nasty_virus
nasty_virus

Rare Linux virus on the loose

'RST.b' similar to Remote Shell Trojan found in October

James Middleton

It has emerged in the last week that another of those rare Linux viruses may be on the loose. And this one has strong similarities to October's Remote Shell Trojan (RST) that was largely dismissed by the Linux community.

In a posting to a security mailing list at the end of December, SecurityFocus brought 'RST.b' to the internet community's attention.

Advertisement

The researchers warned that the culprit carrying the virus is likely to be "some exploit being passed around, possibly a Secure Shell one". Linux users are advised not to run exploits from unknown sources.

Once it has gained a foothold into the system, it installs a back door and attempts to escalate its permissions to root privileges.

The basic differences to the October version are that the new virus tries to communicate with a machine on a different IP address to the original RST, and the backdoor operates on the Exterior Gateway Protocol instead of the User Datagram Protocol.

Like the original RST, the virus infects binary files in the Linux Executable and Linking Format (ELF).

RST.b infects the start address in ELF headers with an address that points to its own code. So when an infected program is run, a parent string forks off to run the original code so as to avoid suspicion, while a child string "takes care of the evil stuff", according to researchers at Lockeddown.net.

"Not only do we have a virus spreading, but it is opening up the infected boxes to attackers," they added.

A SecurityFocus researcher who attempted to contact the host of the web server that had infected the machines said: "The response I got indicated that 'his account was terminated a few weeks ago'. I received no response to a later request for clarification."

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

Complex Linux virus warning

'Zeitgeist of new interest', says expert

Experts warn of Linux/Windows virus

Polymorphic, entry-point-obfuscating worm hits the web

Jac virus targets Linux

First to hit the platform in three months

Desktop Linux still remote

Operating system is still no threat to Microsoft.

Related whitepapers

Related jobs

Most watched

V3.co.uk weekly debrief, 13 Nov 09

This week we discuss the inaugural V3.co.uk Summit

Summit: Salesforce.com on SaaS and information overload

How web services contribute to data headaches

Analysis and Reports

Remote access - Three steps to getting connected

3.4 million UK professionals now work from home – is your company equipped?

Cost benefits of a global collaboration network

This white paper is a must read for organisations looking for evidence of the bottom-line benefits of high-definition video and voice communications

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

White paper library

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Spotlight

V3.co.uk weekly debrief, 13 Nov 09

This week we discuss the inaugural V3.co.uk Summit

Fingers on keyboard

New Flash vulnerability discovered

Web sites could be vulnerable to Flash attacks

Chris Adams

Summit: Microsoft Office to the rescue

Chris Adams, Office Client product manager for Microsoft UK, explains...

Illegal downloader

Industry and human rights campaigners united in opposition to "three strikes" plan

Critics says government proposals to curb illegal downloading are unworkable...

Primary Navigation