Got a test server for Plan B in the house, it runs on port 8080 and I never really suspected anyone would find it so I made the schoolboy error of not making it safe by removing the management console.
Had to do an upgrade to the software today and noticed a new web application called fexcepkillshell.war running under it, so I'm like WTF? I never put that there.
So I stop the server and have a look at the code in it, it hacks the users file, restarts the server then it awaits URL hits which I think tells it to download an exe then runs it.
I don't think it worked, Windows Live care has a few extra 'security events' in the last few days.
Wake up call really, server is safe now but it shows you never to be complacent.
Had to do an upgrade to the software today and noticed a new web application called fexcepkillshell.war running under it, so I'm like WTF? I never put that there.
So I stop the server and have a look at the code in it, it hacks the users file, restarts the server then it awaits URL hits which I think tells it to download an exe then runs it.
I don't think it worked, Windows Live care has a few extra 'security events' in the last few days.
Wake up call really, server is safe now but it shows you never to be complacent.
Comment