'Windigo' Malware Campaign Floods Internet with Spam, Porn

Status
Not open for further replies.

jhansonxi

Distinguished
May 11, 2007
525
0
18,930
From Ars Technica (http://arstechnica.com/security/2014/03/10000-linux-servers-hit-by-malware-serving-tsunami-of-spam-and-exploits/): "The Windigo campaign doesn't rely on technical vulnerabilities to take hold of servers, Eset said. Instead, it uses stolen credentials. That finding led the researchers to conclude password authentication to access servers is inadequate."IOW, no OS exploit. Just typical idiots setting up servers.
 

DA Dope

Estimable
Mar 19, 2014
1
0
4,510
Note that the "$" is not part of the test command. If you type "$ ssh..." you will get a false "system infected" response.
 

deksman

Distinguished
Aug 29, 2011
30
0
18,580
1. Adblock2. HTTPS everywhere3. Do Not Track A 'must have' extensions for Chrome. I also use Microsof Security Essentials with 0 problems, and Free Malwarebytes as a backup just in case.
 
Status
Not open for further replies.