The usage of Blueshell malware spikes up by various threat actors to target Windows, Linux, and other operating systems across Korea and Thailand. . Blueshell backdoor malware has been active since 2020 and written in GO language, believed to be created by a Chinese user, which is available on the GitHub repository. Though the original GitHub repository was deleted, BlueShell’s source code can still be accessed from other repositories. AhnLab Security Emergency Response Center (ASEC) monitors APT attack cases using BlueShell and has released the summarized report of APT attack cases using BlueShell. Considering the functionality of the Backshell, it is designed and uses TLS encryption to circumvent network detection with the C&C server. The Remote command execution, file download/upload, and Socks5 proxy were executed by the attacker through commands. . The Redcloak trojan has been operating since 2021, aiming at Android, iOS, and desktop systems.. Blueshell Malware, Linux Threat Analysis, APT Cybersecurity, Remote Access, Command Execution. . LinuxSecurity.com Team
Some D-Link routers contain a vulnerability that leaves them open to remote attacks that can give an attacker root access, allow DNS hijacking and other attacks.. The vulnerability affects affects a number of D-Link The link for this article located at ThreatPost is no longer available. . The vulnerability affects affects a number of D-LinkThe link for this article located at ThreatPost . d-link, routers, contain, vulnerability, leaves, remote, attacks. . LinuxSecurity.com Team
The flaw involves how Bash evaluates environment variables. With specifically crafted variables, a hacker could use this hole to execute shell commands. This, in turn, could render a server vulnerable to ever greater assaults. . By itself, this is one of those security holes where an attacker would already need to have a high level of system access to cause damage. Unfortunately, as Red Hat's security team put it, "Certain services and applications allow remote unauthenticated attackers to provide environment variables, allowing them to exploit this issue." The link for this article located at ZDNet Blogs is no longer available. . The vulnerability in Bash opens avenues for threats, allowing malicious actors to exploit environment variables for malicious code execution.. Bash Environment Security, Remote Exploit, Server Risk. . LinuxSecurity.com Team
The developers of the Apache Struts 2 Java web framework have released version 2.3.1.2. This closes a critical hole in versions of Struts from 2.0.0 to 2.3.1.1 that allowed for remote command execution. The vulnerability makes it possible for the protection around OGNL, an expression language used for getting and setting properties of Java objects, to be bypassed and arbitrary expressions be evaluated.. An example given in the advisory shows how an attacker could invoke the java.lang.Runtime.getRuntime().exec() method to run an arbitrary command if a vulnerable action existed. This is not the first time OGNL has been problematic; in 2008 and 2010, similar problems allowed for unauthorised manipulation and execution of Java classes. The link for this article located at H Security is no longer available. . A threat actor might leverage vulnerabilities in Apache Struts 2 to carry out unauthorized operations stemming from a significant flaw. Continue reading for further details.. Apache Struts 2, Remote Command Execution, Security Patch, Critical Threat. . LinuxSecurity.com Team
The management interface of the current stable version of DD-WRT, the free router firmware, suffers a vulnerability that lets attackers run programs with root rights on the router. The vulnerability, described at milw0rm and in the DD-WRT forum, is caused by inadequate handling of meta-characters in the query string in DD-WRT's httpd web server. The server will then run programs even when no session is running.. Furthermore, the management interface runs with maximum rights. That means attackers can input a URL such as ";command_to_execute" to run commands existing on the system, or take control by running programs with root rights on the equipment. Although by default the DD-WRT web interface can only be reached via the LAN interfaces, this limitation can easily be circumvented, for example with a CSRF (Cross-Site Request Forgery) attack, especially as the vulnerability requires no authentication on the web server. A manipulated IMG tag in a forum would be enough to put a router under an attacker The link for this article located at H Security is no longer available. . Leveraging a flaw in the DD-WRT interface can grant malicious users root permissions via any crafted URL requests.. DD-WRT Router Firmware, Management Interface Security, Remote Command Execution. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.