Webshells Hiding in .well-known Places https://isc.sans.edu/diary/32320
If you have a fediverse account, you can quote this note from your own instance. Search https://infosec.exchange/users/sans_isc/statuses/115265397054651431 on your instance and quote it. (Note that quoting is not supported in Mastodon.)
RE: https://infosec.exchange/@sans_isc/115265397054651431
This is a really nice write-up on the .well-known directory being abused to drop webshells. This would make for a good hunting rule for Suricata/Snort, so I'll be working on that today.
