HYIP-Man: new Linux worm
Wednesday, December 04, 2013
new Linux worm

Symantec has discovered a new Linux worm that appears to be engineered to target the “Internet of things”. The worm is capable of attacking a range of small, Internet-enabled devices in addition to traditional computers. Variants exist for chip architectures usually found in devices such as home routers, set-top boxes and security cameras. Although no attacks against these devices have been found in the wild, many users may not realize they are at risk, since they are unaware they own devices that run Linux.

The worm, Linux.Darlloz, exploits a PHP vulnerability to propagate itself in the wild. The worm utilizes the PHP 'php-cgi' Information Disclosure Vulnerability (CVE-2012-1823), which is an old vulnerability that was patched in May 2012. The attacker recently created the worm based on the Proof of Concept (PoC) code released in late Oct 2013.

Upon execution, the worm generates IP addresses randomly, accesses a specific path on the machine with well-known ID and passwords, and sends HTTP POST requests, which exploit the vulnerability. If the target is unpatched, it downloads the worm from a malicious server and starts searching for its next target. Currently, the worm seems to infect only Intel x86 systems, because the downloaded URL in the exploit code is hard-coded to the ELF binary for Intel architectures.

Linux is the best known open source operating system and has been ported to various architectures. Linux not only runs on Intel-based computers, but also on small devices with different CPUs, such as home routers, set-top boxes, security cameras, and even industrial control systems. Some of these devices provide a Web-based user interface for settings or monitoring, such as Apache Web servers and PHP servers.

We have also verified that the attacker already hosts some variants for other architectures including ARM, PPC, MIPS and MIPSEL on the same server.


Figure:The “e_machine” value in ELF header indicates the worm is for ARM architecture.

These architectures are mostly used in the kinds of devices described above. The attacker is apparently trying to maximize the infection opportunity by expanding coverage to any devices running on Linux. However, we have not confirmed attacks against non-PC devices yet.

Vendors of devices with hidden operating systems and software, who have configured their products without asking users, have complicated matters. Many users may not be aware that they are using vulnerable devices in their homes or offices. Another issue we could face is that even if users notice vulnerable devices, no updates have been provided to some products by the vendor, because of outdated technology or hardware limitations, such as not having enough memory or a CPU that is too slow to support new versions of the software.

To protect from infection by the worm, Symantec recommends users take the following steps:

1.Verify all devices connected to the network

2.Update their software to the latest version

3.Update their security software when it is made available on their devices

4.Make device passwords stronger

5.Block incoming HTTP POST requests to the following paths at the gateway or on each device if not required:

  • -/cgi-bin/php
  • -/cgi-bin/php5
  • -/cgi-bin/php-cgi
  • -/cgi-bin/php.cgi
  • -/cgi-bin/php4

Related:
Free BitDefender Antivirus on UBUNTU LINUX

5 Comments:
NedGraphics 2010 Collection Cracked/License
If you want more information about please Contact us
By
Email : softwarelinked@gmail.com

( NedGraphics Texcelle 6.1.0.24 & Jacquard Pro and Virtual Loom 9.2.0.24 , aLL Languages )

( DesignCOM , Vision Design Studio , EasyMap Pro )
( Catalog Creator , Design Workshop , Tuft ,Storyboard And Cataloguing )
Eat DesignScope victor 2009 Collection Cracked
( Eat DesignScope victor 4.4.8 )
( Eat DesignScope victor 4.4.6 )
( Eat DesignScope victor 4.4.1 )
( Eat DesignScope victor 3.0.4 )
( Eat DesignScope Racshel 3.0.3 )
Sophis Jacquard & Socrates 8.2 / 2005 / USB MEMORY SUPPORT
( We Have Two Original dongle Key with Complete Pc )
( With Matrox Vga Card And Prokey Floppy And Customize Floppy )
( Working With Staubli Punching Card 19-33 And Staubli Card Reader )
Penelope Collection Cracked
( Penelope Yarn 8.9.0.1 )
( Penelope Jacquard 9.0.2.4 )
( Penelope Atrezzo 3D 2.2 )
( Penelope Jacq Dobby Terry )
MüCAD Collection Cracked
( MüCAD 3.600 with Digicolor )
Pointcarre Collection Cracked
( PointCarre 3.0.64 /2009/ )
Pixel Art Collection Cracked
( Pixel Art Jacquard 2008 )
( Pixel Art Studio 2008 )
( Pixel Show 2.86.0.0 )
( Pixel Form 1.0.10.1 )
CSS Carpet Software Solutions
( Loom Manager NT 2.0.11 / 20.9.2010 / )
( Carpet Weaver NT 2.7.4 / 16.09.2010 /)
Booria Collection Cracked
( Booria design pro and weaver 2008 )
Stäubli 19-33 Collection Cracked
( Software for Stäubli 19-33 punching machine from Nedgraphics Company )
( Software for Stäubli 19-33 punching machine from Penelope Company )
( Software for Stäubli 19-33 punching machine from Eat Designscope Company )
If you want more information about please Contact us
By
Email : softwarelinked@gmail.com

NedGraphics 2010 Collection Cracked/License
If you want more information about please Contact us
By
Email : softwarelinked@gmail.com

( NedGraphics Texcelle 6.1.0.24 & Jacquard Pro and Virtual Loom 9.2.0.24 , aLL Languages )

