Over 3 million servers running outdated JBoss software open to attack

frogboy

In memoriam 1961-2018
Thread author
Verified
Top Poster
Well-known
Jun 9, 2013
6,720
Spurred by the recent discovery that the Samas (aka SamSam) ransomware is being spreadvia compromised servers running out-of-date versions of Red Hat’s JBoss server software, Cisco Talos researchers have begun scanning the Internet for machines that might be at risk.

They found approximately 3.2 million vulnerable machines, but also a considerable number of those that are already compromised: 2,100 backdoors have been already been installed across nearly 1600 IP addresses.

Another way into the compromised systems was through a vulnerability in Destiny, a library management system by Follett. This vulnerability has already been patched and customers were urged to implement the patch.

“We’ve learned that there is normally more than one webshell on compromised JBoss servers and that it is important to review the contents of the jobs status page,” the researchers noted.

Full Article. Over 3 million servers running outdated JBoss software open to attack - Help Net Security
 

DJ Panda

Level 30
Verified
Top Poster
Well-known
Aug 30, 2015
1,928
Kind of scary that the school I went to has like four routers placed along the school for each classroom. If one get striked everyone would be in a world of hurt... :eek:
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top