Home / Companies / Sysdig / Blog / May 2014

May 2014 Summaries

2 posts from Sysdig

Filter
Month: Year:
Post Summaries Back to Blog
Sysdig 0.1.82 has been released as a maintenance update, setting the stage for more significant future developments. This release is part of an ongoing effort to enhance Sysdig's capabilities, particularly through initiatives like Falco Feeds, which provides open-source-focused companies with continuously updated, expert-written security rules to counter emerging threats. Users can access community support via the Sysdig mailing list, and report bugs or issues through GitHub, ensuring that the software remains responsive to user needs and security challenges.
May 08, 2014 128 words in the original blog post.
In an intriguing exploration of Linux server vulnerabilities, Gianluca Borello deliberately set up poorly configured servers to observe and analyze real-world cyberattacks, capturing the entire process using Sysdig. By exposing these servers, he quickly attracted attackers who compromised a server within four hours, installing IRC bots and a rootkit to launch a DoS attack and hide their tracks by altering logs and replacing binaries. Borello's detailed analysis, achieved through Sysdig's system call tracking, revealed the attacker's methods, including the use of perl scripts disguised as common system processes to execute commands and evade detection. This experiment not only provided valuable insights into common attack vectors and hacker behavior but also highlighted the effectiveness of Sysdig in monitoring and analyzing system activity during security breaches. The exercise underscores the importance of robust server configurations and continuous monitoring to defend against such vulnerabilities in real-world scenarios.
May 05, 2014 2,646 words in the original blog post.