ZDNet:  Reviews | Downloads | Tech Update | Prices
Page OneApplicationsNetworkingeBusinessHardwareCommentary


Virus writers get Slapper happy
By Robert Lemos
Special to ZDNet News
October 4, 2002, 3:56 PM PT


Internet vandals have continued to modify the recent Slapper worm and have sent at least four new variants of the hostile Linux program into the electronic wilds.

The newest variant, dubbed "Mighty," exploits the same Linux Web server flaw that other versions of the Slapper worm have used to slice through the security on vulnerable servers. Russian antivirus company Kaspersky Labs said in a release Friday that more than 1,600 servers had been infected by this latest variant as of Friday morning and are now controlled by the worm via special channels on the Internet relay chat system.

"In this way, 'Mighty' is able to leak out confidential information, corrupt important data, and also use infected machines to conduct distributed (denial of service) attacks and other nasty activities," Kaspersky Labs said in the advisory.

Because the worm deposits its source code on any system that it infects, security researchers expect more modified versions of the virus to appear.

"People are doing a lot of variants," said Marc Maiffret, chief hacking officer for network protection firm eEye Digital Security. "No one has found any good way to handle these worms."

As long as there are servers whose administrators don't care enough or don't know enough to patch the security holes, such worms will continue to spread, Maiffret said.

Since Code Red infected more than 350,000 servers last summer, computer worms have become the No. 1 perceived danger on the Internet. The self-replicating programs exploit security vulnerabilities to break into computers, then use those systems to infect other servers around the Internet.

While the worst attacks--Code Red and Nimda--have been against Microsoft's Web server, Linux servers have been compromised by worms in several moderate incidents, starting with the Ramen worm and moving on to the latest Slapper worm.

The Slapper worm infected as many as 20,000 servers before system administrator began installing patches and cleaning compromised systems, putting the program on the endangered species list.

A variant by any other name...
"Mighty" may be the fifth variant of Slapper to hit the Internet since the original worm was released last week. However, because of the different naming conventions used by security companies, the worm may be too similar to another version, Slapper.D, to be considered a variant.

Slapper.D, also known as "DevNull," appeared on the Internet on Monday, according to security software firm Symantec. While the original Slapper worm and previous variants all created a homegrown peer-to-peer network to communicate among themselves, DevNull used a well-known hacking tool--called "Kaiten"--to let the compromised servers talk with their creator via a channel on Internet chat, said Elias Levy, security architect for Symantec.

Levy expects more variants, but he believes that the tactic of using the SSL (secure sockets layer) vulnerability to bypass security is past its prime.

"The number of infected systems has been reduced," Levy said. "Different antivirus vendors have been e-mailing the people in charge of those (infected) machines."

In some cases, Levy said, gray hat hackers in the underground have used the peer-to-peer network against itself, sending commands from one compromised server across the homegrown network to shut down other, infected computers.

Other variants of the Slapper code merely changed the port--a software address that computers use to talk to each other over the Internet--that the worm used as the communications channel for the peer-to-peer network. Slapper itself is a Linux variant of another worm, Scalper.c, which didn't get far because it only targets OpenBSD systems, a far smaller pool of computers.

In any event, Scalper is on the way out, said Roger Thompson, director of malicious-code research at security service provider TruSecure.

"We know that most people, but not everybody, are going to patch their systems," Thompson said. A few, old machines that aren't well administered will keep the worm alive for some time, but it shouldn't infect many more computers.

"I think that the Slapper things are just going to become background noise," Thompson said.

E-mail this story! Printer Friendly

Also on ZDNet
Find the tech gear you need in CNET's Back to School guide.
Get ahead of the competition with the BizTech Library.
Improve your PC's performance with the Memory Configurator.
Don't miss up-to-the-minute IT commentary on TechRepublic's blog.
Laid off? Find a new IT job today in our Career Center.

 TalkBack: Post your comment here
       Defend your OS now you linux hippies  Martin Marvinski

       Re: Defend your OS now you linux hippies  bech emot

       Re: Defend your OS now you linux hippies  Andy Calhoun

       Re: Defend your OS now you linux hippies  Jim K

       Re: Defend your OS now you linux hippies  Kevin Hughes

       What a bunch of FOOLS, M$ sucked you in again  Andy Calhoun

       I laugh at thee  Penguins^ ^Abound

       Re: I laugh at thee  Jeremy Esquire

       No, you misunderstood.  Michael O'Brien

       Jeremy, 90% of your posts are worthless  Andy Calhoun

       Re: Jeremy, 90% of your posts are worthless  Richard Hayes

       Um, let's see....  Joe Cuervo

       Stupid administrators!  George Mitchell

       Re: Virus writers get Slapper happy  Peter Schroeder

       Re: Virus writers get Slapper happy  Don Jackson

       Re: Virus writers get Slapper happy  Don Jackson

       I am so sick of this...  Damon Kaswell

       Re: I am so sick of this...  Kahlil Haynes

       Re: I am so sick of this...  Don Jackson

       Re: I am so sick of this...  Suckers Cents

       What about MS SQL worm?  Joe Bob

       Re: What about MS SQL worm?  Suckers Cents

       Re: What about MS SQL worm?  Don Jackson

       Re: Virus writers get Slapper happy  Don Jackson

       Re: Virus writers get Slapper happy  Michael O'Brien

       Re: Virus writers get Slapper happy  Suckers Cents

       Re: Virus writers get Slapper happy  Brian Hartman

       Re: Virus writers get Slapper happy  Suckers Cents

       Linux few - Mirosoft many  Roberto Salazar

       Re: Linux few - Mirosoft many  William Zack

       Question about Slapper ...  Dick Leaky

       Re: Question about Slapper ...  Yagotta B. Kidding

       Roberto I disagree  Gary Simmons

       No one seems to recall...  pete sanchez

       (NT) Childish feuding alll of you.  Jim K

       Has anybody considered...  Charles Otstot


 Tech Update

Securing cyberspace: The national plan

InfiniBand--old before its time?

Take steps to minimize laptop loss

More networking analysis...

 News in Brief

Professional gamers cash in at jackpot sites  04:56PM

eBay delays insurance program  03:36PM

Malaysians see no trace of Bugbear author  02:39PM

Telecoms see little demand for 3G  01:06PM

Teen saved after online suicide bid  12:04PM



Read Tech Update's expert on security and networking More...

More Commentary...

ZDNet Tech Update
Featured Resource Centers
Request for more info, Whitepapers and more.
Hardware, Products and more.

 News Tools

 News Archives

 News in Brief

 News for your PDA

 Contact Us

Tech Update Today
Security Update
OS Update

All newsletters
Manage my newsletters

Services: IT Jobs | New WebFerret | Premium Research | Web Hosting | Windows XP Guide

      CNET Networks: Builder | CNET | GameSpot | mySimon | TechRepublic | ZDNet
About CNET Networks 

About Us | Feedback | Your Privacy | Service Terms | Advertise | ZDNet Jobs 
Copyright © 2002 CNET Networks, Inc. All rights reserved. ZDNet is a registered service mark of CNET Networks, Inc. ZDNet Logo is service mark of CNET Networks, Inc.