Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Linux is favourite hacker target: Study
The Globe and Mail ^ | 09/11/03 | JACK KAPICA

Posted on 09/11/2003 1:21:15 PM PDT by Salo

Linux, not Microsoft Windows, remains the most-attacked operating system, a British security company reports.

During August, 67 per cent of all successful and verifiable digital attacks against on-line servers targeted Linux, followed by Microsoft Windows at 23.2 per cent. A total of 12,892 Linux on-line servers running e-business and information sites were successfully breached in that month, followed by 4,626 Windows servers, according to the report.

Just 360 — less than 2 per cent — of BSD Unix servers were successfully breached in August.

The data comes from the London-based mi2g Intelligence Unit, which has been collecting data on overt digital attacks since 1995 and verifying them. Its database has tracked more than 280,000 overt digital attacks and 7,900 hacker groups.

Linux remained the most attacked operating system on-line during the past year, with 51 per cent of all successful overt digital attacks.

Microsoft Windows servers belonging to governments, however, were the most attacked (51.4 per cent) followed by Linux (14.3 per cent) in August.

The economic damage from the attacks, in lost productivity and recovery costs, fell below average in August, to $707-million (U.S.).

The overall economic damage in August from overt and covert attacks as well as viruses and worms stood at an all-time high of $28.2-billion.

The Sobig and MSBlast malware that afflict Microsoft platforms contributed significantly to the record estimate.

"The proliferation of Linux within the on-line server community coupled with inadequate knowledge of how to keep that environment secure when running vulnerable third-party applications is contributing to a consistently higher proportion of compromised Linux servers," mi29 chairman D.K. Matai said.

"Microsoft deserves credit for having reduced the proportion of successful on-line hacker attacks perpetrated against Windows servers."


TOPICS: Business/Economy; Technical
KEYWORDS: linux; lowqualitycrap; security
Navigation: use the links below to view more comments.
first 1-2021-4041-6061-80 ... 181-182 next last
More grist for the mill. BTW, study paid for by MS - not that it discounts the information.
1 posted on 09/11/2003 1:21:15 PM PDT by Salo
[ Post Reply | Private Reply | View Replies]

To: rdb3; Bush2000
Pinging Dr. Penguin. And here, b2k - you've had a crappy couple of weeks - thought you might like this. :-)
2 posted on 09/11/2003 1:22:46 PM PDT by Salo
[ Post Reply | Private Reply | To 1 | View Replies]

To: Salo
I can't wait to see the Penguin dorks spin this...


3 posted on 09/11/2003 1:24:34 PM PDT by xrp
[ Post Reply | Private Reply | To 1 | View Replies]

To: John Robinson; B Knotts; stainlessbanner; TechJunkYard; ShadowAce; Knitebane; AppyPappy; jae471; ...
The Penguin Ping.

Wanna be Penguified? Just holla!

Got root?

4 posted on 09/11/2003 1:26:12 PM PDT by rdb3 (Which is more powerful: The story or the warrior?)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Salo
Most of these probably happened to cut-rate shared-hosting servers, where Linux prevails and security is kept lax to keep customer questions to a minimum.

It's easier to clean up a defaced homepage than try to explain chmod to Mom and Pop.
5 posted on 09/11/2003 1:27:07 PM PDT by E. Pluribus Unum (Drug prohibition laws help support terrorism.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Salo
successful and verifiable

Them's the keywords.

Look up details on the SHATTER attacks on Windows systems-

No definite way to tell if your system's been hacked except for certain indicators which are by no means definitive, and no way to know that your system's secure after installing the patches.

6 posted on 09/11/2003 1:27:58 PM PDT by George Smiley (Is the RKBA still a right if you have to get the government's permission before you can exercise it?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: xrp
FreeBSD is fine. What's your beef?


7 posted on 09/11/2003 1:29:43 PM PDT by rdb3 (Which is more powerful: The story or the warrior?)
[ Post Reply | Private Reply | To 3 | View Replies]

To: E. Pluribus Unum
I suppose it's easier with any OS to ignore security and ignore security updates. None of the recent worms would have gotten off the ground if people had simply installed the automatic updates.
8 posted on 09/11/2003 1:30:33 PM PDT by js1138
[ Post Reply | Private Reply | To 5 | View Replies]

To: rdb3
Huh? When I said Penguin dorks, I was referring to the Linux bigots who think that Linux can do no wrong.
9 posted on 09/11/2003 1:32:29 PM PDT by xrp
[ Post Reply | Private Reply | To 7 | View Replies]

To: Salo
Linux is favourite hacker target

DemocRATS claim Bush is responsible.

