LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-09-2015, 02:46 AM   #1
Kropotkin
Member
 
Registered: Oct 2004
Location: /usr/home
Distribution: Mint, Ubuntu server, FreeBSD, Android
Posts: 362

Rep: Reputation: 32
Ransomware now targetting Linux servers


Hi all,

There is a new blog post by Brian Krebs about how ransomware is now targetting Linux servers, and he refers to a case of a site that was attacked via a Magento vulnerability:
Quote:
This latest criminal innovation, innocuously dubbed “Linux.Encoder.1” by Russian antivirus and security firm Dr.Web, targets sites powered by the Linux operating system. The file currently has almost zero detection when scrutinized by antivirus products at Google’s Virustotal.com, a free tool for scanning suspicious files against dozens of popular antivirus products.

Typically, the malware is injected into Web sites via known vulnerabilities in site plugins or third-party software — such shopping cart programs. Once on a host machine, the malware will encrypt all of the files in the “home” directories on the system, as well backup directories and most of the system folders typically associated with Web site files, images, pages, code libraries and scripts.
http://krebsonsecurity.com/2015/11/r...our-web-sites/

I get the feeling that Krebs doesn't know much about Linux, as in when he refers to the malware needing "administrator" access to the OS to work. Aside from terminology, who runs Apache as root anyway? I would be interested in hearing from others here who have more Linux-specific experience with security on the issues related to malware that targets Linux OS.

Thanks
 
Old 11-09-2015, 02:52 AM   #2
berndbausch
LQ Addict
 
Registered: Nov 2013
Location: Tokyo
Distribution: Mostly Ubuntu and Centos
Posts: 6,316

Rep: Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002
From the article:

Quote:
ramsomware infected a server used professional Web site designer Daniel Macadar
and

Quote:
Macadar was behind on backing up the site and the server
I guess there is something we can learn from this.

EDIT: It's true that the article mentions the need for good backups. But a "professional website designer" that runs a web shop should know this.

Last edited by berndbausch; 11-09-2015 at 02:54 AM.
 
Old 11-09-2015, 03:19 AM   #3
Kropotkin
Member
 
Registered: Oct 2004
Location: /usr/home
Distribution: Mint, Ubuntu server, FreeBSD, Android
Posts: 362

Original Poster
Rep: Reputation: 32
Well, it seems that not only was Macadar behind on backups, he was also behind in applying security updates to Magento, also a real no-no.
 
Old 11-09-2015, 03:47 AM   #4
allend
LQ 5k Club
 
Registered: Oct 2003
Location: Melbourne
Distribution: Slackware64-15.0
Posts: 6,376

Rep: Reputation: 2756Reputation: 2756Reputation: 2756Reputation: 2756Reputation: 2756Reputation: 2756Reputation: 2756Reputation: 2756Reputation: 2756Reputation: 2756Reputation: 2756
From https://news.drweb.com/show/?i=9686&lng=en
Quote:
Once launched with administrator privileges, the Trojan dubbed Linux.Encoder.1 downloads files...
Same old story, the bad actor needs root.
 
Old 11-11-2015, 03:32 PM   #5
Sefyir
Member
 
Registered: Mar 2015
Distribution: Linux Mint
Posts: 634

Rep: Reputation: 316Reputation: 316Reputation: 316Reputation: 316
Quote:
It’s worth noting that the malware requires the compromised user account on the Linux system to be an administrator; operating Web servers and Web services as administrator is generally considered poor security form, and threats like this one just reinforce why.
Worth noting? I'd say so. It's the theme of every linux "exploit".

This reminds me of users who "fix linux problems" by chmod -R 777 everything or run everything as root.

As for backing up, there shouldn't be "getting behind". They should always be automatic.

Quote:
However, not everything worked the way it should have.
You can say that again.. the person in this example paid the decryption - reinforcing more of this in the future.
 
Old 11-11-2015, 03:39 PM   #6
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
Linux Ransomware Debut Fails on Predictable Encryption Key
 
Old 11-15-2015, 11:51 AM   #7
metaschima
Senior Member
 
Registered: Dec 2013
Distribution: Slackware
Posts: 1,982

Rep: Reputation: 492Reputation: 492Reputation: 492Reputation: 492Reputation: 492
Quote:
We realized that, rather than generating secure random keys and IVs, the sample would derive these two pieces of information from the libc rand() function seeded with the current system timestamp at the moment of encryption. This information can be easily retrieved by looking at the file’s timestamp. This is a huge design flaw that allows retrieval of the AES key without having to decrypt it with the RSA public key sold by the Trojan’s operator(s).
Classic. Well, this is not the first time crypto ransomware designers have done this. Clearly and luckily, most of them are amateurs.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Wait, STOP: Are you installing Windows 10 or ransomware? LXer Syndicated Linux News 0 08-01-2015 11:00 PM
LXer: Is CryptoLocker Ransomware arriving on Android? LXer Syndicated Linux News 1 05-08-2014 08:06 PM
LXer: Two in five Brits cough up for CryptoLocker ransomware's demands LXer Syndicated Linux News 0 03-01-2014 07:10 PM
LXer: 16 Ways To Beat Cryptolocker and Ransomware LXer Syndicated Linux News 0 12-23-2013 01:30 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:56 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration