FRISK Software International


Summary of Unix/Scalper
Alias:Unix/Scalper.A
Discovered: 29 Jun 2002
Definition files: 29 Jun 2002
 
Jump to:
Brief description
Technical description
Removal Instructions

Brief Description

Scalper is a worm that propagates from a FreeBSD system to another via a security vulnerability in Apache web server, known as chunked encoding vulnerability.



Technical Description

VARIANT: Scalper.A

Scalper affects systems running FreeBSD running the vulnerable version of Apache web server

If the worm gains access to the server, it creates a temporary file "/tmp/.uua", which is an uuencoded worm. This file is decoded to "/tmp/.a" and executed. The uuencoded file is removed

At this point the worm sets up a backdoor to UDP port 2001 and starts scanning predefined set of Class-A networks. If the worm finds a web server, it checks if the server is running Apache, and if so, it will attempt to infect it. While the exploit code that Scalper uses will only infect systems running FreeBSD, these attempts will be visible in Apache servers running on other platforms as well.

The backdoor component of the worm allows a remote control of the worm, sending of email, uploading of files and executing of arbitary programs. The execution of programs happens with the same user privilege as the Apache server. The backdoor can also perform different kind of denial of service attacks against arbitary hosts.

The worm does not modify the system configuration, and it is visible in the system process list as a process ".a".

The vulnerability used by the worm is fixed in Apache server versions 1.3.26 and 2.0.39. Further information is available from:

Apache Sofware Foundation: http://httpd.apache.org/info/security_bulletin_20020620.txt



Removal Instructions
Scalper can be removed from the system by deleting file "/tmp/.a" and terminating the worm process with command "killall -9 .a".


[Analysis: Katrin Tocheva and Sami Rautiainen, F-Secure Corp.; June 29th, 2002]
 


Stay up to date with important developments via e-mail.
Stay up to date with life cycle policies for F-PROT Antivirus for Windows.
Virus news and information directly to your desktop.
Definitions of common antivirus terminology.
For further virus information, please try our partners' websites:

Authentium

perComp Verlag
(in German)
 

agoat@klaki.net argentina@f-prot.com argentina@frisk.is argentina@complex.is argentina@f-prot.is argentina@frisk-software.com argentina@f-prot.net argentina@f-prot.co.uk brazil@f-prot.com brazil@frisk.is brazil@complex.is brazil@f-prot.is brazil@frisk-software.com brazil@f-prot.net brazil@f-prot.co.uk malta@f-prot.com malta@frisk.is malta@complex.is malta@f-prot.is malta@frisk-software.com malta@f-prot.net malta@f-prot.co.uk a.bjani@f-prot.com a.bjani@frisk.is a.bjani@complex.is a.bjani@f-prot.is a.bjani@f-prot.co.uk a.bjani@frisk-software.com a.bjani@f-prot.net z.fifl@f-prot.com z.fifl@frisk.is z.fifl@complex.is z.fifl@f-prot.is z.fifl@f-prot.co.uk z.fifl@frisk-software.com z.fifl@f-prot.net strumpuri@complex.is strumpure@complex.is strumpuru@complex.is