Quantcast

Lupper Worm Targets Linux

So far it's benign, but security vendors urge inoculation.

Nancy Weil, IDG News Service

  • 0 Yes
  • 0 No

A worm that affects Linux systems and spreads by exploiting Web server-related vulnerabilities has been reported by antivirus companies, but so far Linux.Plupii, which is also known as Lupper, hasn't spread much and isn't seen as much of a threat.

Linux users should update antivirus software and patches to protect against the worm, say representatives of the major antivirus product vendors said. Both McAfee and Symantec have updated their software to identify and stop the worm.

Information about the worm can be found at McAfee's Web site and also from Symantec.

How Worm Works

The worm spreads by exploiting Web servers hosting vulnerable PHP/CGI programming language scripts, according to McAfee. The worm is a derivative of the Linux/Slapper and BSD/Scalper worms from which it has taken its propagation strategy, McAfee said in information provided on its Web site about the worm, which was discovered Sunday.

The worm attacks Web servers by sending malicious Hypertext Transfer Protocol (HTTP) requests on port 80, McAfee said. If the server being targeted is running a vulnerable script at certain URLs and is configured to permit external shell commands and remote file download in PHP/CGI the worm could be downloaded and executed, McAfee said. It can also harvest e-mail addresses stored in Web server files.

The worm opens a back door on a compromised computer and then generates URLs to scan for other computers to infect and that can affect network performance, according to Symantec.

Symantec rates the worm as having a medium damage and distribution threat. As of Tuesday morning, it hadn't spread much and Symantec said it is easy both to contain and remove. McAfee assessed it as a low threat for both corporate and home users.

  • Recommend this story?
  • 0 Yes
    0 No

"Lupper Worm Targets Linux" Comments

Print 65% more pages than with refilled inks. Trust Original HP Inks. Hit Print Reliably.

Featured APC Accessories For Your System
10% Off Entire Cart at Online Store

  • APC Back-UPS ES Safeguards your equipment from damaging surges and spikes that travel along your utility & data lines.
  • APC SurgeArrest Performance Highest level of protection for your professional computers, electronics and connected devices, as well as provides surge protection.

People who read this also read:

  • 2007 Microsoft Office Suites Comparison This paper compares and contrasts four suites of the 2007 Microsoft Office system: Microsoft Office Standard 2007, Microsoft Office Professional Plus 2007, Microsoft Office Enterprise 2007 and Microsoft Office Ultimate 2007. This paper is intended to help organizations understand the applications and capabilities offered, and to identify the suite that best fits their needs.
  • Windows Vista Migration: The Business Proposition It's not so much a matter of "if" but "when" for most organizations regarding migration to Windows Vista. Laying the groundwork now for this migration can yield higher ROI than waiting until later. This Computerworld Technology Briefing explains it all.

PC World's Marketplace