RE: https://infosec.exchange/@sans_isc/115265397054651431
This is a really nice write-up on the .well-known directory being abused to drop webshells. This would make for a good hunting rule for Suricata/Snort, so I'll be working on that today.
RE: https://infosec.exchange/@sans_isc/115265397054651431
This is a really nice write-up on the .well-known directory being abused to drop webshells. This would make for a good hunting rule for Suricata/Snort, so I'll be working on that today.
If you have a fediverse account, you can quote this note from your own instance. Search https://infosec.exchange/users/da_667/statuses/115265425625462828 on your instance and quote it. (Note that quoting is not supported in Mastodon.)