Thank you
Your message has been sent.
There was an error emailing this page.
Attackers are widely exploiting a recently patched vulnerability in Apache Struts that allows them to remotely execute malicious code on web servers.
Apache Struts is an open-source web development framework for Java web applications. It's widely used to build corporate websites in sectors including education, government, financial services, retail and media.
On Monday, the Apache Struts developers fixed a high-impact vulnerability in the framework's Jakarta Multipart parser. Hours later, an exploit for the flaw appeared on Chinese-language websites and this was almost immediately followed by real-world attacks, according to researchers from Cisco Systems.
The vulnerability is very easy to exploit and allows attackers to execute system commands with the privileges of the user running the web server process. If the web server is configured to run as root, the system is completely compromised, but executing code as a lower-privileged user is also a serious security threat.
What's even worse is that the Java web application doesn't even need to implement file upload functionality via the Jakarta Multipart parser in order to be vulnerable. According to researchers from Qualys, the simple presence on the web server of this component, which is part of the Apache Struts framework by default, is enough to allow exploitation.
"Needless to say we think this is a high priority issue and the consequence of a successful attack is dire," said Amol Sarwate, director of Vulnerability Labs at Qualys, in a blog post.
Companies who use Apache Struts on their servers should upgrade the framework to versions 2.3.32 or 2.5.10.1 as soon as possible.
Researchers from Cisco Talos have observed "a high number of exploitation events." Some of them only execute the Linux command whoami to determine the privileges of the web server user and are probably used for initial probing. Others go further and stop the Linux firewall and then download an ELF executable that's executed on the server.
"The payloads have varied but include an IRC bouncer, a DoS bot, and a sample related to the bill gates botnet," the Talos researchers said in a blog post.
According to researchers from Spanish outfit Hack Players, Google searches indicate 35 million web applications that accept "filetype:action" uploads and a high percentage of them are likely vulnerable.
It's somewhat unusual that attacks have started so quickly after the flaw was announced and it's not yet clear whether an exploit for the vulnerability already existed in closed circles before Monday.
Users who can't immediately upgrade to the patched Struts versions can apply a workaround that consists of creating a Servlet filter for Content-Type that would discard any requests not matching multipart/form-data. Web application firewall rules to block such requests are also available from various vendors.
Lucian Constantin is an IDG News Service correspondent. He writes about information security, privacy, and data protection.
Sponsored Links
Original post:
Hackers exploit Apache Struts vulnerability to compromise corporate web servers - Network World
- Mind uploading - 01 [Last Updated On: November 8th, 2009] [Originally Added On: November 8th, 2009]
- Mind uploading - 02 [Last Updated On: November 8th, 2009] [Originally Added On: November 8th, 2009]
- A new way to battle Mexican drug cartels - KLTV [Last Updated On: March 8th, 2010] [Originally Added On: March 8th, 2010]
- Mobile Health Screening Units Visit Lowe's Workers - International Supermarket News [Last Updated On: March 8th, 2010] [Originally Added On: March 8th, 2010]
- The quintessential sewing machine - Business Mirror [Last Updated On: March 8th, 2010] [Originally Added On: March 8th, 2010]
- The Future of Windows - Technologizer (blog) [Last Updated On: March 8th, 2010] [Originally Added On: March 8th, 2010]
- SEO Press Release Distribution Site Online PR News Celebrates 10000 Active Users - Online PR News (press release) [Last Updated On: March 8th, 2010] [Originally Added On: March 8th, 2010]
- Utilizing Online Mailing Services – Make the Most of Direct Marketing - RisMedia.com (press release) [Last Updated On: March 8th, 2010] [Originally Added On: March 8th, 2010]
- Carr's first look at 'Extreme' home - KLTV [Last Updated On: March 8th, 2010] [Originally Added On: March 8th, 2010]
- Should you advertise on iPhones? - Smart Company (blog) [Last Updated On: March 8th, 2010] [Originally Added On: March 8th, 2010]
- Review: Mega Man 10 - Destructoid [Last Updated On: March 8th, 2010] [Originally Added On: March 8th, 2010]
- Had I World Enough, and Time - Institute for Ethics and Emerging Technologies [Last Updated On: March 8th, 2010] [Originally Added On: March 8th, 2010]
