There is a new worm about with an interesting twist, it affects multiple operating systems. This one is quite intriguing.
The worm takes advantage of an old Solaris buffer overflow (sadmind) and then propogates from there to exploit one of the plethora of IIS vulnerabilities (web server folder directory traversal.) Once on IIS it is said to modify the web content and possibly damage files (reported by unverified by CERT.) In addition once the worm gets 2000 IIS machines (an hours work) it then modifies the default index.html file on the Solaris machine as well.
Clever, yeah, pain in the ass, yeah, cool, well, kinda.
Check the CERT advisory for more info. sadmind-IIS
Chatter
3 days 13 hours ago
3 days 19 hours ago
1 week 17 hours ago
1 week 17 hours ago
1 week 3 days ago
4 weeks 1 day ago
4 weeks 2 days ago
4 weeks 4 days ago
4 weeks 6 days ago
5 weeks 2 days ago