It's Been a Year and Georgia.gov Continues to Be Hacked
boehs.org
boehs.org
Assuming you've breached WordPress, and can run arbitrary php, you can produce that kind of result. I think that path is more likely/common.
"The state’s goal is for citizens to lose one million pounds, and httpx://sanyuwu.com/index.php?top-lesbian-dating-sites-pii the website even suggests ways to get the family dog involved. Trainers and nutritionists will be"
Bottom of this page: https://team.georgia.gov/georgia-news/state-parks-fitness-ch...
And this query: https://www.google.com/search?q=site%3Ateam.georgia.gov+viag...
At least this time, it appears to just be a user on some forum, as opposed to something cooked directly into the server
Was this reported to the site owners (https://gema.georgia.gov/get-involved/report-cybersecurity-e...) and appropriate government law enforcement agencies (https://www.cisa.gov/report)?
I do see a call to share other incidents to the blog owner.
Edit: and I’m not sure standard disclosure even applies. I’m just talking about IOCs, not the actual attack vector (which I do not know)
"Responsible" disclosure is anything but.
Asking because I had multiple bad experiences with responsible disclosure, yet I do not believe full (public presumably) disclosure is the right initial path.
(Full disclosure should be done anonymously to prevent the latter from happening anyway)
Some would say a "responsible" disclosure which allows the danger to continue unabated for a year is a greater danger than a public disclosure, which would lead to the danger being fixed.
Seems reckless to me to not even _try_ responsible disclosure. You don't have to wait a year. But at least give a chance for the problem to be solved before you make it common knowledge.
:)
It's the 90% of the time, when it doesn't work, that's the problem.
Full disclosure might have short-term negatives for _companies_ involved but is best for customers/users as it allows them to evaluate and implement their own mitigations as early as possible. It's the only truly ethically consistent way to operate.
One can see the results by searching google for the domain and the "gold" string from the article.
curl -i -H 'Referer: google.com' https://team.georgia.gov/medicicnes/kamagra-gold-100/
HTTP/1.1 301 Moved Permanently
Date: Fri, 26 Apr 2024 12:36:14 GMT
Server: Apache/2.4.6 (CentOS)
X-Powered-By: PHP/7.4.33
Location: https://gomylink.site/vkKXXr8G?sub1=kamagra-gold-100&sub2=team.georgia.gov
Connection: close
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8Google says it's against their policy but plenty of sites do that. Plenty of sites let their paywalls down just for GoogleBot to the ranked in search but real users have to pay.
Some sites don't load ad crap to show GoogleBot how fast they are.
We should all become GoogleBot.