Your WAF is a lovely front door. Such a shame the attackers found the side entrance 

The Abstract ASTRO team have been studying AI attack agents with Eyal Sela & Gambit Security and have found some interesting playbooks. They just blogged about this late yesterday evening.

One small yet interesting piece: a method for finding the real server behind your CDN. They check SPF records, the staging subdomain someone forgot to proxy (oops), and your favicon hash sitting in Shodan. Once they find your origin, they go straight to it and your WAF never gets a vote.

They’re tidy, too. Tools get shredded, logs get scrubbed, and timestamps get backdated before you’ve finished your coffee.

But the nice thing about robots is they’re lazy in very predictable ways. And their cleanup routine reads like a checklist of commands your web server should never run. Thanks for the detection list, guys!

It’s all written up: a script to find your own origin leaks before they do, plus managed detections that fire while the attacker is still on the box (not three days later in a log review).

Homework for this week: does your origin only accept 80/443 from your CDN’s ranges? If you’re not sure, the answer is probably no.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading