On BNET: Dumb (but funny) career moves
BNET Business Network:
BNET
TechRepublic
ZDNet

September 14th, 2009

The Linux botweb story that wasn't ...

Posted by Adrian Kingsley-Hughes @ 3:23 am

Categories: Security

Tags: Web Server, Linux, Web Servers, UNIX, Operating Systems, Open Source, Software, Internet, Adrian Kingsley-Hughes

Late last Friday a story appeared on my radar that seemed interesting - it was about a botweb (a botnet made up of web servers) utilizing Linux web servers. Was Linux cracked? Would Linux fans have to wind in all their security bragging? Was the Linux fortress wall breached? Was the sky falling in?

Short answer, no.

Slightly longer answer, no, no, no and no.

If there was a way that hackers could crack Linux web servers and use them to create an huge botweb, then that would be a very big deal indeed. Botwebs, since they use web servers rather than zombie home or office PCs, make a far more effective botnet since they have a better connection to the internet. The idea of millions of compromised Linux web servers causing all sorts of mayhem isn’t a pretty picture.

Which is why the story was interesting.

But alas, this story doesn’t have anything to do with Linux hacks, but instead comes down to basic security, or the lack of it. It seems that the hack comes down to bad passwords. Hackers regularly sweep the web looking for vulnerable systems, which is why good passwords are vital. If your passwords are weak then the system can, and eventually will, be compromised. It doesn’t matter if it’s Windows-based or Linux-based.

Normal “Linux is more secure than Windows” bragging can resume …

Adrian Kingsley-HughesAdrian is a technology journalist and author who has devoted over a decade to helping users get the most from technology. He also runs a popular blog called The PC Doctor. See his full profile and disclosure of his industry affiliations

Want to get in touch? Got a tip? Feel free to drop me a note! I ALWAYS respect anonymity. I'm also on Twitter (@the_pc_doc)

Right to Reply: Should any industry representatives wish to comment on any posts on Hardware 2.0, I will be happy to publish their reply verbatim on this blog.

Subscribe to Hardware 2.0 via Email alerts or RSS.

  • Talkback
  • Most Recent of 29 Talkback(s)
RE: The Linux botweb story that wasn't ...
I have a feeling you're talking to a brick wall. What I don't understand is why they let Bill Gates post on this site.... (Read the rest)
Posted by: arlin5000@... Posted on: 09/22/09 You are currently: a Guest | | Terms of Use
One of the things that always confused me...  NStalnecker | 09/14/09
The short answer is yes.  Letophoro | 09/14/09
Thats what I was thinking  NStalnecker | 09/14/09
Not so much.  Letophoro | 09/14/09
Sorry  NStalnecker | 09/14/09
No more damaging. Just a little different.  Letophoro | 09/14/09
Already Answered, but in Other Words  DannyO_0x98 | 09/14/09
Passwords can be guessed  Tregi | 09/14/09
Which Is Why You Should Have a GOOD Strong One  drprod@... | 09/14/09
Source code has nothing to do...  bjbrock | 09/14/09
I wasn't referencing  NStalnecker | 09/14/09
re: I wasn't referencing...  Tsingi | 09/14/09
The answer is no unless you are storing  alaniane@... | 09/15/09
Telnet port are only open...  bjbrock | 09/14/09
Telnet is defaultly closed on Ubuntu...  DevJonny | 09/14/09
A botnet was still created...  eqpc | 09/14/09
RE:A botnet was still created...  richdave | 09/14/09
Maybe I wasn't clear..  eqpc | 09/14/09
Total number of advisories ...  MisterMiester | 09/14/09
Not at all.  eqpc | 09/14/09
re: SQL Injections  Tsingi | 09/14/09
Number of Reported Vulns is Meaningless  daengbo | 09/16/09
IIS is much worse...  bjbrock | 09/14/09
Wrong - IIS is much better...  SI-285 | 09/15/09
I disagree with your assumption on one ground  alaniane@... | 09/15/09
The user is always the weakest link  Ronny102 | 09/14/09
Assert what you want...Here are the facts!  SI-285 | 09/15/09
Your facts don't prove anything  alaniane@... | 09/15/09
RE: The Linux botweb story that wasn't ...  arlin5000@... | 09/22/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

Click Here
advertisement

Recent Entries

advertisement

Archives

ZDNet Blogs

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline