Feeds

Oracle UK systems accused in 'SSH hacking spree'

Database giant investigates DenyHosts reports

Remote control for virtualized desktops

Compromised computers at Oracle UK are listed among the 10 worst offenders on the net for launching attacks on servers which run SSH (secure shell) server software.

Oracle said it is investigating the reported problem, which it is yet to either confirm or refute.

A box (or group of boxes behind a proxy) at Oracle UK is among the worst offenders for launching attacks, according to statistics from servers running DenyHosts software to block SSH brute-force password attacks.

DenyHosts is a script for Linux system administrators designed to help thwart SSH server attacks. Around 6,800 users contribute to the data it collects.

The compromised Oracle boxes - recorded as active since 3 May - feature at number nine on DenyHosts' list. The listing implies a computer (or multiple computers) at Oracle UK have been compromised for weeks allowing hackers to enjoy access to Oracle's bandwidth in order to hack other boxes elsewhere on the net.

For a firm that prides itself on building a "reputation for delivering many of the industry's most secure solutions", this is surely unacceptable.

In response to Register inquiries, Oracle supplied a statement saying that an ongoing investigation is yet to confirm whether its systems have been misused or not.

"Security is a matter Oracle takes seriously and the company's first priority is meeting customer needs and reducing their risk. As soon as Oracle became aware of the situation an investigation began, which is ongoing, but to date the company has found no evidence for any SSH brute-force attack originating from the Oracle owned machine currently listed on the DenyHosts website." ®

Remote control for virtualized desktops

More from The Register

next story
Download alert: Nearly ALL top 100 Android, iOS paid apps hacked
Attack of the Clones? Yeah, but much, much scarier – report
NSA SOURCE CODE LEAK: Information slurp tools to appear online
Now you can run your own intelligence agency
Whistling Google: PLEASE! Brussels can only hurt Europe, not us
And Commish is VERY pro-Google. Why should we worry?
Microsoft: Your Linux Docker containers are now OURS to command
New tool lets admins wrangle Linux apps from Windows
First in line to order a Nexus 6? AT&T has a BRICK for you
Black Screen of Death plagues early Google-mobe batch
Microsoft adds video offering to Office 365. Oh NOES, you'll need Adobe Flash
Lovely presentations... but not on your Flash-hating mobe
prev story

Whitepapers

Seattle children’s accelerates Citrix login times by 500% with cross-tier insight
Seattle Children’s is a leading research hospital with a large and growing Citrix XenDesktop deployment. See how they used ExtraHop to accelerate launch times.
How to determine if cloud backup is right for your servers
Two key factors, technical feasibility and TCO economics, that backup and IT operations managers should consider when assessing cloud backup.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Managing SSL certificates with ease
The lack of operational efficiencies and compliance pitfalls associated with poor SSL certificate management, and how the right SSL certificate management tool can help.