ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Slapper worm continues to put it about

Published: 17 Sep 2002 12:39 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The Linux Slapper worm had compromised more than 6,700 servers as of early Monday morning, and it continues to create a peer-to-peer attack network that could shut down even corporate Internet connections.

Unlike past worms, which typically tried only to compromise computers on the Internet, the Slapper worm has a grander scheme in mind: to create a large peer-to-peer network that could be used to hit other servers. A computer that gets infected becomes part of the network and could be commanded, or used to command the other computers on the network, to attack, said Al Huger, senior director of engineering for the incident response team at security company Symantec.

"A number like 6,700 hosts is very significant for a (distributed denial-of-service) network," he said. "With the pipes these (infected servers) are connected to, this network could easily take a large enterprise off the Internet."

The worm, known as Linux.Slapper.Worm and Apache/mod_ssl Worm by the security industry, takes advantage of a hole in OpenSSL, a program used by many Web sites based on open-source software to secure Web communications. Specifically, the worm uses a security flaw in the mod_ssl module for the Apache Web server. While Apache accounts for about two-thirds of all Web sites on the Internet, it's unknown how many of those sites use SSL.

As previously reported, the worm is spreading moderately quickly. Symantec reported 2,000 infected servers early Friday afternoon. That jumped to 3,500 by Friday evening, and 6,700 as of 2 a.m PT Monday.

Once infected, a computer drawn into the Slapper network can be ordered -- by commands passed from machine to machine -- to attack a target in one of four different ways: send out a deluge of data, force the target to execute a command, redirect certain requests to another computer, or send back e-mail addresses or information about known infected servers.

"This shows a leap in worm-writing technology," Huger said. "(The network it sets up) can be efficient as well. It's passing router information back and forth, which could be used very intelligently."

The peer-to-peer network has already attacked. On Saturday, incident-tracking Web site Incidents.org said the network had been used to attack another company. A note from a system administrator to the customers of RackShack.net confirmed that more than 20 of their computers had been used in such an attack.

On Monday, Huger confirmed that another security company had been attacked by the network this past weekend.

However, there's a silver lining in this particular network cloud. Security companies and authorities can place a vulnerable computer on the Internet that will eventually be infected, giving the organization a view into what's happening on the network.

Such a tactic gave Huger and his team the ability to collect the IP addresses of much of the network, since every computer eventually advertises itself to its peers. Symantec has forwarded on the information to the FBI's National Infrastructure Protection Center for analysis.

An earlier attempt to contact the owners of the infected systems had little result, Huger said. "We notified the owners of 1,800 computers on the network last week. We received only 4 replies."

Huger warned that his team isn't yet seeing the full extent of the network, however.

The computer that the security team is using to tap into the Slapper network didn't see any sign of this weekend's attack against an unnamed security company. This means that another part of the Slapper network -- which isn't included in the 6,700 servers that Huger's team can "see" -- did the assault.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
18 out of 53 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Linux Administrator Redhat, Suse, Debian,Apache, West of London 38k

Linux Administrator Redhat, Suse, Debian, Apache, 38k Linux Systems Administrator (Debian/Ubuntu/MYSQL/Apache/UNIX) is needed by my leading ...

Perl Developer-Perl, JavaScript, MySQL, SOAP, Apache, Perl Developer

Solaris Windows Server 2003 Zeus ZWS/ZXTM or Apache MS Exchange 2007 Cisco firewalls and switches DNS DHCP UNIX email (preferably qmail) Oracle 10g ...

Web Software Developer ( Graduate ) PHP, MySQL, Apache, UNIX

Graduate Opportunity with Mediahawk Job Title: Web Software Developer ( Graduate ) PHP, MySQL, Apache, UNIX Location: near Olney - Milton Keynes / ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment