PDA

View Full Version : New Worm Targets Linux Systems


Jeff Mincey
11-08-2005, 04:32 PM
Excerpt from a CNET article:

A new worm that propagates by exploiting security vulnerabilities in Web server software is attacking Linux systems, antivirus companies warned on Monday.

The worm spreads by exploiting Web servers that host susceptible scripts at specific locations, according to antivirus software maker McAfee, which has named the worm "Lupper."

Lupper blindly attacks Web servers, installing and executing a copy of the worm when a vulnerable server is found, McAfee said in its description of the worm.

A backdoor is installed on infected servers, giving the attacker remote control over the system. The server joins a network of compromised systems, which can be used, for example, in attacks against other computers, according to McAfee.

For more information, you can access the full article here:

New worm targets Linux systems (http://news.zdnet.com/2100-1009_22-5938475.html?tag=nl.e589)

Meanwhile, what can Rimuhosting and its VPS and dedicated server customers do to protect themselves against this?

retep
11-08-2005, 07:50 PM
This worm appears to target vulnerable web scripts. For example, some script will end up wget'ing a script and running it on your server.

We see the occasional VPS compromised via these vulnerable scripts. With the worm in place it will increase the liklihood of your vulnerable scripts being exploited.

See the security alert for the noted vulnerabilities. In our experience phpBB, awstats and zope's xmlrpc.php are commonly exploited. Make sure you are running the latest versoins of these products. If you need asssistance upgrading your scripts, just pop in a support ticket with us.

ayam
12-22-2005, 05:57 AM
use mod_security (http://modsecurity.org) apache modules to filter unknown worm