Tomdep harnesses strength of servers to wage powerful denial-of-service attacks.
Read the whole story
Read the whole story
[url=http://meincmagazine.com/civis/viewtopic.php?p=25724389#p25724389:22peklgj said:Chuck Knucka[/url]":22peklgj]Of course this is a big deal for Symantec because their Endpoint Protection product uses a Tomcat server to host its web admin console.
I've always been rather puzzled why a security company relies so heavily on Java and Java plugins.
compromised computers can also scan for other Tomcat servers and send the malware to them. When it finds another Tomcat server, it first attempts to log in with the following pairs of weak usernames and passwords
[url=http://meincmagazine.com/civis/viewtopic.php?p=25724555#p25724555:2oxhe9xi said:motytrah[/url]":2oxhe9xi]
One of the reasons I suspect the infection rate is so low is because very few people use the UI for production servers. You only need to set up an admin user if you want to use the UI to administer the server. You don't need to use the admin user to deploy a Java app. Just copy the WAR or EAR file into the webapp directory from the command prompt. Anything that can be managed in the UI can be managed in the config files from the command prompt too. The rare times I have seen the UI used in prod it was restricted behind a firewall or on a port on accessible internally.
for all intents and purposes[url=http://meincmagazine.com/civis/viewtopic.php?p=25724555#p25724555:2p4x523z said:motytrah[/url]":2p4x523z]By default a fresh Tomcat server no admin user/password and for all intensive purposed is disabled.
[url=http://meincmagazine.com/civis/viewtopic.php?p=25725177#p25725177:20i8u7go said:Faramir[/url]":20i8u7go]for all intents and purposes[url=http://meincmagazine.com/civis/viewtopic.php?p=25724555#p25724555:20i8u7go said:motytrah[/url]":20i8u7go]By default a fresh Tomcat server no admin user/password and for all intensive purposed is disabled.
This is not a Java issue, read the article.[url=http://meincmagazine.com/civis/viewtopic.php?p=25726899#p25726899:ydv7ddya said:toyotabedzrock[/url]":ydv7ddya]I love how the Java runs on everything promise is now a liability.
[url=http://meincmagazine.com/civis/viewtopic.php?p=25728617#p25728617:24f4o57m said:bonewah[/url]":24f4o57m]So to be clear here, the exploit vector is weak passwords? This isnt some new vulnerability in tomcat? Can the author perhaps state that explicitly in the article?
[url=http://meincmagazine.com/civis/viewtopic.php?p=25728617#p25728617:bhsmv398 said:bonewah[/url]":bhsmv398]So to be clear here, the exploit vector is weak passwords? This isnt some new vulnerability in tomcat? Can the author perhaps state that explicitly in the article?