhat as a companion piece: An... experimental bot I wasn't able to push out in time: @fuckeduprefs_bot@infosec.exchange . I have no idea if it actually works but I kinda need to test this in prod so... well, at least it's posting Unlisted :neobot_giggle: It checks for new references* since the last run and then checks for various issues: malformed URLs (to a degree, unfortunately what qualifies as a well-formed URL is quite ... permissive)DNS-level unavailabilityHTTP-level unavailabilityHTTP 5xx statuses While the bot respects robots.txt checking for 404 isn't feasible, given the tendency of some providers to still 404 bots they allow under their robots.txt ( #fuckCloudflare ). The bot almost certainly also has stability issues & will almost certainly produce FPs & I am not even sure it will "catch" anything ever. So, uh, not sure it's worth to follow rn :neobot_giggle:
Quoting
New blogpost: A little detour from the CVE linkrot: What if we just made up the references in the first place? https://blagh.nyanbinary.de/posts/look-ma-im-a-cve-reference/ Tldr: For about 3 years a portion (<10% or so) of MITRE CVE records contained references of ... beyond questionably quality, including multiple hundred completely bogus domains.
Open quoted post
0
0
0
1
Cloudflare is protecting a booter. Then rather than stop the criminals from leveraging Cloudflare infra, they sold their protection to the victim. How is this even legal? We all know it's been happening at smaller scale but even with a high profile extended attack like Ubuntu has been dealing with, their response is "LOL. Fuck you. Pay me." #fuckCloudflare
78
24
82
2
You've seen all posts