Lupper worm targets Linux systems

IGBT

Lifer
Jul 16, 2001
17,961
140
106
Text


NOVEMBER 08, 2005 (IDG NEWS SERVICE) - A worm that affects Linux systems and spreads by exploiting Web server-related vulnerabilities has been reported by antivirus companies, but so far Linux.Plupii, which is also known as Lupper, hasn?t spread much and isn?t seen as much of a threat.
The worm spreads by exploiting Web servers hosting vulnerable PHP/CGI programming language scripts, according to McAfee Inc. The worm is a derivative of the Linux/Slapper and BSD/Scalper worms from which it has taken its propagation strategy, McAfee said in information provided on its Web site.

The worm, discovered Sunday, attacks Web servers by sending malicious HTTP requests on Port 80, McAfee said. If the server being targeted is running a vulnerable script at certain URLs and is configured to permit external shell commands and remote file download in PHP/CGI, the worm could be downloaded and executed, McAfee said. It can also harvest e-mail addresses stored in Web server files.

The worm opens a back door on a compromised computer and then generates URLs to scan for other computers to infect and that can affect network performance, according to information from Symantec Corp.



 

nweaver

Diamond Member
Jan 21, 2001
6,813
1
0
if yoeur are running a php/cgi that permits external shell commands and remote file download, you deserve the rm-rf / shell command run on you box.
 

sigs3gv

Senior member
Oct 14, 2005
513
0
0
Originally posted by: n0cmonkey
Does it target Linux or systems running PHP?

It targets Linux systems running PHP. I believe the flaw is that an attacker can use `` to execute shell commands.
 

spyordie007

Diamond Member
May 28, 2001
6,229
0
0
Originally posted by: nweaver
if yoeur are running a php/cgi that permits external shell commands and remote file download, you deserve the rm-rf / shell command run on you box.
Agreed.
If the server being targeted is running a vulnerable script at certain URLs and is configured to permit external shell commands and remote file download in PHP/CGI
Any idea what the vulnerable script(s) are/what the entry point is? This site doesnt give that much technical info about the vulnerability.
 

hopejr

Senior member
Nov 8, 2004
841
0
0
Well, my server isn't infected *yet*, but then again, I didn't set the external shell commands and remote file download settings (unless they're default???).
 

nweaver

Diamond Member
Jan 21, 2001
6,813
1
0
no, they are not default on any system I've worked on....

This sounds to me, more like a bug with PHP/Apache. If you can upload and execute commands, then any system is vunarable. Write a batch file (shell script, perl script, etc) and then call it using the remote execution...
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |