Home > Support > Global Security Advisor 

Virus Detail

Linux/Lupper.B

Date Published:
7 Nov 2005

Last Updated:
17 Nov 2005

Threat Assessment

Overall Risk:   Low
Wild:  Low
Destructiveness:  High
Pervasiveness:  Medium

Characteristics

Type : Worm

Category : Linux

Also known as:  Linux/Lupper.worm (McAfee)

Immediate Protection Info

 
SignatureProductRemoval Instructions
11.x/9498
eTrust Antivirus v7/8* (Vet Engine)
6.2x/9498
eTrust EZ Antivirus 6.2x
6.3x/9498
eTrust EZ Antivirus 6.3x
6.4x/9498
eTrust EZ Antivirus 6.4x
7.x/9498
eTrust EZ Antivirus 7.x
10.6x/9498
Vet Anti-Virus 10.6x
 
 
 

Description

Lupper.B is a worm designed to spread through web servers by exploiting four different security vulnerabilities. This variant has been distributed as 35,567-byte I386 ELF program.

Back to top

Method of Distribution

Via Exploits

Lupper attempts to execute a simple set of four commands on a remote server:


  • Change folder to /tmp
  • Download a copy of the worm named “lupii” from a particular hard-coded IP address using Wget
  • Modify its execution attributes
  • Execute the downloaded copy of the worm

The worm sends the above commands by exploiting the following vulnerabilities:


Trying to exploit the AWStats vulnerability, the worm attempts to submit its commands to the awstats.pl script at the following locations:


/cgi-bin/awstats.pl
/scgi-bin/awstats.pl
/awstats/awstats.pl
/cgi-bin/awstats/awstats.pl
/scgi-bin/awstats/awstats.pl
/cgi/awstats/awstats.pl
/scgi/awstats/awstats.pl
/scripts/awstats.pl
/cgi-bin/awstats/awstats.pl
/scgi-bin/awstats/awstats.pl
/cgi-bin/stats/awstats.pl
/scgi-bin/stats/awstats.pl
/stats/awstats.pl


Trying to exploit the XML-RPC vulnerability, the worm attempts to submit its commands to the following scripts:


/xmlrpc.php
/xmlrpc/xmlrpc.php
/xmlsrv/xmlrpc.php
/blog/xmlrpc.php
/drupal/xmlrpc.php
/community/xmlrpc.php
/blogs/xmlrpc.php
/blogs/xmlsrv/xmlrpc.php
/blog/xmlsrv/xmlrpc.php
/blogtest/xmlsrv/xmlrpc.php
/b2/xmlsrv/xmlrpc.php
/b2evo/xmlsrv/xmlrpc.php
/wordpress/xmlrpc.php
/phpgroupware/xmlrpc.php


Trying to exploit the Webhints vulnerability, the worm attempts to submit its commands to the following scripts:


/hints.pl
/cgi/hints.pl
/scgi/hints.pl
/cgi-bin/hints.pl
/scgi-bin/hints.pl
/hints/hints.pl
/cgi-bin/hints/hints.pl
/scgi-bin/hints/hints.pl
/webhints/hints.pl
/cgi-bin/webhints/hints.pl
/scgi-bin/webhints/hints.pl
/hints.cgi
/cgi/hints.cgi
/scgi/hints.cgi
/cgi-bin/hints.cgi
/scgi-bin/hints.cgi
/hints/hints.cgi
/cgi-bin/hints/hints.cgi
/scgi-bin/hints/hints.cgi
/webhints/hints.cgi
/cgi-bin/webhints/hints.cgi
/scgi-bin/webhints/hints.cgi


Trying to exploit the Includer vulnerability, the worm attempts to submit its commands to the following scripts:


/cgi-bin/includer.cgi
/scgi-bin/includer.cgi
/includer.cgi
/cgi-bin/include/includer.cgi
/scgi-bin/include/includer.cgi
/cgi-bin/inc/includer.cgi
/scgi-bin/inc/includer.cgi
/cgi-local/includer.cgi
/scgi-local/includer.cgi
/cgi/includer.cgi
/scgi/includer.cgi


Back to top

Payload

Backdoor Functionality

Lupper.B opens a UDP backdoor on port 7222 that allows a remote controller unauthorized access to the affected machine.


The worm can also relay Internet traffic – i.e. act a s a proxy.


Back to top

For additional information:

The worm reports back to its hosting site, sending data through UDP port 7222.


Analysis by Jakub Kaminski


Back to top

CA Global Security Advisor

Current threat condition: Low
Low
Find Threats
Viruses Spyware
Vulnerabilities All

Security Resources

 
 
Page Tools