Backdoor worm owns Tomcat boxes

By
Follow google news

Logs in with weak credentials.

In brief: Symantec has uncovered a backdoor self-replicating worm that targets websites running Apache Tomcat.

Backdoor worm owns Tomcat boxes

The worm (Java.Tomdep) affected Mac OS X, Linux and Solaris boxes. A Java Servlet executed on Apache Tomcat opened an IRC link to attacker servers based in Taiwan and Luxembourg. 
 
The worm attempted to log in with weak usernames and passwords when another Tomcat server was detected. 
 
Symantec said: "Aside from standard commands such as download, upload, creating new process, SOCKS proxy, UDP flooding, and updating itself; compromised computers can also scan for other Tomcat servers and send the malware to them."
 
"It is thus possible that DDoS attacks from the compromised servers are the attacker’s purpose."

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.

Copyright © SC Magazine, Australia

Tags:

Most Read Articles

NAB's CSO to move to ANZ Banking Group

NAB's CSO to move to ANZ Banking Group

Researchers chain Tesla charger bug into a four-vendor EV worm

Researchers chain Tesla charger bug into a four-vendor EV worm

Two Aussies alleged to be "principal participants" of TeamPCP hacking group

Two Aussies alleged to be "principal participants" of TeamPCP hacking group

ASD warns Australian TeamCity servers under attack

ASD warns Australian TeamCity servers under attack

Log In

  |  Forgot your password?