LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-08-2005, 05:25 PM   #1
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
Lupper Worm


A new linux worm named Lupper along with several variants (Lupii, Lupii2, Listen) have been reported in the wild. These worms target several older vulnerabilities, including the XML-RPC, AWStats and Darryl Burgdorf's Webhints vulnerabilities. Analysis of the worm indicates that it attempts to upload a trojan to /tmp using wget. Anyone using PHP, AWStats, or Webhints are strongly encourage to verify that they are running current versions. See the following links for more details:

Worm specific links:
http://isc.sans.org/diary.php?storyid=829
http://isc.sans.org/diary.php?date=2005-11-05
http://www.symantec.com/avcenter/ven...ux.plupii.html
http://news.zdnet.com/2100-1009_22-5938475.html

Info on Vulnerabilities:
XML-RPC for PHP Remote Code Injection vulnerability
AWStats Rawlog Plugin Logfile Parameter Input Validation Vulnerability
Darryl Burgdorf Webhints Remote Command Execution Vulnerability
 
Old 11-09-2005, 08:38 AM   #2
TruckStuff
Member
 
Registered: Apr 2002
Posts: 498

Rep: Reputation: 30
Snort has picked up several of these attacks on our network in the last few days. The specific one I've seen is the one that exploits the XML-RPC vuln in PHP. The web page it posts to indicate that it is trying to attack specific apps that would be vulnerable were they installed. I haven't seen any indiscriminate posting looking for vulnerable pages.
 
Old 11-12-2005, 05:41 PM   #3
schneemann
Member
 
Registered: Nov 2005
Location: Nord Vancouver
Distribution: suse 10.0
Posts: 106

Rep: Reputation: 15
Re: Lupper Worm

Quote:
Originally posted by Capt_Caveman
A new linux worm named Lupper along with several variants (Lupii, Lupii2, Listen) have been reported in the wild. These worms target several older vulnerabilities, including the XML-RPC, AWStats and Darryl Burgdorf's Webhints vulnerabilities. Analysis of the worm indicates that it attempts to upload a trojan to /tmp using wget. Anyone using PHP, AWStats, or Webhints are strongly encourage to verify that they are running current versions. See the following links for more details:

Worm specific links:
http://isc.sans.org/diary.php?storyid=829
http://isc.sans.org/diary.php?date=2005-11-05
http://www.symantec.com/avcenter/ven...ux.plupii.html
http://news.zdnet.com/2100-1009_22-5938475.html

Info on Vulnerabilities:
XML-RPC for PHP Remote Code Injection vulnerability
AWStats Rawlog Plugin Logfile Parameter Input Validation Vulnerability
Darryl Burgdorf Webhints Remote Command Execution Vulnerability
What about my DLINK-604 firewall hardware is it safe?
 
Old 11-13-2005, 01:12 AM   #4
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Original Poster
Rep: Reputation: 69
Re: Re: Lupper Worm

Quote:
Originally posted by schneemann
What about my DLINK-604 firewall hardware is it safe?
As far as I know, it should be. I can't imagine that DLink would put any of those vulnerable applications on a SOHO firewall/router device. Theoretically even if they were to be installed with the Dlink firmware, they'd only be accessible over the configuration web interface which can only be accessed from the LAN side.
 
Old 11-13-2005, 07:26 AM   #5
schneemann
Member
 
Registered: Nov 2005
Location: Nord Vancouver
Distribution: suse 10.0
Posts: 106

Rep: Reputation: 15
Re: Re: Re: Lupper Worm

Quote:
Originally posted by Capt_Caveman
As far as I know, it should be. I can't imagine that DLink would put any of those vulnerable applications on a SOHO firewall/router device. Theoretically even if they were to be installed with the Dlink firmware, they'd only be accessible over the configuration web interface which can only be accessed from the LAN side.
In the Dlink manual tells me to updated my Dlink software.
That CD comes with DLINK-604 is 3years old should I update my driver?
 
Old 11-13-2005, 01:03 PM   #6
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Original Poster
Rep: Reputation: 69
Re: Re: Re: Re: Lupper Worm

Quote:
Originally posted by schneemann
In the Dlink manual tells me to updated my Dlink software.
That CD comes with DLINK-604 is 3years old should I update my driver?
You should always update firmware with the lastest versions. Check the Dlink website to see the most recent release version. Again, I highly doubt that this would affect your router, so I don't believe dlink will release new versions specifically to deal with these vulns. They may have new releases availble to correct other hardware/software bugs though, so upgrading is probably a good idea. Make sure to follow the directions carefully though, as botching a firmware upgrade can turn your router into a brick.
 
Old 11-13-2005, 02:21 PM   #7
schneemann
Member
 
Registered: Nov 2005
Location: Nord Vancouver
Distribution: suse 10.0
Posts: 106

Rep: Reputation: 15
Re: Lupper Worm

Quote:
Originally posted by Capt_Caveman
You should always update firmware with the lastest versions. Check the Dlink website to see the most recent release version. Again, I highly doubt that this would affect your router, so I don't believe dlink will release new versions specifically to deal with these vulns. They may have new releases availble to correct other hardware/software bugs though, so upgrading is probably a good idea. Make sure to follow the directions carefully though, as botching a firmware upgrade can turn your router into a brick.
I looked into it no available.
So I`m doing fine then
 
Old 01-05-2006, 09:36 AM   #8
celejar
Member
 
Registered: Oct 2003
Location: New York
Distribution: Debian Sid
Posts: 185

Rep: Reputation: 30
Quote:
Originally Posted by Capt_Caveman
As far as I know, it should be. I can't imagine that DLink would put any of those vulnerable applications on a SOHO firewall/router device. Theoretically even if they were to be installed with the Dlink firmware, they'd only be accessible over the configuration web interface which can only be accessed from the LAN side.
I don't know about the Dlink specifically, but some routers (like my Netgear MR814) can be configured to allow access to the config web interface from the WAN side too. Of course, you definiteley shouldn't enable that without a) a very good reason, b) a very good password and c) knowing what you're doing
 
Old 02-21-2006, 01:52 PM   #9
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Exclamation The Lupper Worm Has Mutated

Quote:
Since the end of last week, new variants of the Linux worm called Lupper have been making their way through the Internet. Anti-virus experts are using a slew of different names for them: Plupii.C, Lupper.worm.b, Lupper-I and Mare.d.
http://www.heise.de/english/newsticker/news/69878

Quote:
Security experts today warned of a Linux network worm that exploits holes in the Mambo content management system and the PHP XML-RPC library.
http://www.vnunet.com/vnunet/news/21...nux-worm-loose

Quote:
Internet ne'er do wells have created a Linux worm which uses a recently discovered vulnerability in XML-RPC for PHP, a popular open source component used in many applications, to attack vulnerable systems. The Mare-D worm also tries to take advantage of a security flaw in Mambo to spread. If successful, the worm installs an IRC-controlled backdoor on compromised systems.
http://www.theregister.co.uk/2006/02/20/linux_worm/

Quote:
A Linux network worm that installs backdoors to compromised systems and which “listens” for commands from its creator is on the loose, security experts have warned.
http://www.computerweekly.com/Articl...ontheloose.htm
 
Old 02-27-2006, 08:02 AM   #10
redice
Member
 
Registered: Aug 2005
Location: In My Office
Distribution: Fedora, Ubuntu
Posts: 61

Rep: Reputation: 15
So does this machine affect servers running horde on fedora C3??
Iv realised that Horde has files names xmlrpc.php in the following
locations


/usr/share/psa-horde/lib/Horde/RPC/xmlrpc.php
/usr/local/sitebuilder/include/kernel/xmlrpc.php

any ideas?

Redice
 
Old 02-27-2006, 09:07 AM   #11
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
at the time of this post:
Quote:
The Secunia database currently contains 0 Secunia advisories marked as "Unpatched", which affects Horde Application Framework 3.x.
http://secunia.com/product/4524/

just my ...
 
Old 02-27-2006, 09:28 AM   #12
redice
Member
 
Registered: Aug 2005
Location: In My Office
Distribution: Fedora, Ubuntu
Posts: 61

Rep: Reputation: 15
Thanks there,
Meaning nothing needs to be patched up on my horde!

Any other comments out there?

Redice
 
Old 02-27-2006, 09:35 AM   #13
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Original Poster
Rep: Reputation: 69
Agreed. However I would make sure that the main PHP packages themselves have been updated, as they include an xml-rpc lib too.
 
Old 02-27-2006, 11:07 AM   #14
redice
Member
 
Registered: Aug 2005
Location: In My Office
Distribution: Fedora, Ubuntu
Posts: 61

Rep: Reputation: 15
How would one go about updating the PHP packages in Horde?

redice
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
_files directory weirdness / possible Lupper infection? Jim Miller Linux - Security 1 11-17-2005 06:17 PM
Is this a virus / worm? rioguia Linux - Security 1 11-17-2004 05:22 PM
**help** worm.somefool.p AnimaSola Linux - Security 3 05-01-2004 08:55 PM
Worm on Linux? :O Cdzin Linux - Security 7 03-10-2004 04:51 PM
beat the worm!!!! engnet Linux - Networking 14 01-27-2004 02:18 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:45 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration