Home > Enterprise Linux News > Red Hat hit by phishing scam
Enterprise Linux News:
EMAIL THIS

Red Hat hit by phishing scam

By Jack Loftus, News Writer
25 Oct 2004 | SearchOpenSource.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Red Hat Inc. sent users a warning today about a fake e-mail that asked users to install a patch for a vulnerability in fileutils (ls and mkidir). The patch was actually a file that could allow a remote attacker to execute arbitrary code with root privileges in some Red Hat Linux distributions.

The attack arrived in the form of phishing scam from the fake e-mail address "security@redhat.com" and was first spotted late Friday. The heading of the e-mail read "Red Hat: Buffer Overflow in 'ls' and mk'dir'" and contained instructions on how to install a patch that Red Hat said may contain malicious code.

Red Hat said its official security messages are never unsolicited, are only sent from secalert@redhat.com and are digitally signed using GNU Privacy Guard keys.

Pete Lindstrom, an analyst at Malvern, Penn.-based Spire Security, said no individual vulnerability is a big deal in and of itself.

"Ultimately these things are found at the pace of 10 a day, some are more of a sign than others," he said. "What matters is if someone picks up on it and writes an exploit and allows folks to compromise [the application]."

Lindstrom said that these vulnerabilities are what security analysts and antivirus companies are always looking out for, and that the "bottom line is every piece of software is vulnerable."

"The fact that Microsoft is alone is silly and the idea that open source can be compromised is only recently being popularly recognized," he said. "If enough people focus on a particular problem they are going to come up with a vulnerability.

"That's true for all software whether it is packaged or open source, Microsoft or not," Lindstrom said.

that's true for all software whether it is packaged or open source, Microsoft or not

Let us know what you think about the story; e-mail: Jack Loftus, News Writer



Tags: Linux security risks and threatsSecurity advisoriesViruses and wormsVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


Linux Server Distribution Solutions - Red Hat Enterprise, SUSE Linux Enterprise, Ubuntu Linux
HomeNewsTopicsITKnowledge ExchangeTipsBlogsAsk the ExpertsMultimediaWhite PapersIT Downloads
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2010, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts