New 'Lion' virus on the loose

Published: 27 March 2001 y., Tuesday
Computer security experts have unearthed a new worm that they say is spreading rapidly on the Internet and is capable of changing network settings, stealing passwords and eliminating some security measures, setting up the infected machine for further attacks. Known as the Lion worm, the virus spreads through an application called "randb," which infects Linux machines running version 8 of the BIND DNS software, one of several iterations that are known to have numerous security vulnerabilities. Lion scans random networks, probing TCP port 53, looking for potential targets. Once the application finds a vulnerable machine, it uses an exploit called "name" and then installs the t0rn rootkit, which enables the attacker to wreak havoc on the compromised machine, according to an alert posted Friday morning by the SANS Institute. The worm then performs several operations, including sending a password file and some network settings to a mail address with the chin.com domain, deleting a file called /etc/hosts.deny, which eliminates the host-based perimeter protection, installing backdoor root shells on two TCP ports, installing a "trojaned" version of the secure shell, killing the system log and searching for a hashed password. SANS has developed a utility that will detect -- but not remove -- the worm. Lion exploits the transaction signature buffer-overflow vulnerability in BIND (Berkeley Internet Name Domain) version 8, which is one of four weaknesses found in January in the open-source DNS software. Fixes are available for all of the BIND flaws. After the Lion worm finishes its work, it then forces the compromised machine to scan the Internet for other vulnerable servers.
Šaltinis: eWEEK
Copying, publishing, announcing any information from the News.lt portal without written permission of News.lt editorial office is prohibited.

Facebook Comments

New comment


Captcha

Associated articles

search.lt news

search.lt presents newest links more »

Mapping the New Internet

Expert says it will take a new attitude to squash spam, wire your washer, and identify the next IM more »

A Linux Desktop Bonanza

Linux desktop vendors Xandros and Linspire (also known as Lindows) are offering more desktop software for less, and, in the case of Xandros, for nothing more »

Traditional School Moves to the Internet

Penki kontinentai” implements the first unique project of electronic school in Lithuania. This project must change collaboration between teachers and students improve expedition, information search and change such a negative view of school in general.

more »

Windows 'Lock-In' Worries

Microsoft Corp.'s plans for a common set of services that promise its server platform products will work better together are being met with skepticism. more »

New Prescott Pentium 4 processors on tap from Intel

Among the eight new chips will be Intel's first workstation processors with 64-bit extensions technology more »

The Changing Face of E-Mail

Information overload will drive e-mail into the ground unless software vendors act now and make major changes to the 30-year-old technology more »

AMD Refreshes Athlon 64 CPUs

Four 64-bit chips with fast cache join Athlon family. more »

Sony to exit key handheld arenas

Sony is scaling back its Clie handheld line and will bow out of the U.S. and European markets for PDAs more »

CeBIT America means business

In its second year, show improves in size and focus more »