Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Botnet operators have always been able to easily infect and convert PCs into bots, but they also are increasingly going after servers -- even building networks of compromised servers. Web servers, FTP servers, and even SSL servers are becoming prime targets for botnet operators, not as command and control servers or as pure zombies, but more as a place to host their malicious code and files, or in some cases to execute high-powered spam runs.. "FTP servers are a hot commodity in the underground. They are regularly used by drive-by download malware as well as a downloading component for regular bots," says Mikko Hypponen, chief research officer at F-Secure. "Another thing we've noticed is the use of SSL servers. Sites with a valid SSL certificate get hacked and are used by drive-by-downloads." Why SSL servers? "If a drive-by download gets the malware file through an HTTPS connection, proxy and gateway scanners won't be able to scan for the malware in transit, making it easier to sneak in," Hypponen explains. The link for this article located at Dark Reading is no longer available. . 'FTP servers are a hot commodity in the underground. They are regularly used by drive-by download ma. botnet, operators, always, easily, infect, convert. . Alex
We're reported in the past on hacks of the President's campaign web site barackobama.com, still used for political campaigning: This one on January 26, 2009 served malware to users and this one from April 21, 2008 redirected users to the Hillary Clinton campaign site (note: Friends of Hillary is still taking contributions).. The latest attack uses SQL injection to gain full access to the databases on the barackobama.com server. They use Microsoft Access databases, including the one in the graphic (click it for a full-size image): It's the database of administrators and their passwords, all in plain text. By adding themselves to the database they get to log in as administrator and do whatever they want. The link for this article located at PC Magazine is no longer available. . The latest attack uses SQL injection to gain full access to the databases on the barackobama.com ser. we're, reported, hacks, president's, campaign, barackobama, still. . LinuxSecurity.com Team
Insecurely written software still looms as one of the greatest threats to Internet commerce, and user-generated Web content is becoming a vast new vulnerability hackers want to exploit, according to experts at RSA Conference. Cross-site scripting attacks on Web sites can lead to malware taking over the browsers of machines that use the sites, said Caleb Sima, a member of the Secure Software Forum and co-founder of SPI Dynamics. . The link for this article located at Network World is no longer available. . Unprotected applications pose a significant risk to digital trade, as cybercriminals take advantage of weaknesses in website features.. Cross-Site Scripting, Web Exploits, Online Security, Browser Malware. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.