Shellshock continues to reverberate: Attackers are exploiting recently discovered vulnerabilities in the Bash command-line interpreter in order to infect Linux servers with a sophisticated malware program known as Mayhem. . Mayhem was discovered earlier this year and was thoroughly analyzed by researchers from Russian Internet firm Yandex. It gets installed through a PHP script that attackers upload on servers via compromised FTP passwords, website vulnerabilities or brute-forced site administration credentials. The link for this article located at Network World is no longer available. . Hackers leverage Heartbleed to propagate the Chaos malware across Unix systems using Python and SFTP.. Shellshock Exploit, Mayhem Botnet, Linux Security Threat. . LinuxSecurity.com Team
OpenVPN wasn. Stromberg said the attack vector in OpenVPN is particularly dangerous because it The link for this article located at ThreatPost is no longer available. . Stromberg said the attack vector in OpenVPN is particularly dangerous because itThe link for this ar. openvpn, stromberg, attack, vector, particularly, dangerous, because, itthe. . LinuxSecurity.com Team
Somehow there always seems to be another Internet security disaster around the corner. A few months ago everyone was in a panic about Heartbleed. Now the bug called Shellshock (officially CVE-2014-6271), a far more serious vulnerability, is running uncontrolled over the Internet. . It's never a good time to panic, but if you're discouraged I don't blame you; I know I am. In retrospect, the grave concern over Heartbleed seems misplaced. As information disclosure bugs go it was a really bad one, but it was only an information disclosure bug and a difficult one to exploit. The sky's the limit on attacks with Shellshock and it's so easy to exploit that it's already being widely-exploited according to research firm Fireeye, which says they have already observed several forms of attack: The link for this article located at ZDNet Blogs is no longer available. . It's never a good time to panic, but if you're discouraged I don't blame you; I know I am. In retros. somehow, there, always, seems, another, internet, security, disaster, around, corner. . LinuxSecurity.com Team
With a bug as dangerous as the . The shellshock attacks are being used to infect thousands of machines with malware designed to make them part of a botnet of computers that obey hackers The link for this article located at Wired is no longer available. . Bashdoor vulnerabilities are exploited to compromise numerous systems, spawning an alarming surge in botnet risks.. Shellshock Threats, Botnet Exploitation, Malware Impact. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.