Advertisement
Promo

Industry watch Toolkit

Hackers drop spyware into popular tool

Published: 15 Nov 2002 08:40 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The main Web site for downloading a popular open-source network-monitoring tool remained off-line on Thursday following a revelation that rogue hackers had implanted spyware in the latest version of the software.

Copies of tcpdump, a utility for monitoring data traffic on a network, and its library of code, called libpcap, had both been corrupted on the site, said Michael Richardson, Webmaster for the site and a member of the open-source project that maintains the tools.

"The server has been taken down until we can be sure we have found the problem," Richardson said in a phone interview Thursday.

However, other sites had already downloaded the software from the main server and hosted the files on their own computers, a practice known as mirroring. It's unknown how many of these other sites have corrupted copies of the code, Richardson said, although some have already confirmed that they have found the Trojan horse.

Tcpdump is a utility used by Unix, Linux and BSD system administrators to monitor -- or "sniff" -- the data that passes over the network. Libpcap is a code library that helps programmers write programs to tap into network data on many different platforms.

The spyware component of the tainted software -- called "conftes.c" -- enables the hackers to send and execute any command on computers that contain the modified utility.

The attack bears some hallmarks of a group of hackers that struck two other open-source projects, Sendmail and OpenSSH, in October. Specifically, the Trojan horse has commands that can be triggered by using the letters a, d and m -- the name of a major underground hacking group. Whether the actual hackers were members of ADM, were framing the group, or were just using the group's tools is unknown.

The hackers apparently broke into the server during the weekend from a computer in Finland and replaced the code with a corrupted version. The infected software remained available for more than two days because, Richardson said, he had been away from the main server, located in Canada, and the people who found the problem -- members of the Houston Linux Users Group -- didn't notify him.

"It would have been nice to have a little bit more warning," Richardson said. "No one contacted me from that group."

Matt Solnik, president of the Houston Linux Users Group, said the group contacted one of the other members of the tcpdump project less than an hour after realising the software had been compromised. Another HLUG member, Russell Adams, had been installing Snort, an open-source intrusion detection system that uses the libpcap library, when a test that matches the software package with a unique fingerprint failed. The fingerprints, known more formally as digital signatures, are used as a security measure to make sure the software can't be surreptitiously changed.

"He found some interesting code and we looked over it and found that it was a Trojan," Solnik said.

By Tuesday night, HLUG had extracted the Trojan horse and had started notifying tcpdump's maintainers, said Solnik.

Richardson expects to start analysing the server Thursday. He couldn't say when the project's server would again be available. More information is available in an advisory released by Carnegie Mellon University's Computer Emergency Response Team (CERT) Coordination Center.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
36 out of 54 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:









Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010

Discussions

ator1940 ator1940

Microsoft Loses Patent Case Appeal

Friday 25 December 2009, 9:35 PM

6 comments
J.A. Watson J.A. Watson

Google it

Friday 25 December 2009, 1:40 PM

3 comments
J.A. Watson J.A. Watson

Google it

Friday 25 December 2009, 1:38 PM

3 comments
Shibley R Shibley R

Question!

Friday 25 December 2009, 11:09 AM

3 comments
Video icon

Video


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters