LinuxQuestions.org

LinuxQuestions.org (/questions/)
-   Linux - Security (https://www.linuxquestions.org/questions/linux-security-4/)
-   -   Mpack threat, is Linux vulnerable? (https://www.linuxquestions.org/questions/linux-security-4/mpack-threat-is-linux-vulnerable-563161/)

andy.l 06-20-2007 04:28 AM

Mpack threat, is Linux vulnerable?
 
Hi

I've read a lot in the media today about the new MPack malware, that also goes by the name "the iltalian job"

http://www.securityfocus.com/brief/529
http://www.symantec.com/enterprise/s...f_badness.html

But I find very little information about the targeted platforms. Now, my question is very simple, could this be exploited on Linux in genral, and OpenSuse 10.2 in special?

/A.

acid_kewpie 06-20-2007 04:56 AM

no, it's a microsoft exploit. http://www.symantec.com/enterprise/s...052712-1531-99

unSpawn 06-20-2007 12:02 PM

Even though the actual ANI exploit is targetted at Win this doesn't mean a) the sources (the webservers being exploited for redirection) could well be GNU/Linux boxen that where exploited by holes in PHP apps (since that's still common enough, sadly). And b) it's only Win is security-wise (and commercially speaking from certain types of crackers POV) a way easier target compared to Lin.

Note I'm not trying to spread FUD here, just trying to balance things a bit. Because they get exploited today we shouldn't get smug and leave implementing precautionary measures to tomorrow.

phantom_cyph 06-20-2007 12:08 PM

I have always wanted to be able to download a Windows virus and install it on my windows computer to see what happens, but I can never find a place to download them. It seems like you could use some of them for administrative purposes such as reformatting or shredding a drive.

<edit>I forgot you could download IE and Norton...;-)</edit>

unSpawn 06-21-2007 02:00 PM

Just pointing out the SANS Mpack analysis at http://isc.sans.org/diary.html?storyid=3015: "The Italian hosts responsible for most of the domains seen in a recent MPack attack are using cPanel, a Web administration tool for clients. A zero-day cPanel attack took place in the fall of 2006 leading up to the large scale vector mark-up language (VML) attacks at that time.".

Road_map 06-21-2007 02:45 PM

Quote:

Originally Posted by acid_kewpie

I am not so sure. Here, bellow of page there are 4 links. Read MPack.pdf.

jayjwa 06-24-2007 03:11 AM

It's a M$ thing. Any server can host the IFRAME or other exploit (that's just markup in HTML, Javascript, etc.), but it's glass-jawed Windoze-only that gets whacked (again).

The lack of info as to what is effected by all MPack reports I've read is starting to make me think they left it out on purpose (eg, Hmmm... wonder if Linux is vulnerable too? Better check their article... [* increase appropriate website hit counter *] ).


All times are GMT -5. The time now is 12:01 PM.