[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-security] Should I be worried?



<johan@xxxxxxxxxx> wrote:
> Where do these people find our servers?  From the Cobalt lists

Perhaps.  But it would be much easier for them to scan blocks associated
with web farms or just scan random IPs.

> or perhaps by
> trying address blocks assigned to well-known RaQ ISP's?

That's likely.  Last week I spoke with a RaQ owner who said that his servers
and many (or maybe all) others at the same web farm were hacked and rooted.
The fact that most hacks involved exploiting a server that wasn't explicitly
targeted means that no one is safe, no matter how unimportant or obscure the
server is believed to be.

--
Steve Werby
President, Befriend Internet Services LLC
http://www.befriend.com/