Friday, March 21, 2014

Webservers running Linux Kernel 2.6 - We now officially know that they are being compromised


I thought the Linux admins were passionate and security conscious, looks like some are not.

I know we can have outdated systems but , Internet facing and content serving?. 
I think that's a bit IRRESPONSIBLE.



According to the article:- 

They were attacked with dramatic speed over two days last week, Cisco Systems said on Thursday

After the Web server has been compromised, the attackers slip in a line of JavaScript to other JavaScript files within the website. That code bounces the website's visitors to a second compromised host, which runs another JavaScript file.

"The two-stage process allows attackers to serve up a variety of malicious content to the visitor," Lee wrote.


The links below has more information:

No comments:

Post a Comment