-----Original Message-----
From: uniras [mailto:[EMAIL PROTECTED]]
Sent: 29 June 2002 15:24
To: Undisclosed Recipients
Subject: UNIRAS Alert - 19/02 -Apache Worm on the loose
Importance: High


----------------------------------------------------------------------------
------
   UNIRAS (UK Govt CERT) Alert Notice -19/02 dated 29.06.02  Time: 14:55
 UNIRAS is part of NISCC (National Infrastructure Security Co-ordination
Centre)
----------------------------------------------------------------------------
------
  UNIRAS material is also available from its website at www.uniras.gov.uk
and
         Information about NISCC is available from www.niscc.gov.uk
----------------------------------------------------------------------------
------

Title
=====

Apache worm on the loose that exploits the chunked encoding vulnerability

Naming:
=======

Virus name: Linux/Ehcapa
Alias:      Linux/Ehcapa.worm,  FreeBSD.Scalper.Worm, ELF_SCALPER.A,

Summary:
========
Discovered: 2002-06-28 9:45 PM, GMT
Trigger:    Upon execution

Affected systems:
----------------------------------------------
Servers,UNIX,Linux
Internet/ IntranetServers,UNIX,Apache
----------------------------------------------

Payload
----------------------------------------------
Performs TCP, UDP, DNS, and E-mail flooding
Sends the IP address to certain email address
Can allow malicious code to run on the webserver
Allows unauthorized access to the infected machine
----------------------------------------------

Detail:
========

Scalper affects systems running FreeBSD running the vulnerable version of
Apache web server.
If the worm gains access to the server, it creates a temporary file
"/tmp/.uua", which is an
uuencoded worm. This file is decoded to "/tmp/.a" and executed. The
uuencoded file is removed.
At this point the worm sets up a backdoor to UDP port 2001 and starts
scanning predefined set
of Class-A networks. If the worm finds a web server, it checks if the server
is running Apache,
and if so, it will attempt to infect it. While the exploit code that Scalper
uses will only
infect systems running FreeBSD, these attempts will be visible in Apache
servers running on
other platforms as well.

The backdoor component of the worm allows a remote control of the worm,
sending of email,
uploading of files and executing of arbitary programs. The execution of
programs happens with
the same user privilege as the Apache server. The backdoor can also perform
different kind of
denial of service attacks against arbitary hosts.
The worm does not modify the system configuration, and it is visible in the
system process list
as a process ".a".

Scalper can be removed from the system by deleting file "/tmp/.a" and
terminating the worm
process with command "killall -9 .a".
The vulnerability used by the worm is fixed in Apache server versions 1.3.26
and 2.0.39.
Further information is available from:
Apache Software Foundation:
http://httpd.apache.org/info/security_bulletin_20020620.txt
CERT: http://www.cert.org/advisories/CA-2002-17.html
UNIRAS briefing number 190/02

Information taken from discussion groups on the Internet suggests:

The exploit is based on Gobbles,  his signature is in
the shell code (the string is split into parts). And it's limited to IA32
(Intel 32 bit architecture).
The worm has some ddos tools included UDP port 2001 as
used for encrypted communication - for both tcp/udp flooding
as well as e-mail flooding.

The worm source code has been published on the Internet, so expect
variants!!

For systems using Anti Virus, patches are available. However the best course
of action is
to upgrade immediately and not rely on AV. UNIRAS has learnt over the years
that most
LINUX and UNIX systems do not use Antivirus products.
----------------------------------------------------------------------------
------

For additional information or assistance, please contact the HELP Desk by
telephone or Not Protectively Marked information may be sent via Email to:

[EMAIL PROTECTED]
Tel: 020 7821 1330 Ext 4511
Fax: 020 7821 1686

----------------------------------------------------------------------------
------
UNIRAS wishes to acknowledge the contributions of Outpost 24, F-Secure,
Internet Discussion groups for the information contained in this Alert.
----------------------------------------------------------------------------
-----

Reference to any specific commercial product, process, or service by trade
name, trademark manufacturer, or otherwise, does not constitute or imply
its endorsement, recommendation, or favouring by UNIRAS or NISCC.  The views
and opinions of authors expressed within this notice shall not be used for
advertising or product endorsement purposes.

Neither UNIRAS or NISCC shall also accept responsibility for any errors
or omissions contained within this briefing notice. In particular, they
shall
not be liable for any loss or damage whatsoever, arising from or in
connection
with the usage of information contained within this notice.

UNIRAS is a member of the Forum of Incident Response and Security Teams
(FIRST)
and has contacts with other international Incident Response Teams (IRTs) in
order to foster cooperation and coordination in incident prevention, to
prompt
rapid reaction to incidents, and to promote information sharing amongst its
members and the community at large.
----------------------------------------------------------------------------
------
<End of UNIRAS Briefing>




IWS INFOCON Mailing List
@ IWS - The Information Warfare Site
http://www.iwar.org.uk


Reply via email to