ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

New Unix worm could be the next Code Red

Wendy McAuliffe ZDNet.co.uk

Published: 10 Sep 2001 16:58 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A new Internet worm designed to attack a common flaw in Unix systems has been confirmed dead, but security experts are warning that the self-propagating worm could be the next Code Red.

The X.C worm exploits a newly discovered hole in the telnet service that is run on most Unix systems. Antivirus companies are concerned that crackers will have learnt from the success of the Code Red worm and its variants, and will be encouraged by the length of time that it takes system administrators to patch machines against publicised vulnerabilities.

"This is going to go along the same lines as Code Red, as virus writers will know that a lot of machines will be vulnerable," said Mark Read, systems security analyst for computer security company MIS Corporate Defence Solutions. "This is definitely the way forward with viruses, as it removes the need for humans to double click on attachments in order for the worm to spread, and instead looks for servers that have not been patched."

The FBI's National Infrastructure Protection Centre (NIPC) issued an alert on the X.C worm on 30 August, and analysts at SecurityFocus have now confirmed that the spread of the virus has been contained due to the program's dependency on a file located on a Web server in Poland. But infected systems will still be able to break into other vulnerable hosts, and might have succeeded in installing "back doors" on previously attacked systems.

The X.C worm can affect Solaris, SGI IRIX and Open BSD. It targets a buffer overflow exploit in the Telnetd system, and attempts to fetch a copy from the program's source code named "x.c." from the Polish server and replicate it on the victim host.

"Telnetd is very insecure when you are connecting to a Unix box from a remote station, as everything is sent across the network. If someone is using a packet sniffer, it is easy to find out a person's username and password," said Read.

X.C never posed a serious threat, as it only targeted a limited number of Unix systems. "This could have been a test version, or was programmed incorrectly," said Read. But security firms are warning that the next version is likely to be as virulent as Code Red, attacking more popular operating systems such as RedHat 7.0 that include Telnetd in the default.

See the Viruses and Hacking News Section for the latest headlines.

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum.

Let the editors know what you think in the Mailroom. And

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
59 out of 87 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:










Related Jobs

UNIX/NETWORK SYSTEMS ADMINISTRATOR

UNIX/NETWORK SYSTEMS ADMINISTRATOR NET-A-PORTER is an established global Internet retailer of cutting edge luxury fashion labels, relied upon for its ...

Unix SA/Engineer (Solaris,Linux, LVM, Veritas) BANKING

Highly Successful Top Tier Investment Bank is hiring a high Level Unix SA to join a team of 6 in Unix production support. You will be responsible for ...

Unix / Linux Redhat Systems Administrator- Market Leaders- London

Unix / Linux Redhat Systems Administrator Scripting, Oracle, MySql, DNS, DHCP, Apache, My client is a FSTE 100 blue chip organisation looking for ...

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains