한국 조직의 HAProxy에서 발견된 새로운 백도어가 웹 트래픽을 가로채고 있다.
새로운 리눅스 툴킷인 'ted'가 두 개의 한국 조직의 HAProxy 로드 밸런서에 숨겨져 발견되었다. 이 백도어는 웹 트래픽을 가로채고 선택된 방문자에게 수정된 페이지를 제공한다. 이는 HAProxy의 취약점이 아니며, 호스트에서 코드 실행이 필요하다.
A new backdoor named 'ted' is found in HAProxy of South Korean organizations, intercepting web traffic.
A new Linux toolkit called 'ted' has been discovered embedded in the HAProxy load balancers of two South Korean organizations. This backdoor intercepts web traffic and serves altered pages to selected visitors. It's important to note that this isn't a vulnerability in HAProxy itself, but requires code execution on the host to install.