Risk Assessment / Security & Hacktivism New backdoor worm found attacking websites running Apache To

Associate
Joined
18 Aug 2010
Posts
2,112
Location
Scotland
Last edited:
Tomdep-infected machines also seek out other servers running Apache Tomcat and attempt to log in to them using commonly used combinations of user names and passwords. When the credentials match, Tomdep gets installed on another machine.

Super advanced malware.
 
Looking at the article linked to from the OPs link it tries logging onto other instances found using common username: password combinations such as admin:admin, admin: password and root:root (amongst others given).

Frankly if you are using combinations such as these you deserve all you get as a learning experience ...
 
[FnG]magnolia;25346899 said:
Like I'm going to click your RSS link/feed which you've set up with the BACKDOOR WORM HIDDEN IN IT YOU MONSTER

I certainly don't want anything worming its way into my back door.
 
Back
Top Bottom