Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Snort-Signatures
[Top] [All Lists]

[Snort-sigs] VRT Advisory - Confirmed Coverage for Lupper/Plupii Worm

Subject: [Snort-sigs] VRT Advisory - Confirmed Coverage for Lupper/Plupii Worm
Date: Tue, 08 Nov 2005 16:11:22 -0500
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

The Sourcefire Vulnerability Research Team (VRT) has learned of a worm
traversing the Internet that targets known vulnerabilities in certain
PHP and CGI scripts. The worm, known as Lupper or Plupii, makes
requests on port 80 for various scripts such as xmlrpc.php and
awstats.pl.

The Sourcefire VRT has confirmed that a rule identified as sid 3827,
released on July 22, 2005, will generate events when this worm tries
to exploit the vulnerability in the PHP XML-RPC module. The Sourcefire
VRT has also confirmed that a rule identified as sid 3813, released on
June 30, 2005, will generate events when the worm tries to use the
awstats vulnerability as an attack vector.

Details:

Analysis of the worm indicates that it attempts to exploit a weakness
in the PHP XML-RPC module by making a malicious POST request to the
xmlrpc.php script used by some PHP based applications. The worm may
also try to exploit a weakness in the awstats application that can
allow command execution on an affected host.

Successful exploitation results in the worm downloading a Trojan Horse
program named lupii, that opens either port 7111 or 7222 to establish
a UDP based control channel. The infected host then starts to perform
a scan to detect other potential victims at random IP addresses. Once
a host is identified, the worm then attempts to spread using the
attack vectors outlined above.

A detailed advisory is available at
http://www.snort.org/rules/advisories/vrt-rules-2005-11-08.html

- - Sourcefire VRT
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.0 (Darwin)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

iD8DBQFDcRR6Mpm0ve0NhMcRAo3CAJ987eZgsleVgZOIuhFUWaHvxYtNCgCfTEUF
cp+9jiQjtWbgxrinwu9ldE8=
=lHIa
-----END PGP SIGNATURE-----



-------------------------------------------------------
SF.Net email is sponsored by:
Tame your development challenges with Apache's Geronimo App Server. Download
it for free - -and be entered to win a 42" plasma tv or your very own
Sony(tm)PSP.  Click here to play: http://sourceforge.net/geronimo.php
_______________________________________________
Snort-sigs mailing list
Snort-sigs@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/snort-sigs

<Prev in Thread] Current Thread [Next in Thread>
  • [Snort-sigs] VRT Advisory - Confirmed Coverage for Lupper/Plupii Worm, Sourcefire VRT <=