New Mare Kicks At Linux

Tuesday, February 21 2006 @ 02:10 PM EST

Contributed by: sde

Much attention is going to other viral issues on other operating systems right now. That doesn't mean operating systems like Linux don't feel the love because it does. The delightfully well-received Mare family of worms has yet another offspring and this one exploits a vulnerability in Mambo.

Mare.D is a network worm that propagates by exploiting vulnerabilities in the Mambo content management system and the PHP XML-RPC library. The worm installs several backdoors to the compromised system.

The kick in this Mare comes in the form of several backdoors into the infected system. Two of them are connectback shell backdoors that hook up to a remote host on 8080/TCP and open an interactive shell on the infected host. The third is an IRC-controlled backdoor, written in Perl, and waits for marching orders. Apparently, the primary part of the worm can listen in through a 27015/UDP port. Then the attack can do all kinds of naughty things.

Full article

0 comments



http://www.linuxlinks.com/portal/news/article.php?story=20060221141047107