BugTraq
new linux malware Feb 18 2006 10:40PM
Gadi Evron (ge linuxbox org) (2 replies)
Re: new linux malware Feb 20 2006 04:57PM
Christine Kronberg (Christine_Kronberg genua de) (1 replies)
PHP as a secure language? PHP worms? [was: Re: new linux malware] Feb 20 2006 08:22PM
Gadi Evron (ge linuxbox org) (2 replies)
Christine Kronberg wrote:
> On Sun, 19 Feb 2006, Gadi Evron wrote:
>
>> Today, we received a notification about a new Linux malware ItW (In
>> the Wild).
>
>
> They are not exactly new. I've seen them floating around for about
> two months now. There a different binaries running around doing the
> same work (different the way that they have been compiled on different
> linux distributions). Part of that work is to be distributed by trying
> to get in via vulnerable php scripts. Look to me like being part of a
> worm.
>
> Cheers,
>
>
> Christine Kronberg.
>

Indeed, the most annoying thing about the PHP worms today is that these
PHP vulnerabilities being exploited are everywhere.

As I already mentioned, this recent Linux worm has more to it, but
that's in another post.

These vulnerabilities being exploited are very difficult to protect from
because:
1. PHP is the "serious" or at least open-source/Linux/security freak's
choice for web development. Mine as well (although as many still say,
Perl does a better job).

2. Developing secure applications in PHP is difficult, as one of PHP's
creators said recently - even to him after years of trying.

3. Staying on top of new PHP vulnerabilities has become impossible,
popping around everywhere.

4. Determining how secure a PHP application is, looking at the code and
for how silly past vulnerabilities were (i.e. looking at the coder
rather than the code) is now more important than the actual application.

Much like their self criticism said, PHP needs to grow to a far more
secure language, much like we need to chose more carefully what PHP
software we use.

Some of us have been joking for a while about creating a script to
choose from different paragraph we create, and email bugtraq
re-assembling the randomly with a new PHP bug and a random PHP
application name every few hours. Would any of us be able to readily
tell the difference?

From all the fish we can barely see the water. :(

As to the worms, been going on longer than 2 mounths like you mentioned,
but you are correct.

One note I'd like to make, is that even if the second (interesting)
payload in the Linux worm wasn't there, just because someone utilizes
old malware in the creation of new malware doesn't mean it is new, or
99.9% of any "virus" every written would be old.

Does Bagle.**** ring a bell with anyone? :)

Like I already mentioned, if any of you are interested in sharing web
server logs and be notified of new PHP problems we all notice online,
drop me a note.

Gadi.

--
http://blogs.securiteam.com/

"Out of the box is where I live".
-- Cara "Starbuck" Thrace, Battlestar Galactica.

[ reply ]
Re: PHP as a secure language? PHP worms? [was: Re: new linux malware] Dec 30 2006 10:00PM
Kevin Waterson (kevin oceania net) (1 replies)
Re: PHP as a secure language? PHP worms? [was: Re: new linux malware] Jan 01 2007 05:53PM
Bill Nash (billn billn net) (1 replies)
Re: PHP as a secure language? PHP worms? [was: Re: new linux malware] Jan 01 2007 09:00PM
Tino Wildenhain (tino wildenhain de) (1 replies)
RE: PHP as a secure language? PHP worms? [was: Re: new linux malware] Jan 01 2007 09:31PM
Jim Harrison (Jim isatools org) (1 replies)
Re: PHP as a secure language? PHP worms? [was: Re: new linux malware] Jan 01 2007 10:37PM
Dana Hudes (dhudes hudes org) (1 replies)
RE: PHP as a secure language? PHP worms? [was: Re: new linux malware] Jan 02 2007 12:02AM
Jim Harrison (Jim isatools org) (2 replies)
Re: PHP as a secure language? PHP worms? Jan 02 2007 12:01PM
Duncan Simpson (dps simpson demon co uk) (1 replies)
RE: PHP as a secure language? PHP worms? Jan 02 2007 02:17PM
Jim Harrison (Jim isatools org)
Re: PHP as a secure language? PHP worms? [was: Re: new linux malware] Jan 02 2007 10:58AM
Darren Reed (avalon caligula anu edu au) (2 replies)
Re: PHP as a secure language? PHP worms? [was: Re: new linux malware] Jan 02 2007 03:16PM
Dana Hudes (dhudes hudes org) (1 replies)
Re: PHP as a secure language? PHP worms? [was: Re: new linux malware] Jan 02 2007 06:48PM
Lawrence Paul MacIntyre (macintyrelp ornl gov)
RE: PHP as a secure language? PHP worms? [was: Re: new linux malware] Jan 02 2007 02:15PM
Jim Harrison (Jim isatools org) (1 replies)
Re: PHP as a secure language? PHP worms? [was: Re: new linux malware] Jan 02 2007 06:37PM
Darren Reed (avalon caligula anu edu au) (3 replies)
Re: PHP as a secure language? PHP worms? [was: Re: new linux malware] Jan 03 2007 05:16AM
Ronald Chmara (ron Opus1 COM) (1 replies)
Re: PHP as a secure language? PHP worms? [was: Re: new linux malware] Jan 04 2007 08:59PM
Jim Manico (jim manico net)
Re: PHP as a secure language? PHP worms? [was: Re: new linux malware] Jan 02 2007 09:07PM
Bill Nash (billn billn net)
RE: PHP as a secure language? PHP worms? [was: Re: new linux malware] Jan 02 2007 07:18PM
Jim Harrison (Jim isatools org)
Re: PHP as a secure language? PHP worms? [was: Re: new linux malware] Feb 22 2006 10:48AM
Kevin Waterson (kevin oceania net) (2 replies)
Re: PHP as a secure language? PHP worms? [was: Re: new linux malware] Feb 24 2006 09:13PM
Matthew Schiros (schiros gmail com) (1 replies)
Re: PHP as a secure language? PHP worms? [was: Re: new linux malware] Feb 27 2006 03:26PM
L. Adrian Griffis (agriffis dstsystems com) (1 replies)
Re: PHP as a secure language? PHP worms? [was: Re: new linux malware] Feb 27 2006 03:50PM
Matthew Schiros (schiros gmail com) (1 replies)
Re: PHP as a secure language? PHP worms? [was: Re: new linux malware] Feb 27 2006 04:21PM
L. Adrian Griffis (agriffis dstsystems com) (1 replies)
Re: PHP as a secure language? PHP worms? [was: Re: new linux malware] Feb 27 2006 05:55PM
Matthew Schiros (schiros gmail com)
Re: PHP as a secure language? PHP worms? [was: Re: new linux malware] Feb 24 2006 09:07PM
Jamie Riden (jamie riden gmail com)
Re: new linux malware Feb 20 2006 04:24PM
Marco Monicelli (marco monicelli marcegaglia com) (1 replies)
Re: new linux malware Feb 20 2006 07:58PM
Gadi Evron (ge linuxbox org) (1 replies)
Re: new linux malware Feb 22 2006 08:00PM
Jamie Riden (jamie riden gmail com)


 

Privacy Statement
Copyright 2010, SecurityFocus