× Warning! This forum is in archival status. New contributions may not work.
[campsite-support] Santy.a: Culprit of yesterday's hack
  • This is a multipart message in MIME format.
    --=_alternative 00496BA8C1256F72_=
    Content-Type: text/plain; charset="us-ascii"

    Hi all,

    It turns out that yesterday's hack on a server running Campsite was
    actually a worm called Santy.a. It affected more than 60,000 sites
    worldwide - not just Campsite - at its peak. Kaspersky Labs has this about
    it:

    http://www.kaspersky.com/news?id=156681162

    The BBC wrote this:

    http://news.bbc.co.uk/1/hi/technology/4117711.stm

    and The Register had this:

    http://www.theregister.co.uk/2004/12/21/santy_worm/


    As always, it's a good idea to make sure your servers are running
    up-to-date software and are regularly backed up.


    douglas

    =============================================
    Media Development Loan Fund
    =============================================
    Douglas Arellanes
    Head of Research and Development
    Center for Advanced Media--Prague (CAMP)
    Na vinicnich horach 24a/1834, 160 00 Prague 6
    Czech Republic
    Tel: + 420 2 3333 5356, Fax: +420 2 2431 5419
    Mobile: +420 724 073 364
    http://www.mdlf-camp.net
    http://www.campware.org
    =============================================
    http://www.mdlf.org
    =============================================
    --=_alternative 00496BA8C1256F72_=
    Content-Type: text/html; charset="us-ascii"



    Hi all,



    It turns out that yesterday's hack on a server running Campsite was actually a worm called Santy.a. It affected more than 60,000 sites worldwide - not just Campsite - at its peak. Kaspersky Labs has this about it:



    http://www.kaspersky.com/news?id=156681162



    The BBC wrote this:



    http://news.bbc.co.uk/1/hi/technology/4117711.stm



    and The Register had this:



    http://www.theregister.co.uk/2004/12/21/santy_worm/





    As always, it's a good idea to make sure your servers are running up-to-date software and are regularly backed up.





    douglas



    =============================================

    Media Development Loan Fund

    =============================================

    Douglas Arellanes

    Head of Research and Development

    Center for Advanced Media--Prague (CAMP)

    Na vinicnich horach 24a/1834, 160 00  Prague 6

    Czech Republic

    Tel: + 420 2 3333 5356, Fax: +420 2 2431 5419

    Mobile: +420 724 073 364

    http://www.mdlf-camp.net

    http://www.campware.org

    =============================================

    http://www.mdlf.org

    =============================================

    --=_alternative 00496BA8C1256F72_=--

    ------------------------------------------
    Posted to Phorum via PhorumMail
  • 1 Comment sorted by
  • The problem is, that there are no security updates for RedHat 9 and all sites
    running RH 9 or lower and apache can be easilly affected by this worm.
    So it would be vice to upgrade all RH to Fedora3 or some commercial version of
    RH.

    Ondra

    On Wednesday 22 of December 2004 14:22, Douglas.Arellanes@mdlf.org wrote:
    > Hi all,
    >
    > It turns out that yesterday's hack on a server running Campsite was
    > actually a worm called Santy.a. It affected more than 60,000 sites
    > worldwide - not just Campsite - at its peak. Kaspersky Labs has this about
    > it:
    >
    > http://www.kaspersky.com/news?id=156681162
    >
    > The BBC wrote this:
    >
    > http://news.bbc.co.uk/1/hi/technology/4117711.stm
    >
    > and The Register had this:
    >
    > http://www.theregister.co.uk/2004/12/21/santy_worm/
    >
    >
    > As always, it's a good idea to make sure your servers are running
    > up-to-date software and are regularly backed up.
    >
    >
    > douglas
    >
    > =============================================
    > Media Development Loan Fund
    > =============================================
    > Douglas Arellanes
    > Head of Research and Development
    > Center for Advanced Media--Prague (CAMP)
    > Na vinicnich horach 24a/1834, 160 00 Prague 6
    > Czech Republic
    > Tel: + 420 2 3333 5356, Fax: +420 2 2431 5419
    > Mobile: +420 724 073 364
    > http://www.mdlf-camp.net
    > http://www.campware.org
    > =============================================
    > http://www.mdlf.org
    > =============================================

    ------------------------------------------
    Posted to Phorum via PhorumMail