MESSAGE
DATE | 2015-11-16 |
FROM | Rick Moen
|
SUBJECT | Re: [Hangout-NYLXS] ransomware - attacking apache
|
Quoting Ruben Safir (ruben-at-mrbrklyn.com):
> How to easily defeat Linux Encoder ransomware
As per usual, another good Vaughan-Nichols article. One comment: Nothing about the trojan (Linux.Encoder.1) ties it to the recent flaw in the Magento web e-commerce platform. That's just a matter of current default packaging. Linux.Encoder.1, like any other trojan, could be installed following _any other_ variety of break-in and privilege escalation to root authority.
Thus, Linux.Encoder.1 is never the problem. Its an _after-effect_ of an actual problem.
In this, it's exactly like every other trojan.
The best way to 'defeat' any trojan is to not have a system with exploitable vulnerabilities permitting random outsiders to gain illicit access and escalate privilege to root. The second best way is to have current backups and a reasonable recovery plan so that _if_ such an intrusion happens, you can rebuild without losing anything but a small amount of downtime.
That second measure will also protect you against a great many more-credible threats. Thus, if you are actually vulnerable in a way that facilitates installation of the Linux.Encoder.1 'ransomware' trojan, you actually also have much bigger problems.
_______________________________________________ hangout mailing list hangout-at-nylxs.com http://www.nylxs.com/
|
|