BugTraq
Back to list
|
Post reply
update on the linux worm
Feb 19 2006 05:36AM
Gadi Evron (ge linuxbox org)
(1 replies)
A quick digest of some updates from the last few hours on this issue:
1. The worm is based on 'kaiten', which has been going around in
different variants for a long time now.
2. This worm is new.
3. The first part exploits PHP applications, like these variants
normally do.
4. The second part spreads to other systems.
5. The worm connects to a botnet C&C based on two Fast-flux DNS RR's
which are not there anymore, and as they change, are taken down.
As always, more updates if necessary on: http://blog.securiteam.com
Thanks,
Gadi.
--
http://blogs.securiteam.com/
"Out of the box is where I live".
-- Cara "Starbuck" Thrace, Battlestar Galactica.
[ reply ]
Re: update on the linux worm
Feb 20 2006 08:17PM
Stephen J. Smoogen (smooge gmail com)
Privacy Statement
Copyright 2010, SecurityFocus
1. The worm is based on 'kaiten', which has been going around in
different variants for a long time now.
2. This worm is new.
3. The first part exploits PHP applications, like these variants
normally do.
4. The second part spreads to other systems.
5. The worm connects to a botnet C&C based on two Fast-flux DNS RR's
which are not there anymore, and as they change, are taken down.
As always, more updates if necessary on: http://blog.securiteam.com
Thanks,
Gadi.
--
http://blogs.securiteam.com/
"Out of the box is where I live".
-- Cara "Starbuck" Thrace, Battlestar Galactica.
[ reply ]