Of course it isn’t.
It was behind a WAF. But that didn’t matter for the path traversal in this attack.
Of course it isn’t.
It was behind a WAF. But that didn’t matter for the path traversal in this attack.
It’s pretty common in a killchain following a server side request forgery since the traffic isn’t seem by the WAF.
Example: https://github.com/watchtowrlabs/watchTowr-vs-Oracle-E-Business-Suite-CVE-2025-61882
They don’t have to scrape it. They just use the nominatim API like everybody else.