New 'Lion' virus on the loose

Published: 27 March 2001 y., Tuesday
Computer security experts have unearthed a new worm that they say is spreading rapidly on the Internet and is capable of changing network settings, stealing passwords and eliminating some security measures, setting up the infected machine for further attacks. Known as the Lion worm, the virus spreads through an application called "randb," which infects Linux machines running version 8 of the BIND DNS software, one of several iterations that are known to have numerous security vulnerabilities. Lion scans random networks, probing TCP port 53, looking for potential targets. Once the application finds a vulnerable machine, it uses an exploit called "name" and then installs the t0rn rootkit, which enables the attacker to wreak havoc on the compromised machine, according to an alert posted Friday morning by the SANS Institute. The worm then performs several operations, including sending a password file and some network settings to a mail address with the chin.com domain, deleting a file called /etc/hosts.deny, which eliminates the host-based perimeter protection, installing backdoor root shells on two TCP ports, installing a "trojaned" version of the secure shell, killing the system log and searching for a hashed password. SANS has developed a utility that will detect -- but not remove -- the worm. Lion exploits the transaction signature buffer-overflow vulnerability in BIND (Berkeley Internet Name Domain) version 8, which is one of four weaknesses found in January in the open-source DNS software. Fixes are available for all of the BIND flaws. After the Lion worm finishes its work, it then forces the compromised machine to scan the Internet for other vulnerable servers.
Šaltinis: eWEEK
Copying, publishing, announcing any information from the News.lt portal without written permission of News.lt editorial office is prohibited.

Facebook Comments

New comment


Captcha

Associated articles

NASA to merge media archives

Space officials want proposals for a NASA archiving system that would create a one-stop multimedia source for the public more »

Google Focuses Local Ad Targeting

Search giant Google will offer its advertisers the chance to more tightly target the geographical areas where their ads will be seen more »

'Linspiration' Hits Lindows

Lindows executives have rolled out a new moniker for its desktop Linux software and the name is...Linspire more »

Spam reaches new high in March

More than one million junk emails sent on one day alone more »

Internet nonprofit meets with U.N.

U.S. company controls domain names; security, governing discussed more »

ITT fashion spring “CeBIT 2004”

18th world’s largest information technologies’ and telecommunications’ exhibition “CeBIT 2004”, which takes place in Hanover (Germany) annually, has already ended. more »

Foreign fraud hits U.S. e-commerce firms hard

Top offending countries: Yugoslavia, Nigeria, Romania more »

'Buffalo Spammer' convicted

A man accused of using EarthLink Inc. e-mail accounts to release a flood of unsolicited commercial ("spam") e-mail on the Internet has been convicted on charges of identity theft and falsifying business records more »

Google Gets E-Mail

Search player Google is getting into the e-mail game more »

New eMail Tales in Microsoft's Minn. Case

Microsoft officials sought to dissuade Intel from investing in handwriting software startup GO Corporation in 1990, according to the latest round of e-mail evidence more »