Skip to main content

Linux worm turns on Mambo and PHP

posted onFebruary 20, 2006
by hitbsecnews

Security experts today warned of a Linux network worm that exploits holes in the Mambo content management system and the PHP XML-RPC library.

Dubbed Mare.D, the worm leaves multiple backdoors on infected systems. Two of these are connectback shell backdoors that link to a remote host, while a third allows the malware's writer to access and control infected systems via IRC.

"The main component of the Mare.D worm is written in C and compiled with the GNU C compiler," said F-Secure researcher Gergely Erdelyi. The worm scans for vulnerable systems automatically and installs a small shell script which downloads the rest of the malware.

Source

Tags

Viruses & Malware

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th