Search
Items tagged with: threatintel
Wild ass day in the Tor node operator world. Got an email from my VPS, forwarding a complaint from WatchDog CyberSecurity saying that my box was scanning SSH ports!
> Oh no, oh no, I knew I should have set up fail2ban, oh god why was I so lackadaisical!
So I remote in to the machine: no unusual network activity, no unusual processes, users, logins, command history, no sign that anything is doing anything I didn't tell it to do.
So what's up? Turns out there's been a widespread campaign where some actor is spoofing IPs to make it look like systems running Tor are scanning port 22: forum.torproject.org/t/tor-rel…
Operators from all over are saying they're getting nastygrams from their VPS providers because WatchDog is fingering their source IPs (which are being spoofed and NOT part of a global portscanning botnet).
@delroth did an amazing writeup of the whole thing here: delroth.net/posts/spoofed-mass…
#tor #infosec #cybersecurity #threatintel #privacy
[tor-relays] Tor relays source IPs spoofed to mass-scan port 22?
It would be hard to explain to Verizon I run Tor relays since they technically don't allow servers. I hope I'm not forced onto AT&T Internet Air as my particular co-op rental unit won't let met get Spectrum even when other units can, not that I wante…Tor Project Forum
Lottie-Player saga playing out here: github.com/LottieFiles/lottie-…
3 new versions were published today but the threat actor infected them. Appears to be a stolen token.
Malicious code in Lottie-Player CDN files · Issue #254 · LottieFiles/lottie-player
after i use https://unpkg.com/@lottiefiles/lottie-player@latest/dist/lottie-player.js or https://cdn.jsdelivr.net/npm/@lottiefiles/lottie-player@2.0.5/dist/lottie-player.min.js This popup opens on ...GitHub
Lottiefiles Lottieplayer JavaScript library has been compromised forum.lottiefiles.com/t/the-pr…
Somebody also made the first change to the GitHub repo for months 10 minutes ago, reasons unclear.
You may want to proxy block *.web3modal.org
The problem of someone else's popup appearing
Hello, when I connect this link https://unpkg.com/@lottiefiles/lottie-player@latest/dist/lottie-player.js via cdn ( when i add this link to my website), the following popup begins to appear on the site.Let's talk Lottie