Feeds

Red Hat Piranha ‘backdoor’ password discovered

Enables total control of a server

  • alert
  • submit to reddit

Beginner's guide to SSL certificates

An undocumented backdoor password in the Red Hat Linux Piranha package containing Linux Virtual Server (LVS) software has been discovered by Allen Wilson of the X-Force department of security outfit Internet Security Systems. The backdoor password allows remote attackers to execute commands on a server, ISS says. If an affected version of Piranha is installed and the default backdoor password remains unchanged, any remote or local user may log in to the LVS Web interface. From there, LVS parameters can be changed and arbitrary commands can be executed with the same privilege as that of the Web server. The vulnerability is present even if the LVS service is not used, ISS warns. If the affected package is installed and the password has not been changed by the administrator from the pre-set login/pass combination "piranha" and "Q", the system is vulnerable. The current distribution of Red Hat Linux 6.2 is vulnerable. Earlier versions are not. Red Hat has provided an updated Piranha package, version 0.4.13-1, available here. Meanwhile, all the gruesome technical details of the ISS advisory are posted here. ®

Top 5 reasons to deploy VMware with Tegile

Whitepapers

Choosing cloud Backup services
Demystify how you can address your data protection needs in your small- to medium-sized business and select the best online backup service to meet your needs.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Internet Security Threat Report 2014
An overview and analysis of the year in global threat activity: identify, analyze, and provide commentary on emerging trends in the dynamic threat landscape.
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.