Language Selection

English French German Italian Portuguese Spanish

Linux/Lupper.worm rears its ugly head

Filed under
Security

This worm spreads by exploiting web servers hosting vulnerable PHP/CGI scripts. It is a modified derivative of the Linux/Slapper and BSD/Scalper worms from which it inherits the propagation strategy. It scans an entire class B subnet created by randomly choosing the first byte from an hard-coded list of A classes and randomly generating the second byte.

The worm blindly attacks web servers by sending malicious http requests on port 80. If the target server is running one of the vulnerable scripts at specific URLs and is configured to permit external shell commands and remote file download in the PHP/CGI environment, a copy of the worm could be downloaded and executed.

Like its precedents, the infected computers form a global network of compromised servers based on peer to peer communication principles. This network can be used, for example, for Distributed Denial of Service (DDoS) attacks or other purposes because it can accept remote commands. It is also capable of harvesting email addresses stored in files on the web server.

More Details.

More in Tux Machines

Security News

  • Wednesday's security updates
  • This Android botnet relies on Twitter for its commands
  • Android Security Flaw Exposes 1.4B Devices [Ed: Alternative headline is, "Android is very popular, it has billions of users. And yes, security ain’t perfect." When did the press ever publish a headline like, "Windows flaw leaves 2 billion PCs susceptible for remote takeover?" (happens a lot)]
  • Wildfire ransomware code cracked: Victims can now unlock encrypted files for free
    Victims of the Wildfire ransomware can get their encrypted files back without paying hackers for the privilege, after the No More Ransom initiative released a free decryption tool. No More Ransom runs a web portal that provides keys for unlocking files encrypted by various strains of ransomware, including Shade, Coinvault, Rannoh, Rakhn and, most recently, Wildfire. Aimed at helping ransomware victims retrieve their data, No More Ransom is a collaborative project between Europol, the Dutch National Police, Intel Security, and Kaspersky Lab. Wildfire victims are served with a ransom note demanding payment of 1.5 Bitcoins -- the cryptocurrency favored by cybercriminals -- in exchange for unlocking the encrypted files. However, cybersecurity researchers from McAfee Labs, part of Intel Security, point out that the hackers behind Wildfire are open to negotiation, often accepting 0.5 Bitcoins as a payment. Most victims of the ransomware are located in the Netherlands and Belgium, with the malicious software spread through phishing emails aimed at Dutch speakers. The email claims to be from a transport company and suggests that the target has missed a parcel delivery -- encouraging them to fill in a form to rearrange delivery for another date. It's this form which drops Wildfire ransomware onto the victim's system and locks it down.

today's howtos

Openwashing

Games for GNU/Linux

  • Achieve Global Domination in Agenda, Coming to PC, Mac, Linux on September 21
    Agenda, a strategy simulation from Exordium Games where players control an evil organization seeking world domination, will come to Windows, Mac, and Linux on Sept. 21st, 2016. Players will direct covert operations to increase their control over countries' economies, political parties, militaries, science institutions and media outlets. Operations will entail everything from low key kickbacks to military leaders to the brazen assassination of political rivals.
  • Vendetta Online 1.8.385 MMORPG Drastically Improves Chat and Effect Delays
    Guild Software announced the release of a new maintenance update for their popular and cross-platform Vendetta Online MMORPG (Massively Multiplayer Online Role-Playing Game) 3D space combat title. According to the release notes, Vendetta Online 1.8.385 is an important milestone, and it's here to drastically improve the chat and effect delays reported by users during larger capship battles by implementing a new dynamic server packet-queuing and priority change system, which was tested internally with 200 close-proximity capships per battle.
  • Looks like Subnautica from the Natural Selection 2 developers won't get Linux support
    This is quite sad, it seems we have been left wondering for a while (years) about Subnautica, but a developer has now confirmed a Linux version is not being worked on.