Skip to content

Add scenario(s) for commonly probed directories #182

Open
@thansk

Description

@thansk

I have noticed that my VPS constantly gets these directories (and/or subdirectories of these) scanned and it would be awesome if there was a scenario in the hub that bans the IP on the first try.

/vendor/
/console/
/wp-content/
/wp-login.php
/wp-includes
/wp
/wordpress
/jenkins/
/Autodiscover
/solr/
/cgi-bin/
/admin
/boaform
/plus
/laravel
/shell
/cms
/owa
/manager
/phpmyadmin
/pma
/phpunit
/actuator
/mysql
/boaform
/0bef
/config
/?XDEBUG_SESSION_START=phpstorm
/TP
/thinkphp
/GponForm

These aren't sorted in any order.

I've also noticed a lot of CONNECT + {domain}:443 and GET + {url} where the domain and URL lead to a Chinese website.
Examples:

CONNECT www.baidu.com:443 HTTP/1.1
GET http://www.soso.com/ HTTP/1.1

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions