Slashdot Mirror


Hackers Find Home In Amazon EC2 Cloud

snydeq writes "Security researchers have spotted the Zeus botnet running an unauthorized command and control center on Amazon's EC2 cloud computing infrastructure. This marks the first time Amazon Web Services' cloud infrastructure has been used for this type of illegal activity, according to threat researcher Don DeBolt. The hackers got onto Amazon's infrastructure by hacking into a Web site hosted on Amazon's servers and then secretly installing their command and control infrastructure."

6 of 89 comments (clear)

  1. Re:If anything... by Anonymous Coward · · Score: 1, Informative

    And the security of Linux... You see , Amazon uses Apache + Linux in their cloud computing system, so the zealots have told me that such an attack is in fact impossible ;--)

  2. Not Amazon that got hacked by Meshach · · Score: 3, Informative

    According to the article it was not Amazon itself that got hacked but an "unidentified website on Amazon's cloud" that got hacked. The hackers then used that website to get onto the cloud and execute code.

    --
    "Maybe this world is another planet's hell"
    Aldous Huxley
    1. Re:Not Amazon that got hacked by nacturation · · Score: 2, Informative

      According to the summary too: "The hackers got onto Amazon's infrastructure by hacking into a Web site hosted on Amazon's servers..."

      No different than "a web site hosted on Rackspace's servers". I agree with the other posts that this is essentially a non-news item. So a server gets hacked. It doesn't matter that the server is in someone's basement or in a colo or a VM somewhere.

      --
      Want to improve your Karma? Instead of "Post Anonymously", try the "Post Humously" option.
  3. This is not new by ub3r+n3u7r4l1st · · Score: 2, Informative

    If you search "Xbox Host booting" on YouTube, there are hundreds of videos showing you how to utilize the mass computing power of the cloud to knock your opponent off from a Halo 3 session and get the win.

  4. Re:Nothing really special by DaTroof · · Score: 2, Informative

    According to the second article, it has been fixed.

    Please Note:The legitimate hacked website was contacted and informed about its participation in the Zeus bot activity and accordingly has stopped serving the malicious variant.

  5. Re:And? by TooMuchToDo · · Score: 4, Informative

    Link next time. I had to waste 10 seconds googling =) http://rationalwiki.com/wiki/Poe's_Law