Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Solaris 10 Worm

Thread Tools
 
Search this Thread
 
Old 14 November 2007, 11:29 AM
  #1  
Wurzel
Scooby Senior
Thread Starter
iTrader: (1)
 
Wurzel's Avatar
 
Join Date: Nov 2000
Location: Wildberg, Germany/Reading, UK
Posts: 9,706
Likes: 0
Received 73 Likes on 54 Posts
Cool Solaris 10 Worm

Not quite sure how relevent this is, the more I look into it the more it seems to be old hat, but I only found out about it today so decided to share it with anyone who is interested.

Here is a link to the description of the worm and what it does, and there are instructions below as to how to disable the Wanuk Worm this is the link to the description.

http://www.virusbtn.com/virusbulletin/archive/2007/04/vb200704-solaris-worm.dkb

Don't do an
# su - adm
or
# su - lp

as this will execute a malicious .profile of each user!

Look in /var/adm/sa/.adm to see if there are any .lp-door files or any other .xxxx files.

Move (and chmod 444 these files on your system if they are present)

# find /var -mtime +3650 | grep -v apache /var/adm/.profile.weg /var/adm/.sa.wegdamit/.adm.wegdamit/.lp-door.i86pc.wegdamit

/var/adm/.sa.wegdamit/.adm.wegdamit/inetadm.wegdamit
/var/adm/.sa.wegdamit/.adm.wegdamit/.sun4.wegdamit
/var/adm/.sa.wegdamit/.adm.wegdamit/.i86pc.wegdamit
/var/adm/.sa.wegdamit/.adm.wegdamit/devfsadmd.wegdamit
/var/adm/.sa.wegdamit/.adm.wegdamit/.lp-door.sun4.wegdamit
/var/spool/lp/admins/.lp.wegdamit/lpsystem.wegdamit
/var/spool/lp/admins/.lp.wegdamit/.lp-door.i86pc.wegdamit
/var/spool/lp/.profile.wegdamit
/var/spool/cron/crontabs/adm
/var/spool/cron/crontabs/lp

svcadm disable svc:/network/telnet

After that - I expect that the system to be clean but I don't know if it's really fully cleaned.

HTH

If not just ignore it.

Steve

Last edited by Wurzel; 14 November 2007 at 11:58 AM.
Old 15 November 2007, 03:23 AM
  #2  
Boro
Scooby Regular
iTrader: (1)
 
Boro's Avatar
 
Join Date: Jul 2003
Location: Cornwall
Posts: 7,222
Likes: 0
Received 0 Likes on 0 Posts
Default

what he said
Old 15 November 2007, 08:50 PM
  #3  
NotoriousREV
Scooby Regular
 
NotoriousREV's Avatar
 
Join Date: Jan 2002
Posts: 11,581
Likes: 0
Received 0 Likes on 0 Posts
Default

I love Solaris viruses and hacks because a) they're usually pretty creative and b) they're easy to get rid of without a reinstall (unlike some other OSs I won't mention)
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
druddle
Computer & Technology Related
8
05 November 2002 11:12 AM
druddle
Computer & Technology Related
3
16 March 2002 07:23 AM



Quick Reply: Solaris 10 Worm



All times are GMT +1. The time now is 06:14 AM.