Linux worm targets PHP based application

There is news of a worm which uses a vulnerability in the PHPXMLRPC libraries to spread a computer virus. It is called as Linux/Lupper.worm. This is not just Linux or BSD specific it would affect anything that use the PHP. McAfee reports that

This worm spreads by exploiting web servers hosting vulnerable PHP/CGI scripts. It is a modified derivative of the Linux/Slapper and BSD/Scalper worms from which it inherits the propagation strategy. It scans an entire class B subnet created by randomly choosing the first byte from an hard-coded list of A classes and randomly generating the second byte.

WordPress blog software is secure from this attack :D Read the McAfee report here. More coverage is here and here.

Leave a Reply

Your email address will not be published. Required fields are marked *

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

What is 6 + 12 ?
Please leave these two fields as-is:
Solve the simple math (so we know that you are a human)