Follow Us

Novell server under attack

Hackers not playing the game

A company server at Novell, apparently used by employees for gaming purposes, has been hacked to scan for vulnerable ports on potentially millions of computers worldwide.

Chris Brandon, president of Brandon Internet Security, reported the problem to Novell. He said he had been first alerted to the hack when a client reported scanning activity several days ago.

The scans, which have been going on since 21 September use Port 22 - the default port for Secure Shell (SSH) services. SSH programs are used to log into other computers over a network or to execute remote commands and move files between machines in a secure fashion. Scans against the port are often an indication that hackers are looking for vulnerable SSH systems that they can break into and take control of.

Kevan Barney, a Novell spokesman, Wednesday confirmed that one of the company’s systems had been compromised. But he added that the server was not part of the company’s corporate network nor was it a production server.

According to Brandon, the scans were traced back to a server with an IP address assigned to Novell. The hacked system appeared to be running a mail server for a gaming site called Neticus, and the main game web page for Neticus.com was hosted on a separate server that also belonged to Novell.

Going by the large number of IP blocks scanned by the attacking server, it is safe to assume that "millions" of computers may have been probed for SSH-related weaknesses, he said.

"The employees that set it up apparently had no idea of security," Brandon said. "But what is really surprising is that Novell would allow employees to set up game servers on their corporate network and then allow the public to access it."

Logs documenting the scans from the Novell-owned computer were made available to Computerworld by Brandon. One of them is available online.

Barney said that both servers - the one hosting the gaming website and the server that scanned for vulnerable ports on other machines - were test systems outside the company’s firewalls. He also denied that the server hosting the main game web page was actually being used by gamers. Instead, it appears to have been used only to host game-related information, he said.

"There was no major breach of security here," Barney said. "Needless to say, we are taking the appropriate steps" to address the situation.

Attempts to access the Neticu site this afternoon were unsuccessful. But a search for the site yielded references to a group called the Neticus Guild which described itself as a World of Warcraft players. The site appears to have been administered by someone using a Novell.com address.






Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

State of software security report volume 4

If your business has anything worth protecting, be it money, intellectual property or a trusted...

Download Whitepaper

New threats demand innovative responses

Financial institutions in the UK remain susceptible to further systemic problems, as challenging...

Download Whitepaper

Delivering a competitive advantage through IT

IT organisations share a common mission; to optimise investments and streamline operations to...

Download Whitepaper

6 tips to mobilise your existing ERP

Enterprise mobile users throughout the global business community will number 1.19 billion by...

Download Whitepaper

Techworld UK - Technology - Business

Techworld Awards

Techworld Awards Winners 2011


Learn who the winners of this year's Techworld Awards are. Video footage coming soon...

Find out more
Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

Site Map

* *