Feeds

Oracle UK systems accused in 'SSH hacking spree'

Database giant investigates DenyHosts reports

Beginner's guide to SSL certificates

Compromised computers at Oracle UK are listed among the 10 worst offenders on the net for launching attacks on servers which run SSH (secure shell) server software.

Oracle said it is investigating the reported problem, which it is yet to either confirm or refute.

A box (or group of boxes behind a proxy) at Oracle UK is among the worst offenders for launching attacks, according to statistics from servers running DenyHosts software to block SSH brute-force password attacks.

DenyHosts is a script for Linux system administrators designed to help thwart SSH server attacks. Around 6,800 users contribute to the data it collects.

The compromised Oracle boxes - recorded as active since 3 May - feature at number nine on DenyHosts' list. The listing implies a computer (or multiple computers) at Oracle UK have been compromised for weeks allowing hackers to enjoy access to Oracle's bandwidth in order to hack other boxes elsewhere on the net.

For a firm that prides itself on building a "reputation for delivering many of the industry's most secure solutions", this is surely unacceptable.

In response to Register inquiries, Oracle supplied a statement saying that an ongoing investigation is yet to confirm whether its systems have been misused or not.

"Security is a matter Oracle takes seriously and the company's first priority is meeting customer needs and reducing their risk. As soon as Oracle became aware of the situation an investigation began, which is ongoing, but to date the company has found no evidence for any SSH brute-force attack originating from the Oracle owned machine currently listed on the DenyHosts website." ®

Internet Security Threat Report 2014

More from The Register

next story
Nexus 7 fandroids tell of salty taste after sucking on Google's Lollipop
Web giant looking into why version 5.0 of Android is crippling older slabs
Be real, Apple: In-app goodie grab games AREN'T FREE – EU
Cupertino stands down after Euro legal threats
Download alert: Nearly ALL top 100 Android, iOS paid apps hacked
Attack of the Clones? Yeah, but much, much scarier – report
Microsoft: Your Linux Docker containers are now OURS to command
New tool lets admins wrangle Linux apps from Windows
Bada-Bing! Mozilla flips Firefox to YAHOO! for search
Microsoft system will be the default for browser in US until 2020
prev story

Whitepapers

Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Getting ahead of the compliance curve
Learn about new services that make it easy to discover and manage certificates across the enterprise and how to get ahead of the compliance curve.
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.