Comment by nom
4 hours ago
The access log of public http servers is truly interesting to watch.
You know that the scripts doing it are optimized for success rate, so the types of requests they send give you an impression of what's actually out there.
It's clear to me that once we finally achieve rogue AGI, it is going to propagate through unpatched WordPress WooCommerce instances.
Not success rate per request though.
It seems the most common issue of them all is an exposed .env file by that measure.