- Unicast Continues Innovative Technology Enhancements With Latest Release of ... - CNNMoney.com (press release) [Last Updated On: March 16th, 2010] [Originally Added On: March 16th, 2010]
- Facebook scouts for 'passionate' India head - Economic Times [Last Updated On: March 16th, 2010] [Originally Added On: March 16th, 2010]
- SXSW: YouTube Launches Partner Program for Indie Bands - Wired News [Last Updated On: March 17th, 2010] [Originally Added On: March 17th, 2010]
- Wider Still and Wider! - Bangkok Post [Last Updated On: March 17th, 2010] [Originally Added On: March 17th, 2010]
- P2P Versus The World - Rampage [Last Updated On: March 17th, 2010] [Originally Added On: March 17th, 2010]
- Yakuza 3 - The MMOMFG Review - MMOMFG (blog) [Last Updated On: March 17th, 2010] [Originally Added On: March 17th, 2010]
- Behind the musings: The annotated high schools column - Chicago Tribune (blog) [Last Updated On: March 17th, 2010] [Originally Added On: March 17th, 2010]
- Jihad Jane, YouTube, and Me - David Horowitz's NewsReal Blog (blog) [Last Updated On: March 17th, 2010] [Originally Added On: March 17th, 2010]
- Justin Bieber Releases 'U Smile,' Announces Summer Tour Dates - MTV.com [Last Updated On: March 17th, 2010] [Originally Added On: March 17th, 2010]
- FCC announces National Broadband Plan - VentureBeat [Last Updated On: March 17th, 2010] [Originally Added On: March 17th, 2010]
- Image hosting on the cheap: a look at three free services - Ars Technica [Last Updated On: March 17th, 2010] [Originally Added On: March 17th, 2010]
- Content Management: Secrets of the Trade - Formtek Blog (blog) [Last Updated On: March 17th, 2010] [Originally Added On: March 17th, 2010]
- FCC's National Broadband Plan: There is a dark side - ZDNet [Last Updated On: March 17th, 2010] [Originally Added On: March 17th, 2010]
- 5 Reasons Old Media Should Buy Facebook - AllFacebook (blog) [Last Updated On: March 17th, 2010] [Originally Added On: March 17th, 2010]
- "Steal It" and Other Internal YouTube Emails from Viacom's Copyright Suit - Fast Company [Last Updated On: March 19th, 2010] [Originally Added On: March 19th, 2010]
- Now cafes in monument premises for tourists during CWG - Sify [Last Updated On: March 19th, 2010] [Originally Added On: March 19th, 2010]
- Google-Viacom court papers leave a lot to the imagination - FierceOnlineVideo [Last Updated On: March 19th, 2010] [Originally Added On: March 19th, 2010]
- FCC's broadband plan: A possible dream - Washington Post (blog) [Last Updated On: March 19th, 2010] [Originally Added On: March 19th, 2010]
- The Importance of Using Social Networking for Business; Part I – Facebook - IPWatchdog.com [Last Updated On: March 19th, 2010] [Originally Added On: March 19th, 2010]
- Recording YouTube Videos - Acoustic Guitar [Last Updated On: March 19th, 2010] [Originally Added On: March 19th, 2010]
- Who's using location-based social networking? - KC Free Press [Last Updated On: March 20th, 2010] [Originally Added On: March 20th, 2010]
- iPhone will continue to beckon BlackBerry owners - CNET [Last Updated On: March 20th, 2010] [Originally Added On: March 20th, 2010]
- Rain leaves its mark on Azalea Trail events - KLTV [Last Updated On: March 21st, 2010] [Originally Added On: March 21st, 2010]
- Viacom v. YouTube/Google: A Piracy Case in Their Own Words - DailyFinance [Last Updated On: March 21st, 2010] [Originally Added On: March 21st, 2010]
- Getting a look at next high-tech | Philadelphia Inquirer | 03/22/2010 - Philadelphia Inquirer [Last Updated On: March 22nd, 2010] [Originally Added On: March 22nd, 2010]
- Sprint chews on Apple while lauding 4G Overdrive hotspot - The Tech Herald [Last Updated On: March 22nd, 2010] [Originally Added On: March 22nd, 2010]
- 'Repo Men' contest -- the nationwide chase is almost over - Los Angeles Times (blog) [Last Updated On: March 22nd, 2010] [Originally Added On: March 22nd, 2010]
- Viacom vs. YouTube/Google: A Piracy Case in Their Own Words - DailyFinance [Last Updated On: March 22nd, 2010] [Originally Added On: March 22nd, 2010]
- These iPhone apps will help make March Madness a little more sane - Appolicious [Last Updated On: March 22nd, 2010] [Originally Added On: March 22nd, 2010]
- Eye-Fi Pro X2 cards have arrived, and you probably want one - tuaw.com (blog) [Last Updated On: March 23rd, 2010] [Originally Added On: March 23rd, 2010]
- Pharmacist shows who wins, loses with health care bill - KLTV [Last Updated On: March 23rd, 2010] [Originally Added On: March 23rd, 2010]
- High-Tech Texts! - The Campus Slate [Last Updated On: March 24th, 2010] [Originally Added On: March 24th, 2010]
- CTIA WIRELESS 2010: Samsung's New Galaxy Brings 4" AMOLED Screen, Social Hub ... - Marketnews.ca [Last Updated On: March 24th, 2010] [Originally Added On: March 24th, 2010]
- Google must follow Chinese rules or leave - China Daily [Last Updated On: March 24th, 2010] [Originally Added On: March 24th, 2010]
