There's apparently a piece of malware that infects Linux and FreeBSD web hosts.
All it requires is the execution of the malicious php script (injection script) to get it going and it does *NOT* require root privileges to inject.
It's essentially a botnet node at that point and is able to run 'plug-ins', so if the C&C creates new code, they can actually update the node with new functionality.
If you guys aren't running HIDS, definitely start. OSSEC is free, so there's no reason not to run it at this point.
All it requires is the execution of the malicious php script (injection script) to get it going and it does *NOT* require root privileges to inject.
It's essentially a botnet node at that point and is able to run 'plug-ins', so if the C&C creates new code, they can actually update the node with new functionality.
If you guys aren't running HIDS, definitely start. OSSEC is free, so there's no reason not to run it at this point.


Comment