All the latest UK technology news, reviews and analysis

Linux users warned of new Trojan danger

by James Middleton

07 Sep 2001

Be the first to comment

  • Tweet this

Security companies are warning Linux users over a new and dangerous Trojan that may have originated in the UK.

The Trojan contains self-replicating virus-like capabilities and has similarities to the Windows-based Back Orifice tool, putting Linux boxes at risk of remote control.

The so-called Remote Shell Trojan spreads through email as well as replicating itself across the infected system. It installs a backdoor which listens for incoming connections on UDP port 5503 or higher, and allows remote attackers to connect to, and take control of, an infected system.

The Trojan is most dangerous if it is executed by a privileged user as it inherits the credentials of that user, effectively allowing it to take full control.

Qualys, the security firm claiming to have discovered the worm, said: "Once a system is infected, the Remote Shell Trojan calls home to a UK-based website."

The company explained that this would allow hackers to accumulate lists of infected servers which could be used "to construct chronic distributed denial of service attacks on specified targets".

Qualys also warned that the size and scope of the Trojan could be massive. Over 58 per cent of websites worldwide currently use Apache servers for which Linux is the most popular platform.

If the worm turns into an epidemic this gives it more potential for damage than Code Red, which affected Windows NT servers that account for just 25 per cent of website servers, according to Qualys.

More information and a worm removal tool can be found here.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

32%

1%

10%

57%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

Grad BI Consultant

Implementation Consultant - Business Intelligence Software...

SQL Server DBA, ETL, SSIS, Financial

SQL Server DBA, ETL, SSIS, Datawarehousing, Financial...

Senior DB2 DBA

Job description *Customer facing: should be able to...

PHP / MySQL / Zend Framework Developer - Chelmsford

PHP / MySQL / Zend Framework Developer - Chelmsford...

To send to more than one email address, simply separate each address with a comma.