Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Wednesday, 27 March 2024

What is the point of these bots endlessly trying utterly random HTTP requests?

I can't be the only one seeing this kind of garbage in my server logs:

"GET /!?asdas1230ds0a=da90sue21qh HTTP/1.1"
"GET /HotelInformation/HotelInformation.aspx?asdas1230ds0a=da90sue21qh HTTP/1.1"
"GET /++?asdas1230ds0a=da90sue21qh HTTP/1.1"
"GET /.cancel?asdas1230ds0a=da90sue21qh HTTP/1.1"
"GET /.specialSubmit?asdas1230ds0a=da90sue21qh HTTP/1.1"
"GET /img.youtube.com?asdas1230ds0a=da90sue21qh HTTP/1.1"
"GET /.droppable/?asdas1230ds0a=da90sue21qh HTTP/1.1"
"POST /.droppable/ HTTP/1.1"
"GET /_isMasked/?iqi_localization_country=x27f&vst=x27f&gitlab=x27f&1111ef1ee11b=x27f&ocxlaarct7tk=x27f&gad_source=x27f&landcode=x27f&confirmPrivacyStatement=x27f&26=x27f&frm_action=x27f…"

This is just a tiny sampling of endless junk that has been going on for at least the past 2 weeks. The last example is abbreviated, it goes on like that, with exactly 100 of those random query parameters that always have the same value “x27f.” It are several bots, which according to an IP locator service come from different countries, mostly the UK and Hong Kong. However, doing a WHOIS on each of the IP addresses reveals that many of them are hosted by Contabo GmbH, a cheap VPS hosting service in Germany.

Something similar has happened years ago, and then the junk also came from Contabo-hosted addresses. The pattern was similar, but each request then looked like the last example shown above, using a ridiculous number of query parameters with different field names but all the same value “z3re”. I filed an abuse report back then, and the junk stopped for a while, but it has been sporadically returning, and now it is back in a slightly different incarnation, but it still makes no sense at all. NONE.

Often these bots will still perform requests with a ridiculous number of parameters (usually 100), but more often they look like the above: a random string with the same damn query string appended to it. I really mean the same damn string for at least 2 weeks straight, which in the above case was obviously produced by someone bashing their keyboard: “asdas1230ds0a” and “da90sue21qh”. The same bot will keep on doing requests with the same base path like “.specialSubmit” or “London” for a whole day, and then might switch to another string for the next day, if I haven't kicked its ass with an iptables DROP in the meantime. The choice of these strings generally makes no sense. Lately they have also started using random characters next to city names and domains or just random words. Most of the time, the strings don't look like anything a real web app would ever use. It is all totally random. The mind boggles.

I really don't understand what is being tried to achieve with this. It is as if they are trying to brute force the internet in the hopes of finding an exploit, but the chances of this strategy producing anything fruitful is negligibly small, especially when not even varying the query parameters. Also, they do only 1 request about every 10 minutes, maybe to try to stay under the radar of suspicious activity detectors (not mine, obviously). At such slow rate, a Monte Carlo approach is just pointless.

I truly cannot grok what could be going in in the mind of whatever crackpot implemented this piece of junk and then decided to pump Kilowatts into a server farm to unleash this nonsense across the internet. If I see this in my logs, then it probably means they do these requests non-stop on whole IP ranges or a list of domains obtained from wherever. All that electricity is wasted on total nonsense. They had better spent the effort on mining crypto. It must take a very special kind of mental deficiency to believe this strategy will yield any return on investment.

Luckily the incomprehensible act of always using the same strings in the request, makes it easy to ban these bots. The set of IP addresses they work from is also pretty stable, so firing up the firewall is a good option as well.

Update 2025-12-11

Nobody else has mentioned those particular “random” strings since I posted the above, hence it was not a case of some security-through-obscurity login like in CVE-2025-14485. The strings now only show up in a Google search as certain URLs that have been indexed with those parameters in their URL, likely because Google picked them up from security reports published online.
The most likely explanation for this phenomenon, is that this particular bot used those fixed strings as a kind of watermark, with the specific intent of being able to recognise them if they showed up somewhere after the “attacks,” maybe in the hopes of then being able to perform more directed attacks. (Or, the author of the bot was indeed just a total nutcase.)

Friday, 11 January 2019

Is ETCV (Ethereum Classic Vision) a scam or not?

