| | |
Linux boxes make ideal botnet controllers
Please support our Network Security advertiser: Network Management Software: Free IT Tools from Spiceworks
Security researchers at Sophos Labs have revealed that nearly 70 percent of all Linux honeypot infections are caused by a single virus. Perhaps even more shocking, all things considered, is the fact that the virus in question, Linux/Rst-B, is actually six years old now. So concerned is Sophos at this identified trend that is has now made a specific tool available just to detect whether this one virus is present on your Linux based computer or server.
The fact that Linux servers are of great interest to the cyber-criminal fraternity should come as no surprise, after all these are likely to be 24/7 running machines and because the general (misplaced) perception is that Windows based systems are inherently insecure and Linux ones the opposite, protection against malware attack is sadly lacking. The cold, harsh truth is that Linux systems are pretty much ideal for being compromised for use as a botnet controller, ironically more often than not being in control of a virtual army of infected Windows PCs.
"The number of malware programs in existence is around 350,000, and while only a very small number of these target Linux, it seems as though hackers are taking advantage of this false sense of security," said Carole Theriault, senior security consultant at Sophos.
Meanwhile, Billy McCourt, a SophosLabs UK researcher, wants your help to determine just how prominent these Linux based botnet controllers are. In order to do this he is asking that anyone who is not running some kind of anti-virus solution on their Linux boxes to run the small rudimentary Linux/Rst-B scanner and contact the labs with the results if they show that you have been infected. Billy asks that you scan your whole system but if this isn't feasible then at least scan your /bin /usr/bin /tmp /var/tmp /sbin and /usr/sbin directories and send any infected files (in encrypted format) to rstb@sophos.com who will check whether they are infected hacking tools or just infected standard binaries.
The fact that Linux servers are of great interest to the cyber-criminal fraternity should come as no surprise, after all these are likely to be 24/7 running machines and because the general (misplaced) perception is that Windows based systems are inherently insecure and Linux ones the opposite, protection against malware attack is sadly lacking. The cold, harsh truth is that Linux systems are pretty much ideal for being compromised for use as a botnet controller, ironically more often than not being in control of a virtual army of infected Windows PCs.
"The number of malware programs in existence is around 350,000, and while only a very small number of these target Linux, it seems as though hackers are taking advantage of this false sense of security," said Carole Theriault, senior security consultant at Sophos.
Meanwhile, Billy McCourt, a SophosLabs UK researcher, wants your help to determine just how prominent these Linux based botnet controllers are. In order to do this he is asking that anyone who is not running some kind of anti-virus solution on their Linux boxes to run the small rudimentary Linux/Rst-B scanner and contact the labs with the results if they show that you have been infected. Billy asks that you scan your whole system but if this isn't feasible then at least scan your /bin /usr/bin /tmp /var/tmp /sbin and /usr/sbin directories and send any infected files (in encrypted format) to rstb@sophos.com who will check whether they are infected hacking tools or just infected standard binaries.
0
•
•
•
•
I use Linux sometimes because its very flexible and easy to use and has open source, unlike IE.
http://www.1-satellite-tv-facts.com
http://www.1-satellite-tv-facts.com/Direct-TV.html
http://www.1-satellite-tv-facts.com/Dish-Network.html
http://www.1-satellite-tv-facts.com/...ite-Radio.html
http://www.1-satellite-tv-facts.com/...t-Service.html
http://www.1-satellite-tv-facts.com/Satellite-DSL.html
http://www.1-satellite-tv-facts.com/...-Internet.html
http://www.1-satellite-tv-facts.com/VoIP.html
http://www.1-satellite-tv-facts.com/Phone-Systems.html
http://www.1-satellite-tv-facts.com/...-Programs.html
http://www.1-satellite-tv-facts.com
http://www.1-satellite-tv-facts.com/Direct-TV.html
http://www.1-satellite-tv-facts.com/Dish-Network.html
http://www.1-satellite-tv-facts.com/...ite-Radio.html
http://www.1-satellite-tv-facts.com/...t-Service.html
http://www.1-satellite-tv-facts.com/Satellite-DSL.html
http://www.1-satellite-tv-facts.com/...-Internet.html
http://www.1-satellite-tv-facts.com/VoIP.html
http://www.1-satellite-tv-facts.com/Phone-Systems.html
http://www.1-satellite-tv-facts.com/...-Programs.html
Similar Threads
Other Threads in the Network Security Forum
- HTML/CSS to make round edge of boxes (HTML and CSS)
- How to tell your computer is a part of a botnet? (Windows NT / 2000 / XP)
- News Story: Return of the Mega-Botnet (Network Security)
- Seeing Linux boxes over VPN (Networking Hardware Configuration)
- Seeing Linux boxes over VPN (*nix Software)
Other Threads in the Network Security Forum
- Previous Thread: Scotland Yard foils Al-Qaeda plot to blow up Internet
- Next Thread: Debian releases fix for Linux kernel 2.6.8 vulnerabilities
| Thread Tools | Search this Thread |
Tag cloud for botnet, linux, news, security
2010 adobe advertising amazon android app apple attack blogging botnet browser business cellphone china cloud code community computer cpanel ddos debian design desktop distributions dns domains exploit facebook firefox fsf gadget game games gaming gnu google government hack hacking hardware hosting ibm india information internet internet-explorer ipad iphone itsjusthosting java jobs kindle linux litespeed mac malware managed microsoft mobile network networking news nokia os password phishing phone php piracy porn privacy programming protection report search security servers sex shared social-media social-networking software spam stallman storage survey symantec twitter ubuntu unix user video virtualization viruses vista vps vulnerability warning web windows




