LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-28-2001, 09:24 PM   #1
shierly
LQ Newbie
 
Registered: Feb 2001
Posts: 10

Rep: Reputation: 0
Question


hello, everyone.
one of the severs in my lab was infected by a virus named ramen . as a result , our homepage was revised , and yet there is nothing else deviant. all of these took place a few weeks ago.unfortunately, we didn't setup any anti-virus software on it before that.
i'd like to find the virus immediately.
i have tried the find order & there is no result.
does anyone have such experience or any advice?
thx in advacne!
 
Old 02-28-2001, 10:34 PM   #2
jeremy
root
 
Registered: Jun 2000
Distribution: Debian, Red Hat, Slackware, Fedora, Ubuntu
Posts: 13,600

Rep: Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083
Here is some info about the worm:

Quote:
This is an internet worm for Linux. It attempts to use three remote exploits to gain access to computers running Red Hat 6.2 and 7.0. Once it has access on the computer it downloads a copy of itself to /tmp/ramen.tgz and extracts itself to the /usr/src/.poop directory. It appends a line to /etc/rc.d/rc.sysinit so it is executed on startup.

Once executed the worm remains running until the machine is switched off. While the worm is active it will choose a class B internet network at random and probe all addresses in the range looking for machines to infect.

The worm may delete /usr/sbin/lpd or /sbin/rpc.statd or /usr/sbin/rpc.statd to close the exploit it used to gain access to the system.

In order to propagate copies of itself it installs a service named asp, either by appending a line to /etc/inetd.conf or by overwriting the file /etc/xinetd.conf. The worm replaces all index.html files on the computer with an HTML file containing the text

'Hackers looooooooooooooooove noodles.'
 
Old 03-16-2001, 12:28 AM   #3
bretthoward
Member
 
Registered: Mar 2001
Location: Klamath Falls
Posts: 62

Rep: Reputation: 15
First virus I've ever heard of that actually increases security before breaking things!
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
linux find to find files with multiple patterns subu_s Programming 6 12-15-2010 12:15 AM
Can`t find C-compiler in Debian ,or at least can`t find one that can make executables hemmelig Linux - Software 4 05-26-2008 03:07 AM
Kaspersky Anti-Virus for Linux File Server: Can't find license manager azmadar Linux - Security 1 12-02-2004 08:29 AM
Boot virus or Anti-Virus? AVG Free Anti-Virus Software problems SparceMatrix Linux - Security 9 08-02-2004 02:35 PM
trend chipway virus detected boot virus rafc Linux - Security 1 05-13-2004 01:44 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:15 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration