Hackers Find Home In Amazon EC2 Cloud
snydeq writes "Security researchers have spotted the Zeus botnet running an unauthorized command and control center on Amazon's EC2 cloud computing infrastructure. This marks the first time Amazon Web Services' cloud infrastructure has been used for this type of illegal activity, according to threat researcher Don DeBolt. The hackers got onto Amazon's infrastructure by hacking into a Web site hosted on Amazon's servers and then secretly installing their command and control infrastructure."
This is going to Kindle a debate about the merits and demerits of the cloud.
Always proofread carefully to see if you any words out.
There is nothing intrinsic to a cloud of computers that makes them any different then the internet in general. Anything that makes use of unprotected computers on the internet will make use of a cloud as well. In fact, from a logical perspective, the internet is a cloud. Its just that access is generally curtailed in some way.
"Have you ever thought about just turning off the TV, sitting down with your kids, and hitting them?"
Hackers break into website, but it happens to be hosted on EC2. Hosting in cloud doesn't automagically make your sites more secure.
Extreme Programming - Redundant Array of Inexpensive Developers
"This marks the first time Amazon Web Services' cloud infrastructure has been used for this type of illegal activity"
So, has it been used for other illegal things that have been reported on? Is it even possible for anyone to find out all the possible illegal uses of technolgies like cloud computing?
You know, if bot net operators are trusting the EC2 cloud for their mission critical operations, it has to be ready for prime time.
This is a stunning endorsement. Amazon should send out a press release.
According to the article it was not Amazon itself that got hacked but an "unidentified website on Amazon's cloud" that got hacked. The hackers then used that website to get onto the cloud and execute code.
"Maybe this world is another planet's hell"
Aldous Huxley
If you search "Xbox Host booting" on YouTube, there are hundreds of videos showing you how to utilize the mass computing power of the cloud to knock your opponent off from a Halo 3 session and get the win.
New Economic Perspectives
I love that " ...then secretly installing their command and control infrastructure." statement.
When was the last time a criminal came up to your admin and said, "Hi, I'm going to install my unwanted rootkit on your server now so I can use it as a botnet."?
Yeah, it's like saying a burglar secretly robbed your house... Like he's really going to send you a postcard saying, "Tonight when you go to the movies, I'm going to pillage your apt.".
"This marks the first time Amazon Web Services' cloud infrastructure has been used for this type of illegal activity"
So, has it been used for other illegal things that have been reported on? Is it even possible for anyone to find out all the possible illegal uses of technolgies like cloud computing?
I'm willing to bet that folks like Apple, Google, Amazon, and Microsoft are already hiring "security consultants" to act as deniable intermediaries to other consultants using semi-legal (or flat-out illegal) means to gather information. Not only are arrangements like this being used for industrial espionage, but to gather intelligence on illegal operators who might hack into or otherwise subvert corporate resources like AWS or Google's cloud. This would just be an extension of what companies already do with "private detectives."
Someone needs to start writing novels about this!
The interesting thing about this case, to me, is that Amazon's lawful customer will receive a bill in the mail for hacker usage charges.
...since we all know IRC is where hackers go to talk when they don't want to be overheard.
Is it even possible for anyone to find out all the possible illegal uses of technolgies like cloud computing?
Yes. They're exactly the same as all the possible illegal uses of any other kind of computing.
That's what they get for using windows. Every windows box in existence has been compromised seconds after hooking it up to the internet
Hosting in cloud doesn't automagically make your sites more secure.
You mean... I still have to have people who can "manage" my systems?
NOOOO!!!!
Deleted
How is the billing issue different?
Most hosting services are prepaid. Should customers of a $30 VPS hosting plan also receive credit when a hacker exploits a poorly coded PHP file and uses resources of their VPS? Very similar scenario.
The real story here is not that it was on EC2. The resource suggests this is the first time EC2 has been used for such a purpose....... but EC2 instances have been compromised before -- as everyone else has already posted, all servers will have these vulnerabilities.
I bet someone was using it to buff their ratings!
http://www.abox.org
Avery Howell
Thundercloud... subs?
-l
Help cure AIDS, cancer, and more. Donate your unused computer time to worldcommunitygrid.org. Join Team Slashdot!
Is it even possible for anyone to find out all the possible illegal uses of technolgies like cloud computing?
Yes, it is possible. However, it is the same as trying to win a war against jealousy or envy.
I know you sign my performance reviews every year, but that doesn't mean you can invade my home like this.
Dare to Hope. Prepare to be Disappointed.
"This marks the first time Amazon Web Services' cloud infrastructure has been used for this type of illegal activity"
I posted to my blog back in June that Amazon cloud nodes were compromised and performing brute force SSH scans against some of my hosts.
This story and my post merely highlight the obvious fact that most cloud services are just scalable hosting. Remember your instance / slice / vm can be compromised like any other web host.
Amazon Cloud Service Brute Force Attacks
Is this new? Various AWS based IP's have been trying to hookup with my server by fondling it's SSH port for a while now. Damn AWS perverts. Can't keep their sockets and packets to themselves.
I'm seeing attempts to access a bunch of non-existent but suspicious files on my server (most recent at 12:32 EST today)
mydomain.com/
install.txt , cart, zencart, zen-cart, zen, shop, bulk, zcart, shop2, catalog, mobile, iphone, mobi, m, boutique, cart, store
None of these things exist on my server, and it -might be the case- that a legitimate web crawler would look for mobile web customizations in mobile, mobi, iphone or even m, the rest of these make absolutely no sense for anything other than nefarious purposes...
I'm also seeing attacks against
phpMyAdmin, phpmyadmin, mysql, ok.txt
(There are some significant advantages to running a "dumb" webserver without ASP, PHP, JSP, etc :-)
I need to figure out a way to have a 'blacklist file', such that any attempt to access these files adds the requester to a blacklist.
err wait...
---- Booth was a patriot ----
Which is no different than any system that gets hacked/taken over. There is a cost associated with the intrusions *somewhere* along the way. It may be a 3rd party hosting charge, bandwidth or just your time (which may be considerable) in repairing graffiti, clearing your good name etc.
Rich people are eccentric. Poor people are strange. Me, I'd be happy with odd.
Crackers, not Hackers
VMs have been compromised through some exploit that has nothing to do with Amazon. The exploit allowed C&C component of a botnet to lodge itself into the hosting machine(s). And ... it's news because Amazon is hosting? The machines are only as secure as the images provided to Amazon, are they not?
I had an astrix server honeypot being actively attacked and then compromised by Amazon EC2 instances. After making a bunch of calls to Amazon, it was confirmed that the instance had been compromised and the admins had been contacted. This was two years ago!
Let me see if I can find those emails...
Hello from Amazon.com.
We're sorry to hear you've experienced issues with the malware/penetration attempts coming from Amazon cloud computing servers.
The symptoms you've reported are consistent with malicious software (malware), such as a virus or spyware, installed on your computer. If your computer has been infected with this type of software, it can replace images in the Amazon.com advertisement slots or generate pop-up ads with images that are not intentionally inserted by Amazon or our advertising partners.
followed by a bunch of stuff relevant to delousing Windows desktops...
You've lost that argument, you might as well give it up.
Also, ^W (delete word) not ^H^H^H^H^H^H^H.
It's official. Most of you are morons.