'Lupper' Attacks Linux Systems

    Date08 Nov 2005
    8568
    Posted ByBenjamin D. Thomas
    Security specialist McAfee has discovered a new virus, an internet worm that is attacking Linux systems. The worm spreads by exploiting web servers hosting vulnerable PHP/ CGI scripts and has been named 'Lupper' by Mcafee. McAfee, which has rated Lupper as low risk, says that the worm is a modified derivative of the Linux/ Slapper and BSD/ Scalper worms from which it inherits its propagation strategy. It scans an entire class B subnet created by randomly choosing the first byte from a hard-coded list of A classes and randomly generating the second byte.

    The worm blindly attacks web servers by sending malicious http requests on port 80. If the target server is running one of the vulnerable scripts at specific URLs and is configured to permit external shell commands and remote file download in the PHP/ CGI environment, a copy of the worm could be downloaded and executed.

    You are not authorised to post comments.

    LinuxSecurity Poll

    What is your favorite LinuxSecurity.com page/section?

    No answer selected. Please try again.
    Please select either existing option or enter your own, however not both.
    Please select minimum 0 answer(s) and maximum 4 answer(s).
    /component/communitypolls/?task=poll.vote&format=json
    20
    radio
    [{"id":"73","title":"News","votes":"0","type":"x","order":"1","pct":0,"resources":[]},{"id":"74","title":"Advisories ","votes":"4","type":"x","order":"2","pct":80,"resources":[]},{"id":"75","title":"HOWTOs","votes":"0","type":"x","order":"3","pct":0,"resources":[]},{"id":"76","title":"Latest Features ","votes":"1","type":"x","order":"4","pct":20,"resources":[]}]["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"]["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"]350
    bottom200

    We use cookies to provide and improve our services. By using our site, you consent to our Cookie Policy.