rgrove / rawgit

Served files from raw.githubusercontent.com, but with the correct content types. No longer actively developed.

Home Page:https://rawgit.com

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

How to block rawgit.com to access my website ?

crossing1 opened this issue · comments

Hello,

I think some hacker injected some script that is using rawgit.com. Recently my website is connected for some reason with rawgit.com, I noticed my website is slower lately and then I sow the bottom browser message "Transferring data from rawgit.com" or "Read rawgit.com" right when my website is slower/ frozen. I have never used rawgit.com so I'm pretty sure something is wrong. I would like to totally block my website from getting data from rawgit.com, cdn.rawgit.com, can you tell me the full hataccess content to achieve that ? Thank you.

commented

That can also be some browser plugin which uses rawgit internally

I have tried on 3 browsers with the same result.

commented

Well, any 3rd party script (gallery plugin, whatever) can load something from rawgit.

So you're saying that the chances are very slim that someone is actually attacking my website.

commented

I am saying that it is better to check 3rd party stuff on your website first. In devtools you can see which script initiated the request to rawgit.

@crossing1 If you let me know the URL of your website, I can find and ban the offending script.

@crossing1 also look into Subresource Integrity and Content Security Policy and make sure to let rgrove which script is causing your issue, as it may be causing others trouble as well.