Feeds

Oracle refutes 'SSH hacking' slur

Mystery over bogus DenyHosts listing

Protecting against web application threats using SSL

An investigation by Oracle has revealed the none of its systems were involved in launching a recent brute force attack on secure servers around the net.

From the beginning of May until earlier this week, "compromised computers" at Oracle UK were listed among the ten worst offenders on the net for launching attacks on servers which run SSH (secure shell) server software, according to statistics from servers running DenyHosts software to block SSH brute-force password attacks. DenyHosts is a script for Linux system administrators designed to help thwart SSH server attacks. Around 6,800 users contribute to the data it collects.

Oracle servers - recorded as active since 3 May - featured at number nine of DenyHosts list. The listing implied a computer (or multiple computers) at Oracle UK been compromised for weeks, allowing hackers to gain access to Oracle's bandwidth to hack other boxes elsewhere on the net.

Following our inquiries last week, Oracle supplied us with a holding statement saying it was investigating the problem. The database giant concluded this investigation early this week. It says none of its systems were responsible for the attack.

"Security is a matter we take seriously at Oracle and our first priority is meeting customer needs and reducing their risk. As soon as Oracle was made aware of the situation we began an investigation, which is now complete. Oracle can confirm that none of its systems were responsible for an SSH brute force attack and the allegation of compromised computers at Oracle has been removed from the Deny Hosts website," it said.

So if DenyHosts's listing was erroneous how did the entry for the database giant get there in the first place. Reg reader Stephen has one theory:

"There are a couple of issues in the present DenyHosts that could cause a group to insert their favourite bad-guy site into the DenyHosts database. They all seem to be related to regular expression problems".

"I confirmed that one could insert false sites in by just spamming a bunch of sites with echo "string from oracle IP" as listed above. It is probably not the cause for this issue, but could be used as a cover," he adds.

We were unable to contact DenyHosts at the time of writing so the exact cause of the Oracle listing remains unclear. ®

Reducing the cost and complexity of web vulnerability management

More from The Register

next story
Spies would need SUPER POWERS to tap undersea cables
Why mess with armoured 10kV cables when land-based, and legal, snoop tools are easier?
Early result from Scots indyref vote? NAW, Jimmy - it's a SCAM
Anyone claiming to know before tomorrow is telling porkies
TOR users become FBI's No.1 hacking target after legal power grab
Be afeared, me hearties, these scoundrels be spying our signals
Jihadi terrorists DIDN'T encrypt their comms 'cos of Snowden leaks
Intel bods' analysis concludes 'no significant change' after whistle was blown
Home Depot: 56 million bank cards pwned by malware in our tills
That's about 50 per cent bigger than the Target tills mega-hack
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
China hacked US Army transport orgs TWENTY TIMES in ONE YEAR
FBI et al knew of nine hacks - but didn't tell TRANSCOM
Microsoft to patch ASP.NET mess even if you don't
We know what's good for you, because we made the mess says Redmond
NORKS ban Wi-Fi and satellite internet at embassies
Crackdown on tardy diplomatic sysadmins providing accidental unfiltered internet access
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.