March 23, 2001 1:15 PM PST

'Lion' worm stalks Linux machines

A dangerous worm that can steal passwords from Linux servers is rapidly spreading across the Internet and infecting other machines, researchers said Friday.

see special report: Year of the Worm Dubbed the "Lion" worm, the self-spreading program attacks servers running specific versions of BIND (Berkeley Internet Name Domain) server software. Because it can be so difficult to remove, victims may have to wipe out their entire hard disks.

"We think it's going to cause people, unless they are brilliant, to nuke the machine, erase everything on the disk, install the entire operating system against hope (their) back-up files work," said Alan Paller, director of research at the The System Administration, Networking and Security (SANS) Institute. "We don't believe it can be cleaned out."

BIND server software gives instructions to domain name system (DNS) servers to translate Web addresses, or URLs, into number-based IP addresses. Those addresses then are read by PCs to direct a user to a specific Web site.

The SANS Institute said they have had five confirmed reports of worm infections: four companies and one university.

Linux machines infected with the worm send encrypted administrator level, or "root," password files to China.com, where hackers can potentially decrypt the password and use the information to gain access to various areas of a company's system. The worm also creates "back doors," which provide administrator-level access to hackers.

The worm appears to be mutation of the Ramen worm that was discovered in January and infects only servers running Red Hat's version of Linux.

"If they gain access through one of these back doors, they have unrestricted access to the machine," said John Green, director of information security for the SANS Institute. "This includes deleting software, installing software, gaining proprietary information, altering trust relationships, anything."

Despite the potential problems the worm could cause, little serious damage has been detected so far.

"To my knowledge, no one has recorded that they have been breached by an attack. They simply noted that the worm infected them and they're looking to get rid of it," said Elias Levy, Chief Technical Officer of SecurityFocus.com.

The "Lion" worm attempts to protect itself from detection by installing a "root kit" on infected machines, which hides the presence of hacker tools. As a result, IT administrators checking an infected machine may not immediately see it.

As a remedy, SANS has created a program called Lionfind that IT administrators can use to determine if their machines are infected.

Levy said a patch for this vulnerability has been available from the Internet Software Consortium for several months. "The only machines that are becoming infected are machines that haven't been kept up to date with security patches," Levy said.

SANS' Paller warned that the worm could easily mutate to infect other Unix-based machines, including Solaris, AIX and HPIX.

"The change to make this worm work on other versions of Unix is trivial," Paller said. "There's no reason to think you're safe if you run Solaris or another Unix box."

See more CNET content tagged:
SANS Institute, worm, IT administrator, Linux server, Unix

Powered by Jive Software
advertisement

Latest tech news headlines

Resource center from News.com sponsors
What you need in business class email.
Mailtrust

Click Here!
Never worry about email again. From mobility and shared calendaring to virus and spam protection starting at only $3 per mailbox. more>

Rackspace Mailtrust
Total Email Relief

We'll take care of your email so you can take care of your business.

14 Day Free Trial

With expert support 24x7x365 we guarentee 100% uptime. Try us for free for 14 days. Never worry about your email again.

Just $3 per mailbox

Choose the plan that is right for your company and only pay for what you need.

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right
  • Nanotech: The Circuits Blog

    Report: More competitive processors due from AMD

    AMD will bring out processors by early next year that appear to be much more competitive with Intel offerings.

  • Gallery

    Photos: Top 10 reviews of the week

    Here are CNET Reviews' 10 favorite items from the past week, including the TiVo HD XL, Sony Cyber-shot DSC-H50, and the Dish Network's newest digital TV converter box.

  • News - Apple

    Apple watchers spot 'iPod Nano' pix, iTunes hints

    The rumor mill has long been predicting a longer, leaner new version of the iPod Nano, and now it's conjuring up some pictures.

  • Coop's Corner

    Chris Shipley 1, Internet lynch mob 0

    Demo's impresario goes public with a tart and smartly written riposte to the shoot-from-the-lip crowd.

  • Video

    Katie Couric reflects on first Webcast

    The political conventions are over and so are CBS Evening News anchor Katie Couric's first series of Webcasts. CNET's Kara Tsuboi sat down with Couric on the final night of the Republican National Convention to discuss what she liked about Webcasting, some of her most memorable guests, and whether TV news will still be around by the next round of conventions.

  • News - Digital Media

    Ad trade group opposes Yahoo-Google search deal

    Association of National Advertisers announces it has sent a letter to the top antitrust chief for the U.S. Department of Justice, issuing its objections to the controversial Yahoo-Google search ad partnership.

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Gaming and Culture

    Are Demo and TechCrunch50 fragmenting their audiences?

    With both events scheduled to start Monday, many press, as well as venture capitalists and others are having to choose which one to attend.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Images: The art of 'Spore' prototypes

    Will Wright and his Maxis team worked on dozens of prototypes to test the elements of their soon-to-be-released evolution game. Here's a sampling.

  • Webware

    DemoFall preview: 10 to watch

    If you can only watch 10 pitches from DemoFall, these would be good ones.

  • Green Tech

    Duke Energy to invest in mini solar power plants

    Can hundreds of rooftop solar panels collectively operate like a central power plant? Duke Energy launches $100 million distributed solar program to find out.