Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Snort-sigs] VRT Advisory - Confirmed Coverage for Lupper/Plupii Worm |
|---|---|
| Date: | Tue, 08 Nov 2005 16:11:22 -0500 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1
The Sourcefire Vulnerability Research Team (VRT) has learned of a worm traversing the Internet that targets known vulnerabilities in certain PHP and CGI scripts. The worm, known as Lupper or Plupii, makes requests on port 80 for various scripts such as xmlrpc.php and awstats.pl.
The Sourcefire VRT has confirmed that a rule identified as sid 3827, released on July 22, 2005, will generate events when this worm tries to exploit the vulnerability in the PHP XML-RPC module. The Sourcefire VRT has also confirmed that a rule identified as sid 3813, released on June 30, 2005, will generate events when the worm tries to use the awstats vulnerability as an attack vector.
Details:
Analysis of the worm indicates that it attempts to exploit a weakness in the PHP XML-RPC module by making a malicious POST request to the xmlrpc.php script used by some PHP based applications. The worm may also try to exploit a weakness in the awstats application that can allow command execution on an affected host.
Successful exploitation results in the worm downloading a Trojan Horse program named lupii, that opens either port 7111 or 7222 to establish a UDP based control channel. The infected host then starts to perform a scan to detect other potential victims at random IP addresses. Once a host is identified, the worm then attempts to spread using the attack vectors outlined above.
A detailed advisory is available at http://www.snort.org/rules/advisories/vrt-rules-2005-11-08.html
- - Sourcefire VRT -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.0 (Darwin) Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org
iD8DBQFDcRR6Mpm0ve0NhMcRAo3CAJ987eZgsleVgZOIuhFUWaHvxYtNCgCfTEUF cp+9jiQjtWbgxrinwu9ldE8= =lHIa -----END PGP SIGNATURE-----
------------------------------------------------------- SF.Net email is sponsored by: Tame your development challenges with Apache's Geronimo App Server. Download it for free - -and be entered to win a 42" plasma tv or your very own Sony(tm)PSP. Click here to play: http://sourceforge.net/geronimo.php _______________________________________________ Snort-sigs mailing list Snort-sigs@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-sigs
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Snort-sigs] new rule for detect JBoss JMXInvokerServlet access, rmkml |
|---|---|
| Next by Date: | [Snort-sigs] Bleedingsnort.com Daily Update, bleeding |
| Previous by Thread: | [Snort-sigs] new rule for detect JBoss JMXInvokerServlet access, rmkml |
| Next by Thread: | [Snort-sigs] new rule for detect apache (1.3/2.0) dir browsing|list, rmkml |
| Indexes: | [Date] [Thread] [Top] [All Lists] |