Comment by sothatsit
10 hours ago
It looks like the agents just worked around anti-scraping measures, it seems dubious to call this a hack. The agents did unsuccessfully probe for a XSS vulnerability, but otherwise it sounds like the data was just publicly accessible.
From https://transluce.org/agent-activity:
> Minutes after Cloudflare blocked the dataset download, an agent sent a reflected cross-site scripting probe to the same dashboard: a web address with code embedded in it, designed to test whether the site would run code supplied by an outsider. Cloudflare's firewall blocked the probe before it reached the dashboard. When Cloudflare blocked the dataset download on AIHW's main site, they fetched the file from AIHW's pre-production server (pp.aihw.gov.au) instead, which served it in pieces over more than 100 scans. The file itself is public, so no non-public data was exposed, but the agent bypassed the site's anti-bot controls.
No comments yet
Contribute on Hacker News ↗