This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Linux.Plupii.C worm - elevated levels of activity

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.sarc.com/
"The ThreatCon is at Level 2… The DeepSight Threat Analyst Team continues to observe slightly elevated levels of activity from Linux.Plupii.C, a worm propagating through exploitation of several previously disclosed vulnerabilities, including an XML-RPC for PHP Remote Code Injection Vulnerability (BID 14088)…"
- http://www.securityfocus.com/bid/14088
XML-RPC for PHP Remote Code Injection Vuln
- http://www.securityfocus.com/bid/14088/solution

>>> http://securityresponse.symantec.com/avcen…x.plupii.c.html
Last Updated on: February 19, 2006
"Linux.Plupii.C is a worm with back door capabilities that spreads by exploiting vulnerabilities…"

:ph34r:
FYI…

Mare.D
- http://www.f-secure.com/v-descs/mare_d.shtml
Alias: Net-Worm.Linux.Mare.d, Linux.Plupii.C, Unix/ShellBot.C
Category: Worm…
Propagation
Mare.D scans random hosts for vulnerable installations of the Mambo content management system and PHP XML-RPC. Exploiting these vulnerabilities the worm downloads a small shell script that installs the rest of the components:
· /tmp/.temp/cb - Connectback shell backdoor
· /tmp/.temp/https - IRC-controlled backdoor
· /tmp/.temp/ping.txt - Connectback shell backdoor
· /tmp/.temp/httpd - Main worm component …"

:ph34r: