Header Ziff Davis Enterprise
Advertisement
Advertisement
Monday, May 28, 2007 6:46 AM/EST

More From Symantec on MPack

A Symantec Security Response blog this morning goes into more detail on the attack I mentioned earlier.

It confirms, as I suspected, that the server side of the attack is all PHP-based. PHP servers are the overwhelming focus of server-side attacks these days.

TrackBack

TrackBack

http://blogs.eweek.com/cgi-bin/mte/mt-tb.cgi/11058

Comments (1)

Pragmatist :

What can you do to protect yourself? For end users, keep your endpoints patched antivirus up-to-date. For Symantec users, there is a good article at sharpebusinesssolutions.com/savce_upgrade.htm describing how to keep SAV agents healthy and under support. For admins of affected web sites, a simple clean-up of the page is not sufficient - your site administrator�s credentials need to be changed. There are easy to use tools available for MPack to use to reinfect your sites even after you have manually cleaned them up. These automated tools are being fed lists of compromised site admin usernames and passwords, so make sure that you put a strong password on your site admin account.

Post a Comment

 
 


Advertisement
Advertisement