. Updated Daily. Editions SDA India   SDA Indonesia
JAX Asia 2008 - Conference for Enterprise Java, SOA, Spring, Web Services, Ajax, Agile and more
BUSINESS ENTERPRISE SOLUTIONS ARCHITECTURE INFORMATION SECURITY WIRELESS & MOBILITY DATA & STORAGE DEVELOPMENT HARDWARE













News

Tuesday, 21 February 2006

Linux Worm Turns On Mambo and PHP

 

 

Security experts today warned of a Linux network worm that exploits holes in the Mambo content management system and the PHP XML-RPC library. Dubbed Mare.D, the worm leaves multiple backdoors on infected systems. Two of these are connectback shell backdoors that link to a remote host, while a third allows the malware's writer to access and control infected systems via IRC.

"The main component of the Mare.D worm is written in C and compiled with the GNU C compiler," said F-Secure researcher Gergely Erdelyi.

The worm scans for vulnerable systems automatically and installs a small shell script which downloads the rest of the malware.

The vulnerabilities in Mambo and the PHP XML-RPC library are both rated as 'highly critical' by vulnerability testing group Secunia, but patches are available for both.


 

Source

 
 
print save email comment

print

save

email

comment

 
 

Search SDA Asia

Free eNewsletter

SDA Asia Magazine Free Download
 
 
 
Copyright @ 2008 SDA Asia Magazine - All Right Reserved Privacy Policy | Terms of Use