home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > Applications and Operating Systems
Ask a Tech Support Question (free)!

linux trojan!! beware folks

Reply
Get bargains at  »  Dealighted.com
 
Thread Tools Search this Thread
Currently Active Users: 1249
Discussions: 200,929, Posts: 2,379,147, Members: 246,296
Old January 18th, 2003, 10:24 PM   Digg it!   #1 (permalink)
Ultimate Member
 
pbharris's Avatar
 
Join Date: Oct 2001
Location: Chicago, IL
Posts: 2,514
Send a message via ICQ to pbharris Send a message via AIM to pbharris Send a message via Yahoo to pbharris
linux trojan!! beware folks

hopefully no one will get hit with this, i have all oggs so i am not worried about it, but maybe *you* should be. get more infor here:

http://securityresponse.symantec.com...ux.jbellz.html
__________________
Odds are very good there are several spelling mistakes in this post.
pbharris is offline   Reply With Quote
Old January 18th, 2003, 10:27 PM     #2 (permalink)
Ultimate Member
 
cunokyle's Avatar
 
Join Date: Sep 2002
Location: Iowa
Posts: 3,343
Send a message via AIM to cunokyle
good thing I use XMMS! Does sound like a nasty little virus though.
cunokyle is offline   Reply With Quote
Old January 18th, 2003, 10:32 PM     #3 (permalink)
may contain mild peril
 
SpookyEddy's Avatar
 
Join Date: Oct 2001
Location: UK
Posts: 3,329
Thanks for the info, time for a quick dist-upgrade
__________________
I dreamt that a large eagle circled the room three times and then got into bed with me and took all the blankets.
SpookyEddy is offline   Reply With Quote
Old January 18th, 2003, 10:36 PM     #4 (permalink)
mickwish
 
Posts: n/a
Thanks for the Heads up , PB.

I've only got one Mandrake install at present, with no sound card, so mp3's ain't a prob for me.
Quote:
The current version of Trojan.Linux.JBellz is designed to affect the following Linux systems only:

Suse 8.0
Slackware 8.0

NOTE: The Trojan may affect other Linux systems, and modifying the Trojan is easy enough to support other Linux distributions, or other platforms.

So no complacency for other distros, either.

Cheers
Mick

edit: BTW, these virus threat reports could go in the new Security forum.
  Reply With Quote
Old January 18th, 2003, 10:41 PM     #5 (permalink)
Banned
 
thronka's Avatar
 
Join Date: Dec 2002
Location: Garland, Texas USA
Posts: 1,785
Even if it was to affect other distros, you could easily modify the kernel to stop that service.
thronka is offline   Reply With Quote
Old January 18th, 2003, 10:42 PM     #6 (permalink)
Ultimate Member
 
Germ's Avatar
 
Join Date: Oct 2001
Location: Lat:36.5N, Lon:95.5W
Posts: 1,274
Send a message via AIM to Germ Send a message via Yahoo to Germ
Thanks for the info, Paul. I'm migrating to ogg, guess I better get it finished. Just in case.
__________________
How do you set this laser printer to stun??
Germ is offline   Reply With Quote
Old January 18th, 2003, 10:48 PM     #7 (permalink)
Senior Member
 
Join Date: Oct 2001
Posts: 959
that's very community-minded of symantec considering I couldn't find any linux/unix products in their shopping list

dontcha just love a conspiracy....
the jester is offline   Reply With Quote
Old January 18th, 2003, 11:01 PM     #8 (permalink)
Where's the beef?
 
Scott Tiger's Avatar
 
Join Date: Mar 2002
Location: Southwest, VA
Posts: 3,585
Thanks for the update PB..

Guess Linux's rising popularity is going to increase the likelyhood of threats like these.
__________________
Where's Lunch?
Scott Tiger is offline   Reply With Quote
Old January 18th, 2003, 11:08 PM     #9 (permalink)
dword to your moms
 
krohnjw's Avatar
 
Join Date: Oct 2001
Location: ~/
Posts: 3,195
Send a message via AIM to krohnjw
Scott: Looks like someone took the jinglebell code released by gobbles that allows code to be executed with mpg123 and made their own trojan...go kiddies. This isnt an attack on linux, it's an oppertunist using some one else's code

There is an updated mpg123 package that was released a day or so ago in response to the gobbles code. Should be a quick fix.

thronka: this isnt due to a running service, this is due to someone downloading a modified MP3, modified with the jinglebells code, and playing it with mpg123, the command line mp3 player.

Last edited by krohnjw : January 18th, 2003 at 11:11 PM.
krohnjw is offline   Reply With Quote
Old January 18th, 2003, 11:59 PM     #10 (permalink)
Ultimate Member
 
pbharris's Avatar
 
Join Date: Oct 2001
Location: Chicago, IL
Posts: 2,514
Send a message via ICQ to pbharris Send a message via AIM to pbharris Send a message via Yahoo to pbharris

good point
mickwish!

cunokyle - xmms does use mpg123 to playback mp3s...

Last edited by pbharris : January 19th, 2003 at 12:01 AM.
pbharris is offline   Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Most Active Discussions
Is It Just Me? (2868)
Obama the Muslim (14)
California Passes Anti-Flat-HDTV Le.. (39)
Is the PSU I received dead? (10)
windows vista security holes (9)
HIS HD5770 graphic card question (15)
Print spooler problem (13)
Foreign voltage (10)
Install XP pro and a Vista laptop ?.. (10)
Dept. of HS: NSA 'Helped' Develop V.. (15)
A good PSU? (10)
Ideal cheap graph card for PC-Gamin.. (16)
New Computer wont recognize XP disc (7)
EVGA 9800 gtx help with finding a g.. (8)
Recent Discussions
Regular Build (3)
solutions for virtical white lines on.. (0)
Ideal cheap graph card for PC-Gaming? (16)
Graphics Card Upgrade Question (0)
Fire in DVD (2)
Modern Warfare For the PC (33)
radeon x850xt platinum & shader 3 (3)
Have you switched yet? (84)
Install XP pro and a Vista laptop ?? (10)
Wireless Router+Cable Modems and Much.. (0)
Optical Audio A-B Switch (1)
windows vista security holes (9)
The NTDVM CPU has encountered an ille.. (24)
[F@H SPAM 11/16/09] ! 1/2 months to r.. (34)
Wireless speakers for PC? (11)
Print spooler problem (13)
Help getting around port 80 for camer.. (2)
Display shows 3x5 inch in middle of s.. (3)
monitor will not turn on at all, (1)
World's largest Monopoly Game using G.. (331)
Foreign voltage (10)
FiOS modem/router interfering with ne.. (7)
Browsers wont load websites (2)
Virus Doctor Popup? (1)
Dept. of HS: NSA 'Helped' Develop Vis.. (15)


All times are GMT -4. The time now is 04:01 AM.
TechIMO Copyright 2009 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28