OT: New Virus targets Linux OS

RaySun2Be

Lifer
Oct 10, 1999
16,565
6
71
*LINUX OS TARGETED BY NEW BREED OF TROJAN
By Shawna McAlearney, Security Wire Digest
A Trojan, Remote Shell Trojan b, is demonstrating a new twist by adding a viral component to malicious code targeting Linux systems.

"We see more of a trend targeting Linux systems--systems that are increasingly being used in corporate environments," says Gerhard Eschelbeck, vice president of engineering at Qualys. "RST.b is not currently in the wild, but it--and Trojans like it--have a much higher probability of success in compromising a system than a standard Trojan."

Since it uses any of nearly 65,000 UDP ports as a control vector, compared with only one or two ports used by most Trojans, chances of an infected system being utilized by an attacker are exponentially increased. It self-replicates and infects Linux Executable and Linking Format (ELF) binary executable programs. Once a system is infected--often through the execution of binary e-mail attachments or downloaded software--RST.b then initiates a virus-like self-replication process that infects additional executable binaries in the current working directory and in the /bin directory. No memory resident infection activities have been identified so far, according to Qualys.

"A virus-based Trojan placed on a public FTP server or Web server where many users download software could really take off," says Paul Robertson, director of risk assessment at TruSecure. (TruSecure publishes Security Wire Digest.) "When getting binary code from a public site, you need to verify its integrity before you install it. Linux admins aren't used to dealing with viral code so clean up is going to be a problem."

Systems infected with RST.b can be hijacked by the attacker, used as a secondary attack platform, searched for sensitive data or be destroyed.

"This Trojan turns any infected system into a network sniffer," says Eschelbeck. "And the tiniest hole in a firewall--for example, UDP port 53 for DNS--can be exploited."

Qualys offers free Remote Shell Trojan RST.b detection and cleaning tools
at:
Free tools
Alert:
Alert
 

Robor

Elite Member
Oct 9, 1999
16,979
0
76
But I thought only M$ operating systems were vulnerable to viruses, trojans, hacks, etc. I have a feeling if Linux was as popular as the various forms of Windows we'd see a lot more Linux viruses, trojans, and hacks. Windows is the most popular and that makes it the most popular to exploit. It's not perfect but apparently neither is Linux. :Q

The only question is, who to blame? When M$ screws up everyone says %#&@ Bill Gates. Who do you get pi$$ed at with Linux? The penguin?
 

Shuxclams

Diamond Member
Oct 10, 1999
9,286
15
81
I think a point that it missed is that there have been viruses for every OS ever written, it invariably falls on the end user to not be a putz and open attachments in emails, or download stuff that you have no clue about. I would think the average Linux user is far more advanced than the run of the mill M$ user and would probably skip on downloading or opening wierd attachments.











SHUX
 

RaySun2Be

Lifer
Oct 10, 1999
16,565
6
71
<I would think the average Linux user is far more advanced than the run of the mill M$ user and would probably skip on downloading or opening wierd attachments.>

That may have been true at one time, but as Linux becomes more mainstream and corporations start using it, you will get the same ID10T errors with Linux as you get with Micosoft. Probably more, because they will have come from a MS environment and will be unfamiliar with Linux. :Q

There's no avoiding the most common problem of ALL Operating Systems: A "short" between the chair and keyboard.

To think otherwise is just begging for trouble.

 

Evadman

Administrator Emeritus<br>Elite Member
Feb 18, 2001
30,990
5
81


<< A "short" between the chair and keyboard >>



Hey, I wear a grounding strap on my butt

I am sure the Linux compunty fill find a patch for this within the week. nothing like 10,000 people all working to fix the same problem
 

Robor

Elite Member
Oct 9, 1999
16,979
0
76
"There's no avoiding the most common problem of ALL Operating Systems: A "short" between the chair and keyboard." - RaySun2Be

You mean a PICNIC error?

Problem
In
Chair
Not
In
Computer

or a PBKAF error?

Problem
Between
Keyboard
And
Floor

I'm sure there's more ID10T errors out there! Let's hear them!
 

Rendus

Golden Member
Jul 27, 2000
1,312
1
71
Well, there's the original PEBKAC - Problem Exists Between Keyboard And Chair. I haven't bothered trying to come up with any myself

I really need to get out of doing tech support
 

Mookow

Lifer
Apr 24, 2001
10,162
0
0


<< The only question is, who to blame? When M$ screws up everyone says %#&@ Bill Gates. Who do you get pi$$ed at with Linux? The penguin? >>



I love the smell of burning pengiuns in the morning
 

kulki

Senior member
Jul 18, 2001
739
0
0
I thought Linux was virus free. Interesting post. one learns something new everyday
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |