Advertisement
Promo

Online business Toolkit

Linux world dismisses new Trojan risk

Wendy McAuliffe ZDNet.co.uk

Published: 04 Jan 2002 17:51 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A Remote Shell Trojan (RST) is making its way around the Linux community, but security experts say it should not pose a risk if users are vigilant with the programs they run.

The Trojan is a more complex variant of an earlier RST that hit Linux systems last October. In order to propagate, RST.b requires a user to run an infected binary, which then opens up a remote shell and allows an attacker to access the machine.

Linux distributor Red Hat is categorising RST.b as a low risk. The variant requires a root user to download the malformed binary in order for the Trojan to run, which is less likely to happen on Linux machines as it products are designed to keep partitions on what users can do.

"On Linux a lot of packages are digitally signed and come with their own source code, which makes it a lot harder for a trojan to attach itself, and ensures that the product is not affected during transit," said Mark Cox, senior director of engineering at Red Hat.

The virus replaces the start address in the Executable and Linking Format headers with an address that points to its code. When an infected program is run it is re-directed to the virus code. According to researchers at lockeddown.net, a parent string forks off to the real start address and runs the normal code while a child string "takes care of the evil stuff".

Trojan horses designed to attack Linux systems are rare. Viruses that exploit vulnerabilities in Microsoft Windows are fairly common, but according to Red Hat, the popular Apache Web server has not had any vulnerabilities that would allow remote access for two years. "The risk factor is a lot lower than IIS (Internet Information Server) for example," said Cox.

For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum.

Let the editors know what you think in the Mailroom. And read other letters.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
18 out of 65 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:








Sentry Posts Blog

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Beware of keeping your head in the clo...

Information security professionals can look forward to a deepening appreciation for their skills as security continues to be recognised as an essential element for doing business in... More

1 comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment

Video icon

Video

Google Chrome

Roundup: Full coverage of Google Chrome

The search giant has launched a beta of its own open-source browser, sending a clear challenge to Microsoft in the way it lets users work with applications More

Blog: Google Chrome has Microsoft's code inside, says MS manager

And furthermore, he says, that's a good thing... More

Blog: Google Chrome — nine things we've found since launch

Google must be very happy with the coverage Chrome has gathered. But it's not all good news... More


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters