Lupper Worm Targets Linux
by Nancy Weil, IDG News Service
A worm that affects Linux systems and spreads by exploiting Web
server-related vulnerabilities has been reported by antivirus
companies, but so far Linux.Plupii, which is also known as Lupper,
hasn't spread much and isn't seen as much of a threat.
Linux users should update antivirus software and patches to protect
against the worm, say representatives of the major antivirus product
vendors said. Both McAfee and Symantec have updated their software to
identify and stop the worm.
Information about the worm can be found at McAfee's Web site and also
from Symantec.
How Worm Works
The worm spreads by exploiting Web servers hosting vulnerable PHP/CGI
programming language scripts, according to McAfee. The worm is a
derivative of the Linux/Slapper and BSD/Scalper worms from which it
has taken its propagation strategy, McAfee said in information
provided on its Web site about the worm, which was discovered Sunday.
The worm attacks Web servers by sending malicious Hypertext Transfer
Protocol (HTTP) requests on port 80, McAfee said. If the server being
targeted is running a vulnerable script at certain URLs and is
configured to permit external shell commands and remote file download
in PHP/CGI the worm could be downloaded and executed, McAfee said. It
can also harvest e-mail addresses stored in Web server files.
The worm opens a back door on a compromised computer and then
generates URLs to scan for other computers to infect and that can
affect network performance, according to Symantec.
Symantec rates the worm as having a medium damage and distribution
threat. As of Tuesday morning, it hadn't spread much and Symantec
said it is easy both to contain and remove. McAfee assessed it as a
low threat for both corporate and home users.
Copyright 2005 PC World Communications, Inc.
NOTE: For more telecom/internet/networking/computer news from the
daily media, check out our feature 'Telecom Digest Extra' each day at . Hundreds of new
articles daily.
*** FAIR USE NOTICE. This message contains copyrighted material the
use of which has not been specifically authorized by the copyright
owner. This Internet discussion group is making it available without
profit to group members who have expressed a prior interest in
receiving the included information in their efforts to advance the
understanding of literary, educational, political, and economic
issues, for non-profit research and educational purposes only. I
believe that this constitutes a 'fair use' of the copyrighted material
as provided for in section 107 of the U.S. Copyright Law. If you wish
to use this copyrighted material for purposes of your own that go
beyond 'fair use,' you must obtain permission from the copyright
owner, in this instance, PC World Communications, Inc.
For more information go to: