Skip to content

Biting the hand that feeds IT

The Register ®


Related Whitepapers

[Print][Mobile][Alerts]

Solaris/IIS worm hits 9000 boxes in 48 hours

Off to a good start

Published Friday 11th May 2001 10:55 GMT

The quite reliable hacker tracker attrition.org is reporting that nearly nine thousand machines had been auto-defaced by the sadmind/IIS worm as of Tuesday, making it one of the most effective little scripts ever loosed on the Net.

Attrition has posted the IPs of all the boxes known to have been hit, and mirrored the default defacement to boot.

The worm infects Solaris boxes up to version 7, and then scans for IIS machines susceptible to the folder traversal vulnerability and executes mean-spirited code on them, replacing their default Web pages with naughty words.

What's ironic here is that the worm exploits two separate holes which were reported and patched ages ago. Call it proof-of-concept that sysadmins spend an awful lot of time on activities other than absorbing security bulletins.

The worm's payload is non-destructive -- far more nuisance than threat. However, developing a destructive version wouldn't even be close to brain surgery. So let's get those patches installed, shall we?

Find out how to protect yourself here. ®

Track this type of story as a custom Atom/RSS feed or by email.
Previous Article Next Article
whitepaper title

Enabling the Data Center Metamorphosis

This independent analyst paper gives real world advice on transforming your datacenter into a streamlined, dynamic, liquid engine capable of handling growth..
whitepaper title

Gartner Paper: US Data Centers - The Calm Before the Storm

U.S. enterprise data centers face considerable space and energy constraints over the next few years. Download this free independent report to read more..
Whitepapers Jobs

Top 20 storiesAll The Week’s HeadlinesArchiveSearch