Feeds

Oracle refutes 'SSH hacking' slur

Mystery over bogus DenyHosts listing

Choosing a cloud hosting partner with confidence

An investigation by Oracle has revealed the none of its systems were involved in launching a recent brute force attack on secure servers around the net.

From the beginning of May until earlier this week, "compromised computers" at Oracle UK were listed among the ten worst offenders on the net for launching attacks on servers which run SSH (secure shell) server software, according to statistics from servers running DenyHosts software to block SSH brute-force password attacks. DenyHosts is a script for Linux system administrators designed to help thwart SSH server attacks. Around 6,800 users contribute to the data it collects.

Oracle servers - recorded as active since 3 May - featured at number nine of DenyHosts list. The listing implied a computer (or multiple computers) at Oracle UK been compromised for weeks, allowing hackers to gain access to Oracle's bandwidth to hack other boxes elsewhere on the net.

Following our inquiries last week, Oracle supplied us with a holding statement saying it was investigating the problem. The database giant concluded this investigation early this week. It says none of its systems were responsible for the attack.

"Security is a matter we take seriously at Oracle and our first priority is meeting customer needs and reducing their risk. As soon as Oracle was made aware of the situation we began an investigation, which is now complete. Oracle can confirm that none of its systems were responsible for an SSH brute force attack and the allegation of compromised computers at Oracle has been removed from the Deny Hosts website," it said.

So if DenyHosts's listing was erroneous how did the entry for the database giant get there in the first place. Reg reader Stephen has one theory:

"There are a couple of issues in the present DenyHosts that could cause a group to insert their favourite bad-guy site into the DenyHosts database. They all seem to be related to regular expression problems".

"I confirmed that one could insert false sites in by just spamming a bunch of sites with echo "string from oracle IP" as listed above. It is probably not the cause for this issue, but could be used as a cover," he adds.

We were unable to contact DenyHosts at the time of writing so the exact cause of the Oracle listing remains unclear. ®

Secure remote control for conventional and virtual desktops

More from The Register

next story
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
Astro-boffins start opening universe simulation data
Got a supercomputer? Want to simulate a universe? Here you go
prev story

Whitepapers

Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
5 critical considerations for enterprise cloud backup
Key considerations when evaluating cloud backup solutions to ensure adequate protection security and availability of enterprise data.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Simplify SSL certificate management across the enterprise
Simple steps to take control of SSL across the enterprise, and recommendations for a management platform for full visibility and single-point of control for these Certificates.