Logo shamelessly stolen from ETCV website
There is quite a bit of FUD about the upcoming Ethereum fork, called Ethereum Classic Vision (exchange token ETCV) being a scam like Ethereum Nowa. This Dutch website for instance tries to give some evidence of this claim.

If ETCV is a scam indeed, the authors sure have done a lot of effort to make it less obvious than with Nowa, whose site has spelling errors and makes ridiculous claims about the forked cryptocurrency. The biggest warning light for Nowa is the procedure to supposedly obtain free ‘ETN’ (which by the way is an already existing token for Electroneum, another fact that makes Nowa extremely suspect). They outright ask you to transfer your ETH to their address and those who are even more gullible than that, can even make it worse by sending them their private keys as well. First rule of cryptocurrencies: never give anyone your private key. Second rule… never give anyone your private key!

The Classic Vision website on the other hand looks a lot more legit. It seems the ‘scam’ claims for ETCV are mainly based on two things:
  1. Confusion between the supposed Nowa fork and the ETCV fork. The aforementioned article mentions some facts that appear to originate from the news about Nowa, like the photo models story. This confusion is understandable because the (supposed) dates for these two forks are only 1 day apart.
  2. The idea that you are supposed to enter your ETH wallet private key to claim ETCV. There is some truth about this because there are only two ways to view an ETCV wallet on their website: either through a keystore or by directly entering the private key. Even though the latter seems to violate the First Rule, in this embryonic stage of the new currency with no third-party support yet, it makes some sense that these are the only options. Obviously the smarter option is to use the keystore but when following proper crypto hygiene, there is no risk with directly using the PK either as I will explain below.
The other suspect facts mentioned are that the website lacks certain information like the exact block number for the fork (which is true and pretty annoying), or obvious contact information for the authors. I don't know about you but in this day and age no sane person would spread all their personal details on a website. There seem to be enough contact methods albeit not very direct.

Fork

Proper Forking Hygiene

This leaves the private key issue as the only big source for concern and until I have actually seen the fork happen, I cannot tell whether this concern is warranted. It is perfectly possible they will indeed use any wallet credentials you enter on their website to plunder your ETH wallet instead of handing you free ETCV. However if you treat the fork as follows, there is zero risk of your ETH being stolen:

  1. Create an entirely new ETH wallet using MyEtherWallet or a similar service. You will never use this wallet for anything else than the ETCV claim.
  2. Transfer as much ETH to this wallet as you want to be replicated into 3 times the amount of ETCV (as they promise).
  3. Leave the ETH on this wallet until you're certain the ETCV fork has happened.
  4. Before doing anything else, withdraw all your ETH from the wallet to another wallet.
  5. Now claim the ETCV using the wallet address from step 1.

If this is a true fork, what will happen is that the entire ETH chain state is duplicated into the new ETCV branch. This means any existing wallet addresses that exist for ETH at that point will also be valid wallet addresses for ETCV. Anything that happens with ETH after the fork will have no effect on the ETCV branch and vice versa because they each go entirely their own ways. Hence if you withdraw the ETH from your wallet with private key abc123, the ETCV wallet with the same private key will still contain the amount of coin that existed at the time of the fork (which in this case will be multiplied by 3). And of course if the whole thing was a scam after all and someone obtains your private key after you have emptied your ETH wallet, they cannot steal anything.

Update: It's (Most Likely) a Scam Alright!

Now the fork is supposed to have been performed, how do things look? Pretty bad:

  • Their website has been suspended
  • Before the site disappeared, a highly suspect prompt was added to it to ‘buy’ ETCV by sending ETH directly to a certain address. This prompt contained conflicting information that the ratio of obtained ETCV would be both 50:1 and 1:1. This looks just like a desperate attempt to grab some more ETH before their whole façade collapses.
  • Their wallet site is suspended
  • Their twitter account is suspended
  • News articles about ETCV being a scam are popping up

Although all this is not 100% irrefutable evidence that it's a scam, let's say it is 99.9% evidence. I have to hand it to them, they were a lot more crafty than the Nowa people. They did a lot more effort to make their scheme appear legit. On BitcoinTalk they managed to gather a considerable following and it seems there still are some believers at this moment.

However, I have lost nothing because I have followed the above procedure even though I haven't executed the last step. I'll keep the wallet address just in case we are in that 0.1% and ETCV exists after all, but I don't hold my hopes up high.