( DesignCOM , Vision Design Studio , EasyMap Pro )
( Catalog Creator , Design Workshop , Tuft ,Storyboard And Cataloguing )
Eat DesignScope victor 2009 Collection Cracked
( Eat DesignScope victor 4.4.8 )
( Eat DesignScope victor 4.4.6 )
( Eat DesignScope victor 4.4.1 )
( Eat DesignScope victor 3.0.4 )
( Eat DesignScope Racshel 3.0.3 )
Sophis Jacquard & Socrates 8.2 / 2005 / USB MEMORY SUPPORT
( We Have Two Original dongle Key with Complete Pc )
( With Matrox Vga Card And Prokey Floppy And Customize Floppy )
( Working With Staubli Punching Card 19-33 And Staubli Card Reader )
Penelope Collection Cracked
( Penelope Yarn 8.9.0.1 )
( Penelope Jacquard 9.0.2.4 )
( Penelope Atrezzo 3D 2.2 )
( Penelope Jacq Dobby Terry )
MüCAD Collection Cracked
( MüCAD 3.600 with Digicolor )
Pointcarre Collection Cracked
( PointCarre 3.0.64 /2009/ )
Pixel Art Collection Cracked
( Pixel Art Jacquard 2008 )
( Pixel Art Studio 2008 )
( Pixel Show 2.86.0.0 )
( Pixel Form 1.0.10.1 )
CSS Carpet Software Solutions
( Loom Manager NT 2.0.11 / 20.9.2010 / )
( Carpet Weaver NT 2.7.4 / 16.09.2010 /)
Booria Collection Cracked
( Booria design pro and weaver 2008 )
Stäubli 19-33 Collection Cracked
( Software for Stäubli 19-33 punching machine from Nedgraphics Company )
( Software for Stäubli 19-33 punching machine from Penelope Company )
( Software for Stäubli 19-33 punching machine from Eat Designscope Company )
If you want more information about please Contact us
By
Email : softwarelinked@gmail.com

OrcaFlex 9.7c Download with Licens
If you want more information about please Contact us
By
Email : softwarelinked@gmail.com



OrcaFlex


OrcaFlex Support
OrcaFlex 9.7
OrcaFlex 9.6
OrcaFlex 9.5
OrcaFlex 9.4
OrcaFlex 9.3
OrcaFlex 9.2
OrcaFlex 9.1
OrcaFlex 9.0
OrcaFlex 8.7
OrcaFlex 8.6
OrcaFlex 8.5
OrcaFlex 8.4
OrcaFlex 8.3
OrcaFlex 8.2
OrcaFlex 8.1
OrcaFlex 8.0


A new data item has been added named skip dynamic simulation file save. When this is checked, the dynamic simulation files are not saved if running in batch mode or Distributed OrcaFlex (i.e. whenever post-calculation actions are active). This is useful if the post-calculation action extracts all the output you need from the simulation. Skipping the saving of the simulation file allows you to reduce storage and bandwidth demands.

If you want more information about please Contact us
By
Email : softwarelinked@gmail.com

By
Email : softwarelinked@gmail.com
Siemens.PLM.NX.v9.0.0.MacOSX6
Fornux.PowerCalc-GX.v4.2
TGS_AMIRA_V3.11_FOR_VC7
TGS.Avizo.v5.0
Xilinx.ISE.Design.Suite.v14.3
Xilinx.ISE.Design.Suite.v14.4
TGS.Open.Inventor.v6.0
TGS Open Inventor SDK v4.0
TGS_OPEN_INVENTOR_JAVA_V5.0
TGS_OPEN_INVENTOR_V5.0_FOR_VC6
Bentley RAM Structural System v8i 14.04.03.00
FlexPde.Professional.3D.v5.0.3
OPTICAL.RESEARCH.ASSOCIATES.LIGHTTOOLS.V6.3
OPTICAL.RESEARCH.ASSOCIATES.LIGHTTOOLS.V7.0
Microsurvey CAD 2013 V13.0.1.3
Minitab.v16.2.4 +minitab v16.2.2
PDMS v11.6 SP4.8
PDMS v12 SP5 +SP4.10
Altair.HyperWorks v11
Altair_SimLab v10
Fledermaus.Pro.v6.5.0.44
GeoStru.DownHole.v2014.9.1.261
GeoStru.GDW.v2014.18.0.182
GeoStru.MDC.v2014.20.4.715
GeoStru.Slope.v2014.18.2.1057
CADRE.Flow.v1.1.1007.0
CADRE.Geo.v5.0.1009.0
CADRE.Pro.v5.0.2.6
CADRE.Profiler.v2.0.6003.0
CADRE.Rescol.v2.0.1.4
NE_NASTRAN_V8.3
QuickField 4.2
Real_flow 1.3
ReelMotion Animation Tool v1.0
StatPoint.STATGRAPHICS.Centurion.v15.1.0.2
t us
By
Email : softwarelinked@gmail.com

Cast-Designer V5.5 introduced a new version of one-stop solution to achieve the casting process
If you want more information about please Contact us

C3P Software , the leading manufacturing industries CAX solutions provider, officially launched the foundry industry integrated solutions - Cast-Design V5.5 , includes many innovative features, the realization of the entire casting process from design to production of the one-stop solution .

The new version of Cast-Designer V5.5 main innovative features:

One-button system is highly automated casting runner design features (high pressure casting):

A new design pattern, can be widely used in high-pressure design. Using highly automated one-button design features pouring runner system, pouring runner design time past Cast-Designer design five to ten times faster, and more traditional CAD models are at least quick 10 to 20 or more times. In addition to high efficiency, this design pattern is ideal for casting a novice, you can quickly get a high standard of design.

One-button system is highly automated casting runner design features, the use of predefined gating system knowledge database, fully parametric settings gating system size, the system default over 25 kinds of commonly used form of stream channel, and the system also supports CDGL ( Cast-Designer casting gating system design ) language, it can be used for the expansion of the form of passengers.

http://softwarelinked.blogspot.com/

If you want more information about please Contact us