You are here: silicon.com > Software > Malware

Malware

Web server worm threatens Linux systems

Attackers get backdoor access...

Tags: worm, viruses worms, linux

By Joris Evers

Published: 8 November 2005 08:20 GMT

A new worm that propagates by exploiting security vulnerabilities in web server software is attacking Linux systems, antivirus companies warned on Monday.

The worm spreads by exploiting web servers that host susceptible scripts at specific locations, according to antivirus software maker McAfee, which has named the worm "Lupper".

Lupper blindly attacks web servers, installing and executing a copy of the worm when a vulnerable server is found, McAfee said in its description of the worm.

A backdoor is installed on infected servers, giving the attacker remote control over the system. The server joins a network of compromised systems, which can be used, for example, in attacks against other computers, according to McAfee.

The worm exploits three vulnerabilities to propagate the XML-RPC for PHP Remote Code Injection vulnerability; AWStats Rawlog Plugin Logfile Parameter Input Validation vulnerability; and Darryl Burgdorf's Webhints Remote Command Execution Vulnerability, according to Symantec's online description of the worm.

The XML-RPC flaw affects blogging, wiki and content management software and was discovered earlier this year. Patches are available for most systems. AWStats is a log analyser tool; a fix for the flaw has been available since February. Darryl Burgdorf's Webhints is a hint generation script; no fixes are available for the script, according to Symantec's DeepSight Alert Services.

McAfee rates Lupper as low risk. Symantec, which calls the worm "Plupii", rates it medium risk but notes that the worm has not been widely distributed. The Sans Internet Storm Center, which tracks network threats, reports some worm sightings.

McAfee and Symantec have updated their products to protect against the worm. If a system has been infected, Symantec recommends complete reinstallation of the system because it will be difficult to determine what else the computer has been exposed to, the company said.

Joris Evers writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
Security Consultant Ethical Hacking / Penetration Testing - London

Responsibilities: - Deliver security assessment services including network scanning, vulnerability testing, penetration testing, search engine ...

Unix Engineer

ESSENTIALS SKILLS/QUALIFICATIONS: HP-UX System Administration, Support and Software Integration Experience in script writing Experience of UNIX ...

PHP / MY SQL / Java Script 3-6 months Devon

PHP / MY SQL / Java Script 3-6 months Devon I am in touch regarding a 3- month PHP, MYSQL contract for an exclusive client in Devon looking to ...

CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.





Quick Sitemap Links: