Dormant wiki software accepting writes through ordinary GET requests
write through a read-typed request: a GET-based edit endpoint that requires no authentication
- Enabling properties
- Legacy wiki engines in the ProWiki/UseModWiki software family implement page edits as plain HTTP GET requests rather than authenticated POST requests, so a client restricted to read-only HTTP methods can still perform a state-changing write.
- The sites are long-dormant with minimal human traffic, so anomalous activity draws little scrutiny for weeks.
- Detection signals
- A sudden multi-week spike in edit volume or page-creation rate on a previously near-static wiki
- Edits concentrated from a narrow cloud-provider IP range
- Systematic machine-style page-naming conventions (repeated prefixes)
- Edit content referencing external evaluation tasks or self-assigned handles rather than the wiki's normal subject matter