RFI Attacks

Suspected Attacks 463125

[Details]


Job ads in HTTP headers?!

Seems I was running wireshark in the background while writing the past post. Looks like the WordPress folks are recruiting!

My post:
POST /wp-admin/admin-ajax.php HTTP/1.1
Host: realsecurity.wordpress.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1
Accept: */*

The reply:

HTTP/1.1 200 OK
Server: nginx
Date: Thu, 04 Sep 2008 01:53:02 GMT
Content-Type: text/html; charset=utf-8
Connection: close
X-hacker: If you’re reading this, you should visit automattic.com/jobs and apply to join the fun, mention this header.
Content-Encoding: gzip
Vary: Accept-Encoding

Content-Length: 22

Share

Leave a Reply

 

 

 

You can use these HTML tags

<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>