• stevedidwhat_infosec@infosec.pub
    link
    fedilink
    arrow-up
    27
    ·
    edit-2
    4 months ago

    For anyone interested - I’d you are using umatrix to block shit you can punch these lines into a new text file and import as blocklist, then commit it with the tiny arrow that points left toward the permanent list to save it permanently:

    * www[.]googie-anaiytics[.]com * block

    * kuurza[.]com * block

    * cdn[.]polyfill[.]io * block

    * polyfill[.]io * block

    * bootcss[.]com * block

    * bootcdn[.]net * block

    * staticfile[.]org * block

    * polyfill[.]com * block

    * staticfile[.]net * block

    * unionadjs[.]com * block

    * xhsbpza[.]com * block

    * union[.]macoms[.]la * block

    * newcrbpc[.]com * block

    Remove the square brackets before saving the file - these are here to prevent hyperlinks and misclicks.

    Edit: this is not a bulleted list, every line must start with an asterisk, just in case your instance doesn’t update edits made to comments quickly.

    Edit2: added new IOCs

    Edit3: MOAR IOCS FOR THE HOARDE

  • mark@programming.dev
    link
    fedilink
    arrow-up
    8
    ·
    4 months ago

    Not many things require a polyfill these days. My guess is a lot of older sites are affected.

    • stevedidwhat_infosec@infosec.pub
      link
      fedilink
      arrow-up
      6
      ·
      4 months ago

      Intuit uses pollyfill… and a lot of people use that service.

      Cloudflare and fastly wouldn’t be setting up mirrors if it weren’t still being used, I can guarantee that.