Cryptocurrency Miner Spreads via Old Vulnerabilities on Elasticsearch
We detected mining activity on our honeypot that involves the search engine Elasticsearch, which is a Java-developed search engine based on the Lucene library and released as open-source. The attack was deployed by taking advantage of known vulnerabilities CVE-2015-1427, a vulnerability in its Groovy scripting engine that allows remote attackers to execute arbitrary shell commands through a crafted script, and CVE-2014-3120, a vulnerability in the default configuration of Elasticsearch.
The post Cryptocurrency Miner Spreads via Old Vulnerabilities on Elasticsearch appeared first on .
Source:
Cryptocurrency Miner Spreads via Old Vulnerabilities on Elasticsearch