ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Worm exploits Solaris hole

Joris Evers CNET News.com

Published: 01 Mar 2007 09:06 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A computer worm is using a recently disclosed flaw in Sun' operating system to propagate, experts have warned.

The worm attempts to log into systems running Solaris 10, execute a number of commands to plant itself and then spread to other vulnerable computers, Jose Nazario, a senior software engineer at Arbor Networks, wrote on his company's blog on Tuesday. Arbor sells network analysis products.

Sun confirmed the threat on Wednesday in an updated alert on its website. "There is at least one worm in existence that is making use of this exploit to compromise system integrity," Sun warned.

The company has offered a worm-cleaning tool for affected customers.

The worm takes advantage of a security hole in the Solaris telnet service that was first disclosed earlier this month. The bug could enable attackers to gain unauthorised access to a system without requiring any action on the part of the user. Sun has released a fix for the flaw and urges users to install it.

The SANS Internet Storm Center, which monitors internet threats, has noticed some increase in activity on the network port used by Solaris' telnet feature, according to an ISC blog posted Tuesday.

"One hopes that there aren't that many publicly reachable Solaris systems running telnet," ISC staffer Joel Esler wrote.

Telnet was one of the first methods devised to allow system administrators to remotely monitor their networks. The service will usually prompt people for their username and password. However, the Solaris bug could allow an attacker to add additional parameters and connect without a username or password.

Systems with telnet disabled are not vulnerable to this attack.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
8 out of 8 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

SOLARIS / AIX Administrator - Manchester

My Manchester City Centre client is looking for a SOLARIS / AIX specialist to assist their experienced team on a contractual basis. You will be ...

Unix Specialists Required Solaris, 24x7, Surrey, 35k

Unix Specialists Required Solaris, 24x7, Surrey, 35k My global client is currently recruiting for several Unix Specialists to join the team in ...

Solaris 8,9,10 System Administrator, Unix, Urgently Required- Dorset

a Solaris Unix Systems Administrator for their well established client in the South Coast area. If you are experienced in a Netapp environment, and ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation