nasty_virus
nasty_virus

Rare Linux virus on the loose

'RST.b' similar to Remote Shell Trojan found in October

Written by James Middleton

It has emerged in the last week that another of those rare Linux viruses may be on the loose. And this one has strong similarities to October's Remote Shell Trojan (RST) that was largely dismissed by the Linux community.

In a posting to a security mailing list at the end of December, SecurityFocus brought 'RST.b' to the internet community's attention.

The researchers warned that the culprit carrying the virus is likely to be "some exploit being passed around, possibly a Secure Shell one". Linux users are advised not to run exploits from unknown sources.

Once it has gained a foothold into the system, it installs a back door and attempts to escalate its permissions to root privileges.

The basic differences to the October version are that the new virus tries to communicate with a machine on a different IP address to the original RST, and the backdoor operates on the Exterior Gateway Protocol instead of the User Datagram Protocol.

Like the original RST, the virus infects binary files in the Linux Executable and Linking Format (ELF).

RST.b infects the start address in ELF headers with an address that points to its own code. So when an infected program is run, a parent string forks off to run the original code so as to avoid suspicion, while a child string "takes care of the evil stuff", according to researchers at Lockeddown.net.

"Not only do we have a virus spreading, but it is opening up the infected boxes to attackers," they added.

A SecurityFocus researcher who attempted to contact the host of the web server that had infected the machines said: "The response I got indicated that 'his account was terminated a few weeks ago'. I received no response to a later request for clarification."

Tags:

Further reading

Complex Linux virus warning

'Zeitgeist of new interest', says expert   More...

Experts warn of Linux/Windows virus

Polymorphic, entry-point-obfuscating worm hits the web   More...

Jac virus targets Linux

First to hit the platform in three months   More...

Desktop Linux still remote

Operating system is still no threat to Microsoft.   More...

Related articles

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

25 Jul 2008

7.85 MBPodcast Special: Views from the Valley More...

24 Jul 2008

3.68 MBSpammer jailed, Esquire e-cover, and network passwords More...

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Credit card transaction

Credit card fraud rampant in the UK

Attempted frauds go unreported and ignored, analysts claim   More...

Intel

Intel rolls out new embedded line-up

System-on-a-chip offerings promise footprint and power saving   More...

Advertisement

Network cables

Tech giants collaborate on wireless HD

Another attempt at cable-free transmission in the home   More...

iPhone fever fills AT&T coffers

US provider cashes in on Apple smartphone   More...

Advertisement