New 'Lion' virus on the loose

Published: 27 March 2001 y., Tuesday
Computer security experts have unearthed a new worm that they say is spreading rapidly on the Internet and is capable of changing network settings, stealing passwords and eliminating some security measures, setting up the infected machine for further attacks. Known as the Lion worm, the virus spreads through an application called "randb," which infects Linux machines running version 8 of the BIND DNS software, one of several iterations that are known to have numerous security vulnerabilities. Lion scans random networks, probing TCP port 53, looking for potential targets. Once the application finds a vulnerable machine, it uses an exploit called "name" and then installs the t0rn rootkit, which enables the attacker to wreak havoc on the compromised machine, according to an alert posted Friday morning by the SANS Institute. The worm then performs several operations, including sending a password file and some network settings to a mail address with the chin.com domain, deleting a file called /etc/hosts.deny, which eliminates the host-based perimeter protection, installing backdoor root shells on two TCP ports, installing a "trojaned" version of the secure shell, killing the system log and searching for a hashed password. SANS has developed a utility that will detect -- but not remove -- the worm. Lion exploits the transaction signature buffer-overflow vulnerability in BIND (Berkeley Internet Name Domain) version 8, which is one of four weaknesses found in January in the open-source DNS software. Fixes are available for all of the BIND flaws. After the Lion worm finishes its work, it then forces the compromised machine to scan the Internet for other vulnerable servers.
Šaltinis: eWEEK
Copying, publishing, announcing any information from the News.lt portal without written permission of News.lt editorial office is prohibited.

Facebook Comments

New comment


Captcha

Associated articles

SMART Comp. to Install Fiber-to-the-Home Optical Infrastructure in 6,600 Brno Homes with Cisco Technology

FTTH Network Provides High-Speed Internet, IPTV and VoIP Telephony in One. more »

Security guards trapped inside cash machine in Erdington

FIRE crews came to the rescue of two security guards who were trapped inside a cash machine for nearly two hours. more »

Wincor Nixdorf names new U.S. CEO

Wincor Nixdorf International has named Patrick Wright its new chief executive officer for the U.S. division. more »

Motorola and Deutsche Telekom Collaborate on IPTV

Deutsche Telekom selects Motorola’s IPTV set-tops for T-Home Entertain Services; users to receive compelling, rich media experiences. more »

Microsoft Unveils Its First Windows Embedded R&D Center in Europe

New regional development center in Germany is part of $75 million global investment by Windows Embedded Business. more »

Cisco Executive Promises Wave of Change at Meeting of Portuguese National Association for the Development of Telecommunications

Diogo Vasconcelos, the newly elected President of the Portuguese National Association for the Development of Telecommunications (APDC), has promised to transform the organisation's role in driving forward the country's digital agenda. more »

Microsoft Working to Make Political Conventions Unconventional

Microsoft is helping transform the upcoming Democratic and Republican national conventions into the most technologically advanced and inclusive conventions ever held. more »

Real-time fraud alerts notify Visa cardholders of ID theft

Visa and leading North American financial institutions have agreed to launch a pilot with up to 2,000 participants to test the delivery of real-time notification alerts on Visa accounts. more »

Wincor Nixdorf to provide ATMs to Australia's Banktech

Wincor Nixdorf International has secured a deal to provide ATMs to Banktech, an independent ATM provider in Australia. more »

Branch, ATM security moves toward more holistic solutions

Financial breaches and identity theft cases seem to be in the headlines on an almost regular basis. Just last month, hackers broke into a Citibank-branded ATM network and stole millions. more »