More From Symantec on MPack
|
A Symantec Security Response blog this morning goes into more detail on the attack I mentioned earlier. It confirms, as I suspected, that the server side of the attack is all PHP-based. PHP servers are the overwhelming focus of server-side attacks these days. |

Comments (1)
What can you do to protect yourself? For end users, keep your endpoints patched antivirus up-to-date. For Symantec users, there is a good article at sharpebusinesssolutions.com/savce_upgrade.htm describing how to keep SAV agents healthy and under support. For admins of affected web sites, a simple clean-up of the page is not sufficient - your site administrator�s credentials need to be changed. There are easy to use tools available for MPack to use to reinfect your sites even after you have manually cleaned them up. These automated tools are being fed lists of compromised site admin usernames and passwords, so make sure that you put a strong password on your site admin account.
Posted by Pragmatist | June 20, 2007 1:09 PM