The Register®

Original URL: http://www.theregister.co.uk/2006/02/20/linux_worm/

Linux worm targets PHP flaw

Silly Mare

By John Leyden

Posted in Anti-Virus, 20th February 2006 15:09 GMT

Internet ne'er do wells have created a Linux worm which uses a recently discovered vulnerability (http://secunia.com/advisories/15852) in XML-RPC for PHP, a popular open source component used in many applications, to attack vulnerable systems. The Mare-D (http://www.f-secure.com/v-descs/mare_d.shtml) worm also tries to take advantage of a security flaw (http://secunia.com/advisories/14337) in Mambo to spread. If successful, the worm installs an IRC-controlled backdoor on compromised systems.

Most affected applications have been updated to address the security flaw exploited by Mare-D, which anti-virus firms rate as a low risk. The malware is noteworthy mainly because of the rarity of malware strains targeting Linux systems rather than the minimal threat is poses. ®