Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Focus-Virus
[Top] [All Lists]

Outpost24 Public Security Note: Linux/Elxbot

Subject: Outpost24 Public Security Note: Linux/Elxbot
Date: Mon, 05 Dec 2005 21:20:58 +0100

_______ __ __ ______ _____ | |.--.--.| |_ .-----..-----..-----.| |_ |__ || | | | - || | || _|| _ || _ ||__ --|| _|| __||__ | |_______||_____||____|| __||_____||_____||____||______| |__| Public Security Note |__| http://www.outpost24.com




[BACKGROUND] Mambo is a dynamic portal engine and content management system. The software is written in PHP. A computer researcher which goes under the alias rgod released an exploit for the "register_globals" Emulation Layer Overwrite vulnerability and just a few days after the vulnerability was released increased attacks for this vulnerability was monitored, the increased traffic is due to a worm which is currently in the wild.



[DESCRIPTION]
Linux/Elxbot is a backdoor for the Mambo vulnerability. It will search
on Google for vulnerable targets. Once it infects a computer it will
connect to a predetermined IRC server where the attackers will wait and
have the possibility to gain access to the infected computer. The attackers
may also perform various tasks such as:

* Execute arbitrary commands
* TCP flood
* HTTP flood
* UDP flood
* Search Google for more vulnerable targets
* Portscan

On certain systems it will also download a perl script which will
allow the attacker to create a backchannel and spawn a shell on
the infected computer with the same privileges as the running webserver.


A detailed profile is available for Outpost24 members, for more information please visit our webpage at http://www.outpost24.com



[SOLUTION]
Download the latest version from the official Mambo homepage or
download the specific patch for this vulnerability.

http://mamboforge.net/frs/download.php/7636/Mambo4523.security_fix.zip



[AUTHOR]
Backdoor was analyzed by David Jacoby at Outpost24 Security
http://www.outpost24.com


<Prev in Thread] Current Thread [Next in Thread>
  • Outpost24 Public Security Note: Linux/Elxbot, David Jacoby <=