Unnoticed For Years, Malware Turned Linux Servers Into Spamming Machines
An anonymous reader writes: For over 5 years, and perhaps even longer, servers around the world running Linux and FreeBSD operating systems have been targeted by an individual or group that compromised them via a backdoor Trojan, then made them send out spam, ESET researchers have found. What's more, it seems that the spammers are connected with a software company called Yellsoft, which sells DirectMailer, a "system for automated e-mail distribution" that allows users to send out anonymous email in bulk.
Here's the white paper in which the researchers explain the exploit.
Seriously?
Linux Wud Not Du That!
Would you like some cheese with your whine?
So Windoze, Linux, BSD have all been compromised ... how about Hurd / Plan-9? Have they been compromized?
Muchas Gracias, Señor Edward Snowden !
[The sound of silence]
Look guys just say sorry and we'll say no more about it.
This isn't as interesting as it sounds (or have i misunderstood?) Basically, if you are a spammer, and download binaries of 'cracked' spamming software... surprise surprise, there is a back door in it that lets other spammers use your servers to spam. It is kinda interesting from a technical point of view (putting perl scripts into elf binaries) but the headline is very misleading, this is not a serious linux/bsd security issue.
"Perl code packed inside ELF binary .. The Perl spammer .. The spamming daemon is also written in Perl and packed inside an ELF binary"
OK. how exactly is this Mumblehard malware loaded and executed on the server,without user action and without the user running as root?
Via greed driving user interaction in the hope of a "free lunch". From the article:
So it's a parasite feeding on cheapskate spammers. I'm not sure whether to get annoyed with them or give them a medal.
These PEBKAC exploits happen more often than you might think on Linux
And removing the "text extending babbel":
1.) Don't get a pirated copy of "DirectMailer" - because it's infected and will trojanise your server.
2.) keep your server and especially it's services updated - check your Joomla and Wordpress installation - and additionally to that the themes you installed.
- the white paper says that the researchers think that these were the most likely vectors
- the article puts faith on the thoughts of the researchers
Translation:
The infected server were so extremely outdated that the researchers didn't know where to start to search. Some believe to have seen active kernel versions dating back to 2000 and even further and surrendered the computers to archeologists to study ancient server setups.
3.) an antivirus on freebsd or linux system is pratically useless in detecting recent malware - they need at least 5 yrs. of cultivation
On windows the infection base is much greater. However the idea of "quarantining" software of problematic origin for a certain period of time and early virustotalling it, should be considered.
lesson: no cracked software on linux/freebsd system
Broken content management systems like Joomla and Wordpress seem to play a big part in all sorts of problems these days. Why are these packages not robust, despite them being open source? Isn't the general claim around here that in open source, vulnerabilities are quickly found and fixed?
WTF?
Decent people don't want to be associated with people like MikeeUSA, the fact that the anti-systemd people seem happy to associate with him isn't going to help their cause.
What about this one: "decent people don't want to be associated with people like Hitler, the fact that the vegetarian people seem happy to associate with him isn't going to help their cause."
See what I did there? (no, that doesn't qualify as Godwin, not yet)
I'm one of these anti-systemd people, and I don't want to be associated in anyway with a troll like MikeeUSA. He's behavior has nothing to do with accepting or not systemd and trying to make some kind of true-scotman-non-sequitur-bullshit out of it is utter non-sense.
Great. Now we get to read another informed, thoughtful Slashdot discussion about how OSS sucks and how Linux/*BSD are just as crappy as Windows.
For the people who *did* read the whitepaper (yeah, I know): the paper says the Perl code has constants for Windows as well, so how likely is it that the same code, wrapped in an exe instead of an elf binary, has also infected IIS servers?
Better start checking for connections to 194.54.81.163...
It's not like the script can run without the interpreter. Even if you were stupid enough to mount /tmp other than noexec (the default).
I thought direct mailer was a bulk spamming engine? It seems to be a dog eat dog situation.
i.e. if you install a pirated version of a spamming engine [FOR YOUR OWN USE] it will also spam for other spammers too.
Since when was Russell Coker an official spokesman for Debian?
Watch this Heartland Institute video
I've got three servers that I maintain; four if you count my workstation. They all run Ubuntu Linux 14.04.
What is top in my mind is DETECTION. How to tell if Mublehard has infected us. If it has I must can go in person and re-install all the systems from scratch. But I'm not going to spend several nights on the bus until I get a YES or NO. Perhaps Yellsoft sells a Mumblehard detector, ha ha?
Yes, you're right, anti-systemd people are not all insane, but some of the most vocal of them are.
(And it's not just good old "I want to marry 12 year old girls" MikeeUSA, there are also the "systemd will eat your ouput" loons, the "systemd is an NSA plot" obsessives, the "systemd is an end run around the GPL" tin-foil hatters...)
Watch this Heartland Institute video
Decent people don't want to be associated with people like MikeeUSA, the fact that the anti-systemd people seem happy to associate with him isn't going to help their cause.
What about this one: "decent people don't want to be associated with people like Hitler, the fact that the vegetarian people seem happy to associate with him isn't going to help their cause."
See what I did there? (no, that doesn't qualify as Godwin, not yet)
I'm one of these anti-systemd people, and I don't want to be associated in anyway with a troll like MikeeUSA. He's behavior has nothing to do with accepting or not systemd and trying to make some kind of true-scotman-non-sequitur-bullshit out of it is utter non-sense.
Wikipedia about Godwin:
Godwin's Law is an Internet adage asserting that "As an online discussion grows longer, the probability of a comparison involving Nazis or Hitler approaches 1" — that is, if an online discussion (regardless of topic or scope) goes on long enough, sooner or later someone will compare someone or something to Hitler or Nazism.
This is a perfect example - even if it is not a troll, even if it's meant to tell us that this is not a Godwin, even if meant as a serious answer.
This "article" is beyond retarded.
this malware is pretty unix-y about the way it does things. its small, does few things and does them efficiently.
The author should be complemented on his adherence to the unix philosophy. Even his social engineering campaign is that way.
Functionality wise, an equal malware executable on windows would be megabytes in size and be installed as a service :D
Cheese is a GNOME application and runs natively , no need for a Windows compatibility layer.
oh dear.... what an unoriginal troll.. leave the internet and come back when your age exceeds your shoe size and maybe you'll become more informed
"The hands that help are better far than lips that pray." - Robert Ingersoll (1833-1899)
Are we talking about the same ESET I send them a trojan that infected two computers at the company I work for sample, to add them to their database so their antivirus to finally detect it and they refused? Probably they had the sample in this case for 5 years and they finally analyzed it now.
"\u201cconservative\u201d"
"doesn\u2019t"
"I\u2019m"
Looks like systemd already wrecked your shit. Your punctuation doesn't even fucking work!
Still waiting on Serviscope_minor to wake up to fucking reality and realize that Jessica Price isn't going to fuck him.
Don't you love it when an exploit explanation is given in PDF form... it's a trap!!!
"If any question why we died, Tell them because our fathers lied."
Meanwhile, developers of systemd are all insane.
I guess if you download from public sources with no common sense
Yes, you're right, anti-systemd people are not all insane, but some of the most vocal of them are.
Congratulations on your insightful mod, there, for your fallacious characterization. As if we needed more proof that this place has gone to shit.
"You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
/. announced OpenBSD 5.7 the other day and the usual crowd came out to say, "so what", and "nobody uses it", etc. Well, this is why it has fans. Yes, yes, there were Linux and FreeBSD machines run well enough to be proof against this exploit...it's that OpenBSD machines tend to be safe out of the box and you have to make a real effort to de-secure them.
FYI, you whining about a whiner makes you a bigger whiner.
Unnoticed For Years
I've been dealing with Linux servers spewing more spam than a group of Monty Python vikings for over a decade.
It's been why I've always snorted at the "Hurr, winders virus!" idiots here on Slashdot. Linux has never been, is not, and never will be a magic security panacea when run by idiots.
Just like every other operating system.
Shit, you give an idiot OpenBSD, and it'll spew spam eventually.
Cheese is one of my favorite brands of Marijuana, on sale today at the recreational weed store for $150 an ounce or $8 a gram......
https://www.leafly.com/hybrid/cheese (age check popup)
Donald Trump, on a crusade to make Nixon look respectable
It was indeed meant as a serious answer outlining the absurdity of associating MikeeUSA (and similar lunatics) to all anti-systemd people.
This said, no it is not a Godwin. There is no comparison. I didn't *compare* vegetarians to nazis or Hitler in any way whatsoever.
If I was pedantic (ok, ok, lemme rephrase that: "Since I am pedantic") I'd even say I didn't associate them with him. I merely quoted an absurd sentence with a slight change of content (2 words) while keeping the quotes around to underline that this was not a statement by myself or representing my views (eating vegetarian meals most of the week I wouldn't dare).
Indeed, they're not helping us. Sidenote: I've been following this from afar these days and I didn't even know there were some NSA conspiracy theory going on.
Well, anyways, maybe the ongoing kdbus debacle will finally help people open their eyes on the "quality" of the code and ideas to be expected from systemd people (alright, I confess being just a vile troll there).
Don't be a dick. Pay for the software you use.
This works if the software is still in print. True, on a server, you're going to want to use software that's still maintained. But there are plenty of video games that have gone out of print.
Trojans are exploits of a human vulnerability. How would you go about patching a system against operator stupidity?
PHP, and that means your security is dead right there
In theory, it should be possible to adopt good coding practices that leave out all the bad parts of PHP, in much the same way that Douglas Crockford recommends for JavaScript in his book JavaScript: The Good Parts. If you think the PHP interpreter inherently has poor security despite good coding practices, have you tried notifying the operators of Wikipedia?
Fellow pedantic here. The Godwin definition is of a comparison "involving" Nazis, not "with" or "to" Nazis (the words "compare ... to" are part of a rather poor and unnecessary Wikipedia paraphrase).
No, your children are not the special ones. Nor are your pets.
Agreed, and, again, there is no *comparison* in the aforementioned sentence.
(Love your nickname)
Would you like some hipster with your faggot?
What's falacious? You haven't seen the trolls I've described? You deny that their ideas are insane?
Watch this Heartland Institute video
Men who don't want young girls are the ones who are insane, or gay.
Nice moving the goalposts shill.
He's a debian developer, a respected one, his tone is the one ascendant in debian.
They put a trojan horse into pirated copies of code for a bulk mailer -- then used those servers to send spam. Who's gonna notice? Who's gonna be surprised that their machine gets 'accidentally' flagged as a spam box? Who do you complain to when you figure out that your 'cracked' spam software turned out to contain a trojan?
Sometimes boldness is in fashion. Sometimes only the brave will be bold.
I'm 14 you jerk, and my shoe is 11. So actually my shoe size is smaller than my age. systemd is terrible and anyone with any sense can see that we should be sticking with tried and tested sysvinit.
but rather a reduction in price on PHP hosting due to high demand
I thought "high demand" (movement of the demand curve to the right) caused an increase in price level, not a decrease. Are you claiming that the demand curve moved so much that hosting providers were able to build in enough economies of scale that they could move the supply curve so far to the right that it more than compensates for the increased demand? Or is there some particular shitty aspect inherent to PHP that happens to push its supply curve to the right?
No you compared this MikeeUSA person to Hitler.
MikeeUSA = Hitler
anti-systems people = vegetarians
It certainly was an instance of Godwin's law in the truest sense but just saying "that's Godwin's Law" doesn't invalidate your point.
All I want is a secure system where it's easy to do anything I want. Is that too much to ask ~~ Randall Munroe
s/systems/systemd/
All I want is a secure system where it's easy to do anything I want. Is that too much to ask ~~ Randall Munroe