10 posted on 09/11/2003 1:33:47 PM PDT by jimkress (Go away Pat Go away!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Salo
Wow, that certainly wasn't what I was expecting.
11 posted on 09/11/2003 1:33:47 PM PDT by Quick1
[ Post Reply | Private Reply | To 1 | View Replies]

To: js1138
None of the recent worms would have gotten off the ground if people had simply installed the automatic updates.

With today's smaller IT staffs, thanks to outsourcing and layoffs, it is extremely difficult to constantly apply MS, Linux, FreeBSD, or any series of patches for any OS across any company, ranging from a few dozen desktops and servers to hundreds of thousands of servers and desktops.

12 posted on 09/11/2003 1:34:26 PM PDT by xrp
[ Post Reply | Private Reply | To 8 | View Replies]

To: Salo
Did anyone else notice that the $'s worth of camage was the **ONLY** thing not broken up by operating system? I wonder why tat would be?

I am sure Linux is more attacked than windows, but the attacks are almost always a configuration (not update) related issue. If I leave my webserver open to the internet and not behind a firewall there could be trouble. Most sendmail server are running Linux so if you try to expolit an open relay chances are your going to hit a Linux box.

Compare Nimda to an apache vulnerability that came out at the same time (can think of what the name was) the Linux bug let an attacker bring down a website, no data loss. Nimda opend up any network shares to be read write by all and gave all accounts admin.

13 posted on 09/11/2003 1:34:33 PM PDT by N3WBI3
[ Post Reply | Private Reply | To 1 | View Replies]

To: xrp
I never understood the BSD vs Linux fighting **on both sides** I dont know too many linux admins who wont say that BSD is a far more secure system, they just dont like working on it. Most of my app servers are Linux but you can bet your bottom dollar I have a BSD firewall out in front of them..
14 posted on 09/11/2003 1:35:51 PM PDT by N3WBI3
[ Post Reply | Private Reply | To 3 | View Replies]

To: Salo
mi2g is not seen by many as a credible source:

http://lists.insecure.org/lists/isn/2002/Nov/0101.html
15 posted on 09/11/2003 1:36:23 PM PDT by Wisconsin
[ Post Reply | Private Reply | To 2 | View Replies]

To: js1138
Which you cant (read should not) do on servers, there is a time to test an update to make sure it does not break a system..
16 posted on 09/11/2003 1:36:44 PM PDT by N3WBI3
[ Post Reply | Private Reply | To 8 | View Replies]

To: Salo
The Sobig and MSBlast malware that afflict Microsoft platforms contributed significantly to the record estimate.

words in bold are always fun.

17 posted on 09/11/2003 1:36:57 PM PDT by Havoc (If you can't be frank all the time are you lying the rest of the time?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: xrp
I was referring to the Linux bigots who think that Linux can do no wrong.

People keep referring to these bigots but I don't think I've never seen one.

18 posted on 09/11/2003 1:38:12 PM PDT by TechJunkYard
[ Post Reply | Private Reply | To 9 | View Replies]

To: N3WBI3
I recently saw a saying: BSD is for people who like Unix, Linux is for people who hate Microsoft.

I prefer BSD, as it was the first Unix I used (circa 4.2 BSD), but I admin Solaris for a living.

19 posted on 09/11/2003 1:42:02 PM PDT by cryptical
[ Post Reply | Private Reply | To 14 | View Replies]

To: Salo
Windows regains mantle of most vulnerable OS

London, UK - 14 August 2002, 11:30 GMT - mi2g The latest figures compiled by the Intelligence Unit at mi2g indicate that Windows has once again regained the position of most vulnerable online operating system.

....more here: http://mi2g.com/cgi/mi2g/frameset.php?pageid=http%3A//mi2g.com/cgi/mi2g/press/311002.php


20 posted on 09/11/2003 1:44:30 PM PDT by stainlessbanner
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-6061-80 ... 181-182 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson