{"id":155402,"date":"2016-02-17T13:01:44","date_gmt":"2016-02-17T11:01:44","guid":{"rendered":"http:\/\/mybroadband.co.za\/news\/?p=155402"},"modified":"2016-02-17T14:11:53","modified_gmt":"2016-02-17T12:11:53","slug":"critical-security-bug-hits-south-african-websites","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/cloud-hosting\/155402-critical-security-bug-hits-south-african-websites.html","title":{"rendered":"Critical security bug hits South African websites"},"content":{"rendered":"<p>A severe vulnerability recently uncovered in the widely-used GNU C Library (glibc) can cause severe security problems for websites if they don\u2019t patch soon.<\/p>\n<p>Ars Technica <strong><a href=\"http:\/\/arstechnica.com\/security\/2016\/02\/extremely-severe-bug-leaves-dizzying-number-of-apps-and-devices-vulnerable\/\">recently reported<\/a><\/strong> that the bug was introduced in 2008 in a function known as <code>getaddrinfo()<\/code>, and affects all kinds of devices \u2014 not just web servers.<\/p>\n<p>All versions of glibc after 2.9 are vulnerable to a buffer overflow bug that lets attackers remotely execute malicious code.<\/p>\n<p>It can be exploited in a number of ways, such as when vulnerable devices or applications perform domain name lookups on attacker-controlled domains, or domain name servers.<\/p>\n<p>Researchers have warned that tools such as SSH, sudo, wget, and curl are all known to be vulnerable.<\/p>\n<p>Ars reported that one Linux-based platform that is not vulnerable is Android, with Google explaining that it uses a substitute for glibc called Bionic.<\/p>\n<h3 class=\"my-4\">Hetzner servers patched<\/h3>\n<p>Hetzner has sent an alert to its custom hosting customers informing them about the vulnerability, and recommending that they reboot their servers.<\/p>\n<p>All affected services on Hetzner\u2019s managed server platform will be restarted without the servers themselves being rebooted.<\/p>\n<p>This is in order to minimise the impact on customers, and is in line with Debian\u2019s security advisory, Hetzner said.<\/p>\n<h3 id=\"related\">More security and hosting news<\/h3>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/155278-anonymous-hacks-and-leaks-south-african-government-data.html\"><strong>Anonymous hacks and leaks South African government data<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/155104-the-south-african-government-passwords-cracked-in-anonymous-database-hack.html\"><strong>The South African government passwords cracked in Anonymous database hack<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/hosting-storage\/126798-hetzner-partners-with-dfa-to-offer-greater-isp-choice.html\"><strong>Hetzner partners with DFA to offer greater ISP choice<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/hosting-storage\/116642-inside-hetzners-new-data-centre.html\"><strong>Inside Hetzner\u2019s new data centre<\/strong><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Many Linux-hosted websites, including those hosted in South Africa, are vulnerable to a \u201cpotentially catastrophic\u201d flaw in a core software library.<\/p>\n","protected":false},"author":23,"featured_media":155408,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[25,27],"tags":[35558,35,1065],"class_list":["post-155402","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cloud-hosting","category-security","tag-glibc","tag-headline","tag-hetzner"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/155402"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/23"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=155402"}],"version-history":[{"count":0,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/155402\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/155408"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=155402"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=155402"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=155402"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}