http://lpoaj76nfopd5lpinbskyqtroppamrzhhay3g4vvjm75st6ger34lbyd.onion/posts/2024/07/zipbombing.html
Also, do make sure the /srv/www/bombs directory contains a bomb file (e.g. just run touch bomb in there) n not just the compressed files, otherwise Caddy won't attempt sending the compressed files either. &(bot-defense) { @bot `header({'User-Agent': 'nikto'}) || header({'User-Agent': 'sqlmap'}) || path('*.php', '*.aspx', '/wp/*', '/wordpress*', '/wp-*')` # This matches the default nikto n sqlbase user agent headers, as well as anything that looks like a...