Whole Network Most Recent TOP10 CIO Outsourcing SaaS Security

 

Under the radar Apache worm?

Filed in archive Security by Scott Wilson on January 25, 2008

I haven't seen a lot of detail about this yet, but fellow CW blogger Sue Walsh reports some additional information about the supposed Linux/Apache based exploit that may be infecting a surprising number of servers currently. Unlike other modern worm attacks, this one (if it in fact exists; so far it's only been determined by inference rather than observation) seems to be relatively well-written, managing to install and co-opt servers without causing extensive malfunctions.

Although the exact exploit infecting the servers does not yet seem to have been adequately described, the mechanism of the resulting infection appears to be clear enough: the infected web server acts on visiting web browsers using the Rbot and Sdbot trojan attacks and attempts to take over the client computer and bring it into a larger botnet... to what nefarious purpose yet unknown.

The larger concern currently is over the exploit involved in compromising the webservers. Large-scale botnets are a sad but simple fact of life these days, whether they are built using spam or web-based attacks. Wide-spread web server compromises, however, particularly against the popular LAMP platform, are quite another level of concern. It remains to be seen whether these were limited, uniquely crafted compromises or whether there is some underlying hole which has yet to be exposed and patched in the architecture.

EDIT: Clarified the unconfirmed status of the worm in the opening paragraph.


Advertisement


Permalink: Under the radar Apache worm?
Tags: Apache  Linux  security  exploit  botnet  2007  under+radar  apache+worm 

Trackback: http://www.creative-weblogging.com/cgi-bin/mt-tb.pl/111745



Advertisement


Advertisement


CW ToolbarInstall
RSSrss   | See all blog subscribe options
Googlegoogle   |   What is RSS?
Yahoo!yahoo
AddthisAddThis Feed Button
BloglinesBloglines
Newsletter
Advertisement - Book yours here.

Use our search feature to look for other interesting posts

Just this blog Whole network
 
  • Online MBA Degrees
  • Would you like to have a new interactive marketing channel for your company? Learn more about Sponsored Blogs with Creative Weblogging. See how we helped companies like Weblin and cellity reach their goals.
  • Would you like to reach millions of blog readers every day? See you banner on hundreds of blogs with TierOneAds? Stay in control measuring conversion in real time. Register now.
  • Would you like to make more money blogging? Use TierOneAds a new platform that allows you as a blogger to set your prices per impression. Register now.
  • Do you have a blog with more than 50k page views from the US? Let us market your blog and earn great fix payments and bonuses.
  • Would you like to see your text link here? Let us know!
Advertisement
Book yours here.



  • Testimonials

  • 'I don't really think you should keep testimonials from the last guy here, do you?'
  • Other blogs in the same channel in the Creative Weblogging Network

Advertisement -
Book yours here..






Advertisement - Book yours here..
 
Tagcloud: CIO Data Storage Enterprise Hardware Enterprise Software Events General Help Desk And Support Integration Software Management Market Perturbations Networking Offshoring Outsourcing SaaS Security SOA Sponsored Posts The Cloud The Vision Thing Virtualization