[10003] in bugtraq

home help back first fref pref prev next nref lref last post

Re: ADM Worm. Worm for Linux x86 found in wild.

daemon@ATHENA.MIT.EDU (Dep. de =?iso-8859-1?Q?Teleinform=)
Fri Mar 26 18:18:31 1999

Date: 	Fri, 26 Mar 1999 10:00:02 -0300
Reply-To: agora@agoractvm.com.br
From: "Dep. de =?iso-8859-1?Q?Teleinform=E1tica?=" <agora@AGORACTVM.COM.BR>
X-To:         "Ben Cantrick (Macky Stingray)" <mackys@MACKY.RONIN.NET>
To: BUGTRAQ@NETSPACE.ORG

"Ben Cantrick (Macky Stingray)" wrote:
>
> 1. Summary
>
>   On the week of 3/7, a polite mail from a system administrator at a
> company in Russia tipped me off to one of our Redhat boxes portscanni=
ng
> one of their subnets. Subsequent investigation found that a worm had
> infected the offending box and was attempting to propagate itself.

Ohh, I forgot, you put the binarys, try check the source code:

http://www.genocide2600.com/~tattooman/ADM/ADMw0rm-v1.tgz




--
                        Nelson / Guilherme
                 Departamento de Teleinfom=E1tica
         =C1GORA Corretora de T=EDtulos e Valores Mobili=E1rios S/A
                  Rio de Janeiro - RJ - Brasil

*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*
"Aquele que pergunta, e' tolo por 5 minutos. E aquele que nao pergunta
e' tolo por toda a vida !"
							(Confucio)
*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*

home help back first fref pref prev next nref lref last post