嘟嘟社区

[疑问] 吃灰两年半的甲骨文首尔无了


本帖最后由 mehui 于 2022-8-11 08:38 编辑

昨天收到Netcraft Takedown Service的两封安全提示邮件,机器应该可能是被黑了

  1. Hello,
  2. We have discovered a phishing attack on your network.
  3. hxxps://*****.**/about.php [140.238.*.*]
  4. hxxps://*****.**/session [140.238.*.*]
  5. hxxps://*****.**/login?return_to=https%3A%2F%2Fgithub.com%2Fabout.php [140.238.*.*]
  6. hxxp://*****.**/ [140.238.*.*]
  7. hxxps://*****.**/ [140.238.*.*]
  8. We previously contacted you about this issue on 2022-08-10 03:32:11 (UTC).
  9. Since our last notification, the following additional URL(s) have been detected:
  10. hxxp://*****.**/
  11. hxxps://*****.**/about.php
  12. hxxps://*****.**/login?return_to=https%3A%2F%2Fgithub.com%2Fabout.php
  13. hxxps://*****.**/session
  14. You may not have been aware of this attack, however, you are still responsible for removing it.
  15. This attack targets our customer, GitHub, website URL https://github.com/.
  16. Please remove this fraudulent content, and any other associated fraudulent content, as soon as possible.
  17. Additionally, please keep the fraudulent content safe so that our customer and law enforcement agencies can investigate this incident further once the site is offline.
  18. More information about the detected issue is provided at https://incident.netcraft.com/e6bee1634826/
  19. Kind regards,
  20. Netcraft
  21. Phone: +44(0)1225 447500
  22. Fax: +44(0)1225 448600
  23. Netcraft Issue Number: 34779823
  24. To contact us about updates regarding this attack, please respond to this email. Please note: replies to this address will be logged, but aren’t always read. If you believe you have received this email in error, or you require further support, please contact: [email protected]
  25. This mail can be parsed with x-arf tools. Visit http://www.xarf.org/ for more information about x-arf.

复制代码

半夜收到探针告警,三台机器全部离线,刚刚登录一下后台,结果提示
your account has been disabled due to either tenant/user disable operation.

节哀,一顿火锅没了
最近开始对元老级别的乌龟下手了吗?看到好几个很老的龟就这么没了。
看来我这也没必要去注册这个玩意了
这个邮件看起来是账号 被盗或者被找回了。
还不如卖给我
密钥登录还能被黑啊,用的脚本代码有问题吧。