R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Say Cheese, there's a worm on the loose

Hot on the heels of the sadmind/IIS worm, another automated virus is on the attack.

James Middleton, vnunet.com 18 May 2001
ADVERTISEMENT

Hot on the heels of the sadmind/IIS worm, another automated virus is on the attack.

The self-propagating worm known as Cheese has been infecting Linux servers, and even though it actually patches a security hole under Linux, it is still seen as a threat by security analysts.

The Cheese worm seeks out Linux servers open to the vulnerability exploited by the Li0n worm which was on the loose two months ago. After gaining access to the system, Cheese patches up the back door, supposedly making the system more secure. It then uses the infected server as a platform to seek out other vulnerable servers on the internet.

Because the Li0n worm listens for data on port 10008, Cheese is programmed to scan this port as well, looking for vulnerable machines.

The enormous amount of scans performed by Cheese has also made it more noticeable to admins. One administrator on the BugTraq security mailing list said: "My firewall logs went insane last night with gazillions of connection attempts to port 10008."

Graham Cluley, senior technology consultant for Sophos, said that even though the virus appears to be doing some good, it is still malware. "Administrators will want to authorise any changes to their systems, this is still modifying a machine without authorisation," he said.

"And besides that," he added, "putting patches on a machine in the wrong order can cause even more damage."

Notes included in the virus code seem to portray the virus as being benign in intention. "This code was not written with malicious intent," reads one line. It claims to have been written "to stop pesky haqz0rs messing up your box even worse than it is already".

See also:

'Virus' cleans and patches infected machines  05 Sep 2001
Concern is growing about a malicious scripting tool that can be used to infect a Windows machine with a virus simply by browsing a web page.  18 Jun 2001
A vigilante virus is on the loose which infects Windows machines and shops supposed child pornographers to the authorities.  29 May 2001

All Hacking

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Computer People
SQL Server 2008 Developer – Staffordshire – Market Rate – 3 - 6 month initial role Computer People have an exciting opportunity for a SQL Server 2008 Developer within an Large organisation based in Staffordshire. ... more >
| Aston Carter
JAVA J2SE DEVELOPER – CREDIT DERIVATIVES amp; Credit Derivatives (CDS, CDO, CDX, IRD, IRS), Exotics and Structured Hybrid products. Technical skills include: Server side Java, SQL, Sybase, SOAP, WEB SERVICE and OOA/D. Nice to have ... more >
| Aston Carter
JAVA J2SE DEVELOPER – CREDIT DERIVATIVES amp; Credit Derivatives (CDS, CDO, CDX, IRD, IRS), Exotics and Structured Hybrid products. Technical skills include: Server side Java, SQL, Sybase, SOAP, WEB SERVICE and OOA/D. Nice to have ... more >
| Aston Carter
Java, C++, SQL Analyst Developer – Interest Rate Risk Java, C++, SQL, Analyst Developer, interest rate, risk, credit risk, market risk, perl, scripting • At least 2-5 years experience developing in C++ and Java • ... more >
More job opportunities