Back to the feed

~/article/new-ted-backdoor-hides-inside-victims-own-haproxy-builds-to-intercept-we-1wcquh
mediumSource: The Hacker News

New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic

A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors. The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it requires code execution on the host and

Read at the source

Summary written for cymesh.dev. The full article lives at The Hacker News.

~/cymesh.net

Certificates expire quietly

cymesh.net watches your TLS and SSL certificates and warns you before one lapses.

monitorsTLS/SSL expiry, chain and hostnamealertsemail, ahead of the expiry datescopenon-intrusive, read-only checks

Related

~/related/new-ted-backdoor-hides-inside-victims-own-haproxy-builds-to-intercept-we-1wcquh