Forum     

Go Back   Digit Technology Discussion Forum > News > Technology News
Register FAQ Calendar Mark Forums Read

Technology News News from the world of technology that our members stumble across. NOTE: Sources to be mentioned at the beginning of each post.


Reply
 
LinkBack Thread Tools Display Modes
Old 14-06-2010, 09:39 AM   #1 (permalink)
Linoob
 
celldweller1591's Avatar
 
Join Date: Mar 2010
Location: ambala, haryana
Posts: 705
Default Linux Trojan


Linux Trojan was Unnoticed for a year
It seems the Linux version of the popular IRC server Unreal IRCd was contaminated with malware ever since November 2009, without anyone noticing it. The announcement was made on the Unreal IRCd forums:

Quote:
This is very embarrassing...We found out that the Unreal3.2.8.1.tar.gz file on our mirrors has been replaced quite a while ago with a version with a backdoor (trojan) in it. This backdoor allows a person to execute ANY command with the privileges of he user running the ircd. The backdoor can be executed regardless of any user restrictions (so even if you have passworded server or hub that doesn't allow any users in). [...] It appears the replacement of the .tar.gz occurred in November 2009 (at least on some mirrors). It seems nobody noticed it until now.
This reminds us that an OS is as secure as the owner makes it. Remember to always check the source code before running a script / application. Better yet, only install applications from your distribution's official repositories and very trusted sources.

Source
__________________
root@Celldweller#ping www.linoob.com

Ubuntu User # 31222
Linux User # 516252
celldweller1591 is offline   Reply With Quote
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 18-06-2010, 07:14 PM   #2 (permalink)
Right Off the Assembly Line
 
Join Date: Jul 2009
Posts: 14
Default Re: Linux Trojan

too bad
manu somasekhar is offline   Reply With Quote
Old 18-06-2010, 08:04 PM   #3 (permalink)
Linoob
 
celldweller1591's Avatar
 
Join Date: Mar 2010
Location: ambala, haryana
Posts: 705
Default Re: Linux Trojan

Quote:
too bad
It was just a small issue. As the IRC guys already said " This is very embarassing" . No big deal. Linux is still as secure as it were before this an yes the Security of a home/desktop computer or a Network server largely depend upon its user/pro !
__________________
root@Celldweller#ping www.linoob.com

Ubuntu User # 31222
Linux User # 516252
celldweller1591 is offline   Reply With Quote
Old 18-06-2010, 09:37 PM   #4 (permalink)
Wise Old Owl
 
The Unknown's Avatar
 
Join Date: Nov 2006
Location: Pune, Maharashtra, India
Posts: 1,728
Default Re: Linux Trojan

The hacker cannot damage the Linux server unless and until there is a foolish server administrator who has setup the IRC daemon to run as root or has given sudo permissions to the IRC daemon user.
Even better, there are many ways to put the thing in chroot, so it will be impossible to damage the OS core.
Also, the trojan was right in the source, so the server gets infected, otherwise, it cannot; the permission system is very secure, and if the administrator has enabled SELinux and configured it properly, even if a trojan enters, it cannot do anything with the OS files.
__________________
KDE on ArchLinux
PHP, MySQL, PostgreSQL, Linux, Apache; Message me to hire (freelancing only)
Explore Technology @ http://www.itech7.com
Cheap and Reliable VPS Hosting @ http://j.mp/arHk5e
The Unknown is offline   Reply With Quote
Old 18-06-2010, 09:44 PM   #5 (permalink)
Linoob
 
celldweller1591's Avatar
 
Join Date: Mar 2010
Location: ambala, haryana
Posts: 705
Default Re: Linux Trojan

Quote:
there are many ways to put the thing in chroot, so it will be impossible to damage the OS core.
True ! SElinux is good at security if somebody knows howto handle it properly.
__________________
root@Celldweller#ping www.linoob.com

Ubuntu User # 31222
Linux User # 516252
celldweller1591 is offline   Reply With Quote
Old 18-06-2010, 09:50 PM   #6 (permalink)
Section Moderator
 
gopi_vbboy's Avatar
 
Join Date: Mar 2007
Location: Hyderabad
Posts: 1,187
Default Re: Linux Trojan

whats the big deal?
gopi_vbboy is online now   Reply With Quote
Old 26-06-2010, 11:09 AM   #7 (permalink)
Wise Old Owl
 
The Unknown's Avatar
 
Join Date: Nov 2006
Location: Pune, Maharashtra, India
Posts: 1,728
Default Re: Linux Trojan

^^ These are obvious cases. You need to be always aware what you install and scrutinize the scripts that it runs.

If I configure the SSH server on my system to allow all logins alongwith and empty passwords and the root account has no password then it is an obvious case !

Think about something indirect ! Like some virus invades in and then creates a security hole which usually happens in windows - something impossible in Linux, unless the admin is a dumbo who has improperly configured the server.

That's why Linux server administrators are paid heavily- the job is such.

We have GPG keys and MD5/SHA1 sums for the files downloaded to ensure that the source code isn't tampered.
__________________
KDE on ArchLinux
PHP, MySQL, PostgreSQL, Linux, Apache; Message me to hire (freelancing only)
Explore Technology @ http://www.itech7.com
Cheap and Reliable VPS Hosting @ http://j.mp/arHk5e
The Unknown is offline   Reply With Quote
Old 09-07-2010, 03:00 AM   #8 (permalink)
Right Off the Assembly Line
 
Join Date: Jan 2010
Posts: 40
Default Re: Linux Trojan

well but then it isn't feasible to check the code of each and every stuff, especially when it is Reputed...
techmaniack is offline   Reply With Quote
Old 16-07-2010, 03:53 AM   #9 (permalink)
duh
Right Off the Assembly Line
 
Join Date: Jul 2010
Posts: 41
Default Re: Linux Trojan

i used all ircd's except unreal, well, once i was proven right, else i been proven wrong again and again.
second, ircd, can be run as an ordinary user or inside chroot, so i dont think it can do serious damage if run as ordinary user or chroot.
and thirdly? we got selinux, grsecurity, apparmor, execshield, and rkhunter and chkrootkit and lsat and checksecurity and et al, iptables and snort, so you mean to say this rootkit was a wild one for so long w/o anyone knowing?
wierd.
i will go for freenode's dancer, or efnet's ratbox, or undernet's ircu, or ircnet's ircd, or even dal.net's bahamut, but never unreal, never liked it from start, kinda pissed me off.
duh is offline   Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Ark Linux & Ark Linux Live 2007.1 Released Dark Star Open Source 1 20-08-2007 06:32 PM
Linux Foundation charts Linux's future praka123 Technology News 4 24-06-2007 09:21 AM
Open Office crashes aditya.shevade Open Source 16 25-04-2007 01:26 AM
Linux is NOT Windows-must read praka123 Open Source 21 27-07-2006 02:10 AM
Managing Multiple Linux Operating Systems paragkalra Open Source 1 06-01-2006 09:41 PM

 
Latest Threads
- by Sarath
- by Charan
- by gforz
- by abhidev

Advertisement




All times are GMT +5.5. The time now is 12:21 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2