
09-13-2017, 08:26 PM
|
 |
Administrator
|
|
Join Date: 10-29-07
Location: Canada
Posts: 26,707
|
|
Elasticsearch Servers and Amazon Web Services
Those of you using or considering using Amazon Web Servers might want to read the whole article linked to below:
Quote:
Thousands of insecure Elasticsearch servers are hosting point-of-sale malware, according to an analysis by Kromtech Security Center. In total, researchers found 15,000 insecure Elasticsearch servers with 27 percent (4,000) hosting the PoS malware strains Alina and JackPoS...
...Kromtech said 99 percent of compromised ElasticSearch servers were hosted on Amazon Web Services’ platform. “Every infected ES Server became a part of a bigger PoS botnet with command-and-control (C&C) functionality for PoS malware clients,” Diachenko wrote....
...Insecure ElasticSearch, Amazon Web Services and MongoDB databases are nothing new. Over the past 12 months there have been numerous instances of the cloud-based servers either having data destroyed, held for ransom or sensitive information leaked....
|
Thousands of Elasticsearch Servers Hijacked to Host PoS Malware
|