FW: Apache worm in the wild

From: suniljamesat_private
Date: Fri Jun 28 2002 - 10:21:35 PDT

  • Next message: Maxime Ducharme: "Re: Someone looking for CodeRed infected boxes ?"

    
     ('binary' encoding is not supported, stored as-is)
    In-Reply-To: <Pine.LNX.4.44.0206281205360.28076-100000at_private>
    
    Has anyone seen anything in relation to this?
    
    Thanks,
    
    Sunil
    
    
    -------Original Message-----
    From: Domas Mituzas [mailto:domas.mituzasat_private]
    Sent: Friday, June 28, 2002 7:02 AM
    To: freebsd-securityat_private
    Cc: bugtraqat_private; os_bsdat_private
    Subject: Apache worm in the wild
    
    
    Hi,
    
    our honeypot systems trapped new apache worm(+trojan) in the wild. It
    traverses through the net, and installs itself on all vulnerable apaches
    it finds. No source code available yet, but I put the binaries into public
    place, and more investigation is to be done.
    
    http://dammit.lt/apache-worm/
    
    Regards,
    Domas Mituzas
    
    Central systems @ MicroLink Data
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Fri Jun 28 2002 - 11:09:26 PDT