Re: shared hosting and attacks [FWD: [funsec] HostGator: cPanel Security Hole Exploited in Mass Hack]

2006-09-24 Thread Peter Corlett
On 24 Sep 2006, at 04:00, Gadi Evron wrote: [...] With thousands of sites on every server and virtual machines everywhere, all it takes is one insecure web application such as xxxBB or PHPxx for the server to be remote accessed, and for a remote connect-back shell to be installed. The

shared hosting and attacks [FWD: [funsec] HostGator: cPanel Security Hole Exploited in Mass Hack]

2006-09-23 Thread Gadi Evron
Hi, the following post is a forward of an email by Fergie to funsec. This story by itself is not relevant to NANOG, but it does illustrate a problem nearly all of us have been facing. Mass exploitation of servers in our nets, colos and hosting farms. Nearly ever (relevant, not say, just a