Xansen
Постоялец
- Регистрация
- 30 Мар 2006
- Сообщения
- 435
- Реакции
- 124
- Автор темы
- #1
Друзья, гуру, прошу совета, не понимаю что они от меня хотят. Вот текст абузы:
Please note:
This is an automatically generated message.
Please do not reply to the sender.
For queries, please contact: certbund@bsi.bund.de
[CERT-Bund#2015012628000389]
Dear Sir or Madam
Memcached[1] is an open source cache server which is used to store and
retrieve data from memory easily. Memcached is frequently used in
connection with web applications. The memcached server does not support
any authentication, so that attackers have unrestricted access to the data
stored in the cache if the server is reachable from the Internet. This
makes it possible for attackers to potentially spy out information from
the systems which are affected, such as login data for web applications
or other confidential content.
Memcached servers have been identified by the Shadowserver 'Open Memcached
Key-Value Store Scanning Project'[2] which are openly accessible from the
Internet.
We are sending you the following list of affected systems in your net area.
The timestamp (UTC time zone) shows when the system was checked and when
an open memcached server was identified.
We kindly request that you examine the situation and take measures to
safeguard the memcached servers on the systems concerned or inform your
customer accordingly.
References:
[1] Memcached
<Для просмотра ссылки Войдиили Зарегистрируйся
[2] Shadowserver: Open Memcached Key-Value Store Scanning Project
<Для просмотра ссылки Войдиили Зарегистрируйся
24940 | [здесь мой IP адрес] | 2015-01-26 02:04:55 | 11211 | 1.4.13
Kind regards
Team CERT-Bund
Bundesamt für Sicherheit in der Informationstechnik (BSI)
Referat C21 - CERT-Bund
Godesberger Allee 185-189
D-53175 Bonn
Подскажите, что это значит и что мне нужно сделать. Спасибо!
Please note:
This is an automatically generated message.
Please do not reply to the sender.
For queries, please contact: certbund@bsi.bund.de
[CERT-Bund#2015012628000389]
Dear Sir or Madam
Memcached[1] is an open source cache server which is used to store and
retrieve data from memory easily. Memcached is frequently used in
connection with web applications. The memcached server does not support
any authentication, so that attackers have unrestricted access to the data
stored in the cache if the server is reachable from the Internet. This
makes it possible for attackers to potentially spy out information from
the systems which are affected, such as login data for web applications
or other confidential content.
Memcached servers have been identified by the Shadowserver 'Open Memcached
Key-Value Store Scanning Project'[2] which are openly accessible from the
Internet.
We are sending you the following list of affected systems in your net area.
The timestamp (UTC time zone) shows when the system was checked and when
an open memcached server was identified.
We kindly request that you examine the situation and take measures to
safeguard the memcached servers on the systems concerned or inform your
customer accordingly.
References:
[1] Memcached
<Для просмотра ссылки Войди
[2] Shadowserver: Open Memcached Key-Value Store Scanning Project
<Для просмотра ссылки Войди
24940 | [здесь мой IP адрес] | 2015-01-26 02:04:55 | 11211 | 1.4.13
Kind regards
Team CERT-Bund
Bundesamt für Sicherheit in der Informationstechnik (BSI)
Referat C21 - CERT-Bund
Godesberger Allee 185-189
D-53175 Bonn
Подскажите, что это значит и что мне нужно сделать. Спасибо!