[SANS ISC Diary] Backup Files Are Good but Can Be Evil

I published the following diary on “Backup Files Are Good but Can Be Evil“.

Since we started to work with computers, we always heard the following advice: “Make backups!”. Everytime you have to change something in a file or an application, first make a backup of the existing resources (code, configuration files, data). But, if not properly managed, backups can be evil and increase the surface attack of your web application… [Read more]


  Of course they can. For instance, way back in the day when malware used to first start hiding in the sysvol backup copies for system restore. "Oh no biggie, let me restore to the day before…" Yup, still infected.

