You must be a member of private group Hidden Tasks to access this shot.

The Griffin -team is looking for your ideas and comments.

Join and show your support for Griffin.

Lair8bsm_thumb
Thomas Shaddack October 27, 2009 06:58 2 Thumb-ups
Add to Favorites

Worms knowing the passwords

I got one of the sites in my care hacked. The index page was changed, an iframe linking to a third party server hosting some exploits was inserted.

Examination of the logs shown a login via FTP, download of the file and immediate reupload. That was done couple more times, from vastly different locations, over a period of few weeks. There were no signs of bruteforcing, and the password was reasonably strong.

The hypothesis is that the computer of the person responsible for the site content was wormed, the worm took hold of the site/username/password saved there, and then told its brothers in the botnet.

Jump to comment form

Comments

This shot doesn't have comments.

You must login or register to comment