Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
Motorola, Woot 'fess up to reselling uncleared Xoom tablets
How NOT to get a job 101: Hack Marriott, extort execs for work
FAQ about the VeriSign data breaches
Why the House spectrum bill should be ditched: Q&A with Reed Hundt
Google finally scans malware-ridden Android Market
Lawsuit raises questions about email privacy at work
The future of hypervisors
Vendors show voice call hand-off between LTE, 3G networks
VeriSign admits multiple hacks in 2010, keeps details under wraps
Facebook ripe for ridicule as it suffers outage a day after IPO filing
TD Bank gets social for better business
IT salaries rise, bonuses get bigger
Before Facebook: How other recent dot-com IPOs have fared
Obama web site crushed by Republicans' when it comes to download speeds
FBI busts software copyright fugitive who fled to Pakistan
/

Worm exploits Apache vulnerability on FreeBSD

Today's breaking news
Send to a friendFeedback


A worm that can compromise systems running the Apache Web server on the FreeBSD operating system is crawling the Internet, but its spread and impact are limited, experts said on Monday.

The worm takes advantage of a known security hole in Apache Web servers by scanning the Internet and installing a backdoor application when it finds a vulnerable Web server. This backdoor allows the attacker to remotely control the system and use it in attacks on other Web servers, according to antivirus software vendor F-Secure in Helsinki.

The open-source Apache server is the most commonly used Web server software, running on 63% of Web sites, according to a survey by Web server analysis firm Netcraft Ltd. of Bath, England.

However, the reach of the worm, dubbed Scalper by F-Secure, is limited because it only affects Apache on the open-source FreeBSD operating system, said Mikko Hyppönen, research manager at F-Secure.

"It only hits a small fragment of the Apache users," Hyppönen said.

Mike Prettejohn, director at Netcraft, agreed. "FreeBSD is the third most popular platform for Apache after Linux and Solaris," he said.

Hyppönen does not see the worm as a big danger. "The current version is low risk. It is spreading, we can see hits generated by the worm, but it is not widespread. It could infect a measurable portion of the FreeBSD Web server, but that has not happened yet," he said.

Variants of the worm attacking Apache on other platforms may soon surface, Hyppönen said.

"It would be easy to change this worm to work on Linux or any other system. But then, on the positive side, I would think that Apache Web server administrators are diligent in patching, so the spread would not be as big as Code Red, which infected about 200,000 Web sites in two days about a year ago," Hyppönen said.

Indeed, Apache administrators have responded swiftly, with well over 6 million Web sites running on Apache already upgraded to Apache 1.3.26, a version of the software not vulnerable to this attack. However, about 14 million potentially vulnerable sites using Apache remain, Netcraft said in its monthly commentary released on Monday.

Antivirus software vendor Sophos PLC has received a sample of the Apache worm, but has not yet been able to make it work, said Graham Cluley, senior technology consultant at Sophos in Oxford, England.

"At the moment we think it is a bit of a curiosity. We believe it tries to attack FreeBSD machines, but it is so unstable that getting the right configuration to make it work is tough. That of course also will limit the ability to spread," Cluley said.

The flaw in the Apache Web server that the worm exploits affects all versions of Apache 1.2, versions of Apache 1.3 up to 1.3.24 and versions of Apache 2 up to 2.0.36, according to a statement from the Apache Software Foundation released on June 20. The new Apache 1.3.26 and Apache 2.0.39 fix the issue, the Foundation said.

The flaw relates to the way the Web server parses uploaded data and can cause the software to misinterpret the size of incoming chunks of data. It can be exploited by sending a carefully crafted request to the server, said the Foundation, which manages development of the open-source Apache products.

The IDG News Service is a Network World affiliate.

RELATED LINKS


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.