ZDNet:  Reviews | Downloads | Tech Update | Prices
Page OneApplicationsNetworkingeBusinessHardwareCommentary



Networking


Linux worm creating P2P attack network
By Robert Lemos
Special to ZDNet News
September 16, 2002, 5:06 AM PT


TalkBack!


A new worm that attacks Linux Web servers has compromised more than 3,500 machines, creating a rogue peer-to-peer network that has been used to attack other computers with a flood of data, security experts said Saturday.

The worm seems to spreading fairly rapidly, according to security company Symantec, which early Friday detected about 2,000 infected computers that were actively attacking--a number that climbed to 3,500 late Friday. The company's security personnel could not be contacted for comment Saturday.

"It is confirmed through various sources that this worm is in the wild and actively attacking other servers," the company warned its newest advisory Saturday.
Click Here!

The worm targets Apache Web server installations on a variety of Linux systems, including those from Red Hat, SuSE, Debian, Mandrake and Slackware. By exploiting a security hole in the Apache OpenSSL module that enables a widely used encrypted communications service known as the secure socket layer, the worm can copy itself to new servers.

The advisory includes an analysis of the so-called Linux.Slapper.Worm's code, revealing some details of the attack network created from servers compromised by the worm.

"(Slapper) also includes a number of peer-to-peer capabilities, which allow it to communicate with other clients, and participate in a distributed denial-of-service (DDoS) network," stated the advisory.

It's uncertain how much danger the worm poses. While an advisory posted Friday by Symantec rates the new threat a 2 out of 5, with 5 being the most severe threat, the latest advisory rates the potential danger as "high." Antivirus company Kaspersky released an advisory on the worm early Saturday, which stressed that the the company hadn't seen any reports of infected machines from its customers.

Though the rogue peer-to-peer network of compromised servers is still being created, it has already been used to attack the DNS servers of a major Internet service provider, according to a statement posted on the Internet Storm Center, a Web site that tracks security incidents on the Net by correlating data among voluntarily submitted firewall logs.

Domain-name service, or DNS, servers acts as the yellow pages of the Internet by matching domain names, such as news.com, to the numerical addresses used by the Net's hardware. By leveling a denial-of-service attack at such servers, an attacker can block customers of the assaulted ISP from connecting to Web sites.

Further evidence of the DDoS network being used came in an e-mail sent out by RackShack.net to its customers. The Web hosting provider apparently warned administrators that several of its servers had been used to conduct attacks against other providers.

"This morning we found 20-plus machines that were used to launch a DoS attack," Patrick Smith, a systems administrator for the company, stated in the e-mail seen by News.com. "We are currently reviewing the compromised hosts and it appears this worm is the culprit."


E-mail this story! Printer Friendly

Also on ZDNet
Find the tech gear you need in CNET's Back to School guide.
Get ahead of the competition with the BizTech Library.
Improve your PC's performance with the Memory Configurator.
Don't miss up-to-the-minute IT commentary on TechRepublic's blog.
Laid off? Find a new IT job today in our Career Center.


 TalkBack: Post your comment here
       Re: Linux worm creating P2P attack network  Hellfire™

       THERE GOES LINUX'S STRONGEST BARGAINING CHIP  Kofi Amparbeng

       So, the Word hole is a Windows bug?  Robert Crocker

       Re: So, the Word hole is a Windows bug?  William Beach

       Re: THERE GOES LINUX'S STRONGEST BARGAINING CHIP  Brian Barrier

       Re: THERE GOES LINUX'S STRONGEST BARGAINING CHIP  Hellfire™

       Oop, I made a mistake in my post.  Hellfire™

       Re: Linux worm creating P2P attack network  Homer Simpson

       Re: Linux worm creating P2P attack network  steve mcgrew

       Re: Linux worm creating P2P attack network  Hellfire™

       Does ZDNet do this on purpose...  Patrick Jones

       Re: Does ZDNet do this on purpose...  Homer Simpson

       This Worm Was Created At Microsoft !!  Zarlat Zeigfield

       Re: How fast....??  Joe Cuervo

       Re: How fast....??  toad life

       Re: This Worm Was Created At Microsoft !!  Yagotta B. Kidding

       Re: Linux worm creating P2P attack network  Loverock Davidson

       Re: Linux worm creating P2P attack network  yeah right

       Re: Linux worm creating P2P attack network  steve mcgrew

       Re: Linux worm creating P2P attack network  Don Jackson

       Re: Linux worm creating P2P attack network  Stewart Cannon

       Re: Linux worm creating P2P attack network  Brian Hartman

       Re: Linux worm creating P2P attack network  steve mcgrew

       ZDNET gets it wrong again  yeah right

       Re: ZDNET gets it wrong again  steve mcgrew

       Re: ZDNET gets it wrong again  William Beach

       Already fixed  Yoda *.

       Re: Linux worm creating P2P attack network  Tim Taylor

       Re: Linux worm creating P2P attack network  ph 3W7

       Re: Linux worm creating P2P attack network  steve mcgrew

       Re: Linux worm creating P2P attack network  Peter Wiliams

       Re: Linux worm creating P2P attack network  James Bigger

       Re: Linux worm creating P2P attack network  Burrito Warrior

       Re: Linux worm creating P2P attack network  Alexander S

       Re: Linux worm creating P2P attack network  Ralph Hudson

       Re: Linux worm creating P2P attack network  Yagotta B. Kidding

       Re: Linux worm creating P2P attack network  Alexander S

       Re: Linux worm creating P2P attack network  Damon Kaswell

       Re: Linux worm creating P2P attack network  Hellfire™

       Another useless admin problem.  ph 3W7

       It is not about Linux, it is about Open Source  Alexander S

       A question.  Vily Clay

       An answer  Alexander S

       Where the answer?  Vily Clay

       Re: Where the answer?  Alexander S

       The question was not "who is better".  Vily Clay

       Don't want new crap replace old crap.  Alexander S

       Re: Don't want new crap replace old crap.  Brian Barrier

       Re: Don't want new crap replace old crap.  Alexander S

       Re: Don't want new crap replace old crap.  ph 3W7

More Replies


 Search


 
 Tech Update

Coordinating a disaster plan

WLAN with no plan spells failure

Are you ready for "active networking?"

More networking analysis...

 News in Brief

Vodafone mulls French mobile phone operator  10:07AM

France Tel investors await cash call  08:53AM

WorldCom cuts international jobs  07:42AM

AT&T clamps down on multiple IP addresses  06:13AM

Cuba goes online to refute terror charge  04:54AM

More...

 Commentary

RASH RASH
Read Tech Update's expert on security and networking More...

More Commentary...


ZDNet Tech Update
Featured Resource Centers
Sybase:
Request for more info, Whitepapers and more.
Gateway:
Hardware, Products and more.

 News Tools

 News Archives

 News in Brief

 News for your PDA

 Contact Us

 Corrections
Newsletters
Tech Update Today
Security Update
OS Update




All newsletters
FAQ
Manage my newsletters


ZDNet
Services: Cybersecurity Report | Hosting Providers | IT Resources | CNET Back to School Guide | Tech Jobs

      CNET Networks: Builder | CNET | GameSpot | mySimon | TechRepublic | ZDNet
About CNET Networks 

About Us | Feedback | Your Privacy | Service Terms | Advertise | ZDNet Jobs
 
Copyright © 2002 CNET Networks, Inc. All rights reserved. ZDNet is a registered service mark of CNET Networks, Inc. ZDNet Logo is service mark of CNET Networks, Inc.