- Jay-Z Short Documentary 'NY-Z' Premieres Online - MTV.com [Last Updated On: March 24th, 2010] [Originally Added On: March 24th, 2010]
- DAs clash over Mineola sex ring appeal - KLTV [Last Updated On: March 25th, 2010] [Originally Added On: March 25th, 2010]
- iSilo for iPhone - BusinessWeek [Last Updated On: March 26th, 2010] [Originally Added On: March 26th, 2010]
- Questions Abound as "New START" Agreement is Completed - Global Security Newswire [Last Updated On: March 26th, 2010] [Originally Added On: March 26th, 2010]
- What will Apple do next in mobile services? - Mobile Entertainment [Last Updated On: March 26th, 2010] [Originally Added On: March 26th, 2010]
- How much is too much to pay for health care? - Anchorage Daily News [Last Updated On: March 27th, 2010] [Originally Added On: March 27th, 2010]
- The Future of Smartphones: 4G and Beyond - Entrepreneur [Last Updated On: March 27th, 2010] [Originally Added On: March 27th, 2010]
- Uploading and uplifting: sharing big data files - Earthtimes (press release) [Last Updated On: March 28th, 2010] [Originally Added On: March 28th, 2010]
- Verizon Blasts 'Outdated' FCC Broadband Plan - NewsFactor Network [Last Updated On: March 28th, 2010] [Originally Added On: March 28th, 2010]
- Web Host Layered Tech Offers Mezeo-Powered Cloud Storage - Web Host Industry Review [Last Updated On: March 29th, 2010] [Originally Added On: March 29th, 2010]
- Dropbox: Now one more reason to want a Nexus One - ZDNet (blog) [Last Updated On: March 30th, 2010] [Originally Added On: March 30th, 2010]
- Exaflood: Politicians Prop Up Dinosaurs, Ignore Cutting Edge Technology - NewsBlaze (press release) [Last Updated On: March 30th, 2010] [Originally Added On: March 30th, 2010]
- Instructions - Washington Post [Last Updated On: March 30th, 2010] [Originally Added On: March 30th, 2010]
- Uploading for Life Extension Will Be Valid - Institute for Ethics and Emerging Technologies [Last Updated On: March 31st, 2010] [Originally Added On: March 31st, 2010]
- 'Glee's' MySpace Auditions: What Not To Sing - Wall Street Journal (blog) [Last Updated On: March 31st, 2010] [Originally Added On: March 31st, 2010]
- Memeo iPad Reader: Like the GDrive on your iPad (only different) - ZDNet (blog) [Last Updated On: April 1st, 2010] [Originally Added On: April 1st, 2010]
- Why are pipe bomb 'how to' videos legal? Answer is alarming - KLTV [Last Updated On: April 1st, 2010] [Originally Added On: April 1st, 2010]
- Trip to Haiti inspiration for East Texas teen - KLTV [Last Updated On: April 1st, 2010] [Originally Added On: April 1st, 2010]
- Jason Kilar Leads Hulu To Profitability, But Will He Stay On At Hulu? - TVbytheNumbers [Last Updated On: April 2nd, 2010] [Originally Added On: April 2nd, 2010]
- Layers for IPad Adds Online Gallery, Pro Options - PC World [Last Updated On: April 2nd, 2010] [Originally Added On: April 2nd, 2010]
- Shane Dawson, YouTube's Comic for the Under-30 Set - New York Times [Last Updated On: April 2nd, 2010] [Originally Added On: April 2nd, 2010]
- Hands-On With the Apple iPad — and Your Questions - Wired News [Last Updated On: April 4th, 2010] [Originally Added On: April 4th, 2010]
- FedEx Simplifies International Shipping with FedEx Electronic Trade Documents - MarketWatch (press release) [Last Updated On: April 6th, 2010] [Originally Added On: April 6th, 2010]
- Cacoo Lets Multiple Users Create Designs Collaboratively And In Real-time - TechCrunch (blog) [Last Updated On: April 7th, 2010] [Originally Added On: April 7th, 2010]
- Comcast: Your New Overlord - ITworld.com [Last Updated On: April 7th, 2010] [Originally Added On: April 7th, 2010]
- Bloggers Photograph Food, We Get Hungry - Switched (blog) [Last Updated On: April 7th, 2010] [Originally Added On: April 7th, 2010]
- Apple suggests only the iPhone can fingerprint songs - Geek.com [Last Updated On: April 7th, 2010] [Originally Added On: April 7th, 2010]
- Senior with mental challenges killed along highway - KLTV [Last Updated On: April 7th, 2010] [Originally Added On: April 7th, 2010]
- Book a Cruise and "Flip" Over a Free Camcorder - CruiseCritic.co.uk [Last Updated On: April 8th, 2010] [Originally Added On: April 8th, 2010]
- Creation Myths: what the argument that the iPad's not for creating content ... - Huffington Post (blog) [Last Updated On: April 8th, 2010] [Originally Added On: April 8th, 2010]
- Want market share? Make a brain claim - Marketing Web [Last Updated On: April 8th, 2010] [Originally Added On: April 8th, 2010]
- 10 Ways World of Warcraft - OUPblog (blog) [Last Updated On: April 8th, 2010] [Originally Added On: April 8th, 2010]
- Check-in to Foursquare: Latest social media service lands in SW Florida - Naples Daily News [Last Updated On: April 8th, 2010] [Originally Added On: April 8th, 2010]
- Apple iPhone OS 4 Announcement Makes Users Feel "Finally!" - HULIQ [Last Updated On: April 8th, 2010] [Originally Added On: April 8th, 2010]