logoalt Hacker News

BoredPositrontoday at 3:21 PM2 repliesview on HN

It's the third time that I've read something about availability notifications on discord and other chats getting abused for timed attacks in the last few weeks.


Replies

magicalhippotoday at 4:17 PM

After my Wordpress site got hacked way back through an exploit in one of the WP files, I set up a cron job that compared the hash of the static files with expected hash, and would fire off an email if they differed.

The script lived above the web root, so they'd have to escape that to tamper with it, and was generated by another script.

Saved me a couple of times since, well worth the 15 minutes I spent on setting it up.

show 3 replies
Aurornistoday at 7:47 PM

Can you share what those other attacks were? It's helpful to study additional attacks to know what to look for.