Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Manic malware Mayhem spreads through Linux, FreeBSD web servers
The Register ^ | 18 Jul 2014 | Iain Thomson

Posted on 07/21/2014 6:45:33 AM PDT by Olog-hai

Malware dubbed Mayhem is spreading through Linux and FreeBSD web servers, researchers say. The software nasty uses a grab bag of plugins to cause mischief, and infects systems that are not up to date with security patches.

Andrej Kovalev, Konstantin Ostrashkevich and Evgeny Sidorov, who work at Russian internet portal Yandex, discovered the malware targeting *nix servers. They traced transmissions from compromised computers to two command and control (C&C) servers. So far they have found 1,400 machines that have fallen to the code, with potentially thousands more to come. […]

Mayhem spreads by finding servers hosting websites with a remote file inclusion (RFI) vulnerability—it even uses Google’s /humans.txt to test for this. If the ad giant rewrote this file, specifically changing the words “we can shake”, Mayhem infections would be slowed—until its rfiscan.so plugin is updated. …

(Excerpt) Read more at theregister.co.uk ...


TOPICS: Business/Economy; Computers/Internet
KEYWORDS: freebsd; linux; malware; mayhem

1 posted on 07/21/2014 6:45:33 AM PDT by Olog-hai
[ Post Reply | Private Reply | View Replies]

To: Olog-hai

2 posted on 07/21/2014 6:46:44 AM PDT by dfwgator
[ Post Reply | Private Reply | To 1 | View Replies]

To: Olog-hai

3 posted on 07/21/2014 6:47:39 AM PDT by Jack Hydrazine (Pubbies = national collectivists; Dems = international collectivists; We need a second party!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Jack Hydrazine

Hands down some of the best ads ever.


4 posted on 07/21/2014 6:51:52 AM PDT by drunknsage
[ Post Reply | Private Reply | To 3 | View Replies]

To: Olog-hai

“The software nasty uses a grab bag of plugins to cause mischief, and infects systems that are not up to date with security patches. “

Sounds straight forward enough.


5 posted on 07/21/2014 7:02:09 AM PDT by DonaldC (A nation cannot stand in the absence of religious principle.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Olog-hai

M4L(inux)


6 posted on 07/21/2014 7:15:43 AM PDT by Scrambler Bob
[ Post Reply | Private Reply | To 1 | View Replies]

To: Olog-hai

non-compiled script languages are inherently insecure.

that’s why they’re promoted so heavily. we’re all supposed to write scripts instead of writing compiled programs.

most so-called programmers today (script kiddies) are oblivious.


7 posted on 07/21/2014 7:28:01 AM PDT by PieterCasparzen (We have to fix things ourselves)
[ Post Reply | Private Reply | To 1 | View Replies]

To: DonaldC

Yes it does


8 posted on 07/21/2014 7:30:25 AM PDT by GeronL (Vote for Conservatives not for Republicans)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Olog-hai

Good time to run a scan


9 posted on 07/21/2014 7:32:23 AM PDT by GeronL (Vote for Conservatives not for Republicans)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

tech ping?


10 posted on 07/21/2014 7:33:07 AM PDT by GeronL (Vote for Conservatives not for Republicans)
[ Post Reply | Private Reply | To 8 | View Replies]

To: Swordmaker

Any input for us Mac users?

Or is this a concern for servers only?


11 posted on 07/21/2014 7:40:40 AM PDT by jacquej ("It is the peculiar quality of a fool to perceive the faults of others and to forget his own.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: DonaldC

yep , updates ,updates ,updates


12 posted on 07/21/2014 8:01:26 AM PDT by molson209 (Blank)
[ Post Reply | Private Reply | To 5 | View Replies]

To: jacquej
Article and discussion at SlashDot.
13 posted on 07/21/2014 8:06:20 AM PDT by Dalberg-Acton
[ Post Reply | Private Reply | To 11 | View Replies]

To: Dalberg-Acton

Very interesting discussion on slashdot, even for us that don’t know a whole lot (just enough to be dangerous) about web development.


14 posted on 07/21/2014 8:15:14 AM PDT by DonaldC (A nation cannot stand in the absence of religious principle.)
[ Post Reply | Private Reply | To 13 | View Replies]

To: Dalberg-Acton

Thanks for the link!


15 posted on 07/21/2014 9:37:24 AM PDT by jacquej ("It is the peculiar quality of a fool to perceive the faults of others and to forget his own.")
[ Post Reply | Private Reply | To 13 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson