Slashdot Mirror


New Linux Worm Found in the Wild

randomErr writes "The worms, Slapper.B and Slapper.C, which exploits a known buffer overrun vulnerability in the Secure Sockets Layer 2.0 (SSLv2) handshake process has infected thousands of Web servers worldwide, according to Helsinki-based F-Secure Corp., a computer and network security company. "

4 of 366 comments (clear)

  1. what does it look like? by Anonymous Coward · · Score: 5, Interesting

    What should I look for in my apache logs to see if Im being "hit" by it? Anyone have an example?

    your friendly neighborhood AC

  2. "Wget"ing its source by N+Monkey · · Score: 5, Interesting
    From the article:
    According to researchers at F-Secure, the Slapper.B worm variant is able to retrieve its source code from a Web page after the worm has been removed from infected servers. The worm uses a common free software utility, wget, to retrieve its source code from an infected Web page in the home.ro domain.

    Administrators of the domain, which is located in Romania, have been notified and the infected page has been deleted from the site, according to F-Secure.

    Rather than simply having deleted the page, I wonder if it would have possible to replace this source code with something else that acted as an "antibody"?

  3. A false sense of security by abhikhurana · · Score: 4, Interesting

    I think that linux provides the sys admins with a false sense of security. Most sysadmins think that because running Linux, they can't be infected with any viruses and worms. The result of this is that many of hese adminstarators never bother to check about new threats, because they haven't seen anything like this for a while. Normally linux adminstrators are more tech savy than Windows adminstrators but as linx GUI improves, one will see a prliferation of not so tech savy adminstrators in the Linux market as well.So be prepared for increasing amounts of damage which such worms can cause.
    On the other hand, the adminstrators of Windows machines, because they are facing a new worm every second day, try to stay uptodate with the latest news and patches. Most of them have aautomatic update wizards running on their machines which download new patches instantly.
    Infact I would prefer such an instant update wizard for Linux as well, especially for the Linux running security critical applications, so that even if the system adminstrator is too lazy to check a news site, he will still come to know abot the threat.
    And because it will be running on linux, it will do what its supposed to do, not "God knows What and Gates knows what" as is the case with windows update wizard.

  4. Comment removed by account_deleted · · Score: 4, Interesting

    Comment removed based on user account deletion