Iframe attack a research report
Reportedly, in July 2007 there is a new massive hacking attack on web sites.
This attack targeted primarily budget Webhosting providers but it was not limited
to them. For example several site from HBS were compromised too.
It looks like the attack usually has two stages.
- Account passwords harvesting. On the first state they collect passwords
for the accounts. We will call this stage “account passwords harvesting”.
Details on how they do that are fuzzy. The truth is that on a typical Linux
server it might enough to get just one user account password to be in a
reasonably good position to get the root via some king of little known or
unpatched exploit. Zones and jails are better in this respect as they
protect other users from easily compromised “suckers” who happily use
passwords like 123456 or use infected with spyware PCs at home.
Actually the complexity of the password should be beefed up to at least 8
characters. But this does not help if the user computer is infected with a
keylogger. ISPs need to handle vastly difference classes of users and
security is always as good as the weakest link.



