• Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
Tech News, Magazine & Review WordPress Theme 2017
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
Blog - Creative Collaboration
No Result
View All Result
Home Internet

Hackers are on the hunt for Oracle servers vulnerable to potent exploit

October 29, 2020
Share on FacebookShare on Twitter

Hackers are scanning the Internet for machines that have yet to patch a recently disclosed flaw that force Oracle’s WebLogic server to execute malicious code, a researcher warned Wednesday night.

Johannes Ullrich, dean of research at the SANS Technology Institute, said his organization’s honeypots had detected Internetwide scans that probe for vulnerable servers. CVE-2020-14882, as the vulnerability is tracked, has a severity rating of 9.8 out of 10 on the CVSS scale. Oracle’s October advisory accompanying a patch said exploits are low in complexity and require low privileges and no user interaction.

“At this point, we are seeing the scans slow down a bit,” Ullrich wrote in a post. “But they have reached ‘saturation’ meaning that all IPv4 addresses have been scanned for this vulnerability. If you find a vulnerable server in your network: Assume it has been compromised.”

Honeypots are servers that are deliberately left exposed or unpatched. They’re meant to act as a barometer for tracking Internet attack activity. When hackers scan or exploit them, researchers know that specific vulnerabilities are under threat of attack.

Ullrich said in an interview that SANS honeypots have received GET Web requests that attempt to query whether a server is running a vulnerable version of WebLogic. The honeypots weren’t set up to respond that they were vulnerable, so he doesn’t yet know if the attackers are simply compiling a list of vulnerable machines or are actively exploiting them once they’re found.

Advertisement

In the past few hours, he configured the servers to indicate they’re vulnerable, but so far he has yet to see active exploits. He also said it’s possible that some of the scans are coming from people doing benign research.

The scans come amid warnings that Russian ransomware hackers are targeting hundreds of US hospitals and healthcare providers. Exploits as potent as those against CVE-2020-14882 would likely provide everything needed to initiate such an attack.

Vulnerable versions of WebLogic include 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Oracle credited voidfyoo of Chaitin Security Research Lab with its discovery.

Next Post

VPN by Google One: A VPN for Android, by Google

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

No Result
View All Result

Recent Posts

  • All Sealed Abyss Artifact Locations In Crimson Desert
  • Some Pixel owners are struggling with Android Auto after March update
  • NASA’s Artemis 2 astronauts prepare for launch in isolation
  • Pinterest CEO: Ban kids under 16 from social media
  • Widely used Trivy scanner compromised in ongoing supply-chain attack

Recent Comments

    No Result
    View All Result

    Categories

    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi
    • Home
    • Shop
    • Privacy Policy
    • Terms and Conditions

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    No Result
    View All Result
    • Home
    • Blog
    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    Get more stuff like this
    in your inbox

    Subscribe to our mailing list and get interesting stuff and updates to your email inbox.

    Thank you for subscribing.

    Something went wrong.

    We respect your privacy and take protecting it seriously