Friday, March 2, 2007

Worm attempts to exploit Solaris telnet vulnerability

Yesterday, I blogged about the Solaris Zero-Day Telnet Vulnerability discovered a couple of days back. Now, security firm Sophos is warning Solaris users of a new worm that is trying to exploit the vulnerability in the in.telnetd(1M) binary in Solaris.

The Unix/Froot-A worm (also known as Wanuk) tries to gain access to Solaris machines. Machines running Solaris that have not been patched with the recent fix for the bug and which have telnet access enabled could be infected by this worm. Under certain conditions, the worm sends system broadcast messages that could appear as a text message or as an ASCII art.

Users of Solaris are advised to disable telnet access and patch their systems with the recently released fix. Read this and this for news coverage of this issue.

No comments: