MSNBC on Linux worms for BIND 4.9.7 / 8.2.2 or earlier:
�IT SEEMS TO be a variant of the Ramen worm, said David Dittrich,
security administrator for the University of Washington and an expert
on digital forensics and hacking tools. The Ramen worm, which used
three well-known security flaws to infect systems using the Red Hat
distribution of Linux, hit in mid-January and infected an unknown
number of computers. The vulnerabilities exploited by Ramen occur in
three programs shipped with most Linux distributions and installed by
default. The 1i0n worm, discovered last month by the Systems
Administration Networking and Security Institute (SANS), used a
fourth flaw to spread among servers that had domain name service, or
DNS, software installed.
FINDING FLAWS
The Adore worm�also known as the Red worm�uses all four flaws to
automatically break into vulnerable systems. While patches have
existed for all the vulnerabilities for at least a few months, most
system administrators have not patched their systems, said Matt
Fearnow, incident handler for the SANS Global Incident Analysis Center.
Please visit http://www.ipswitch.com/support/mailing-lists.html
to be removed from this list.
An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/