Monday morning, Metasploit.com was temporarily hijacked using an attack on the local area network of Metasploit's hosting provider. Using what is technically known as ARP spoofing, the attacker was able to intercept visitors to Metasploit.com, and instead serve them up a page saying the site had been "hacked by sunwear ! just for fun. Users were then redirected to a Chinese forum with an image of the hack. . The link for this article located at Wired is no longer available. . The Metasploit.com incident reveals serious network security flaws, particularly with ARP spoofing that exploits ARP's lack of authentication to mislead devices.. Metasploit Incident, ARP Spoofing, Web Security Attack. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.