Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

File-encrypting ransomware starts targeting Linux web servers (re-post)
PCworld.comIDG News Service ^ | Nov 9, 2015 7:00 AM | Lucian Constantin

Posted on 11/10/2015 10:45:12 PM PST by Utilizer

Ransomware authors continue their hunt for new sources of income. After targeting consumer and then business computers, they’ve now expanded their attacks to Web servers.

Malware researchers from Russian antivirus vendor Doctor Web have recently discovered a new malware program for Linux-based systems that they’ve dubbed Linux.Encoder.1.

(Excerpt) Read more at pcworld.com ...


TOPICS: Business/Economy; Computers/Internet
KEYWORDS: malware; ransomware; webadmins
A new ransomware exploit has been discovered which affects the Linux OS. Known as "Linux.Encoder.1", it mostly affects web servers: Nginx and/or Apache are affected (MySQL) so admins are warned.
1 posted on 11/10/2015 10:45:12 PM PST by Utilizer
[ Post Reply | Private Reply | View Replies]

To: Utilizer

I must have copied too many words for the ‘excerpt’ function.

Here is a much-shortened re-post to guide others to this potential problem (the ransomware, in case you were wondering).

Admins beware...


2 posted on 11/10/2015 10:47:05 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzlims trying to kill them)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer; John Robinson; ShadowAce; unixfox; dayglored

Newest thread...


3 posted on 11/10/2015 10:48:02 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzlims trying to kill them)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Utilizer; ShadowAce; unixfox
Oh, poop, you mean all those wonderful pithy comments we put on the other thread are gone?

*sigh*

Okay, well, I'm going to bed, it's after 2AM. I'll stop back tomorrow... :-)

4 posted on 11/10/2015 11:01:18 PM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 3 | View Replies]

To: Utilizer
I clicked on this Comment link.

Then, my computer was taken over by ransom-ware.

What should I do?

Please send your advice to me at:

www.boguswebsite.rus

5 posted on 11/10/2015 11:02:18 PM PST by zeestephen
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

No worries. Talk to you when we all make it back then. :)


6 posted on 11/10/2015 11:05:15 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzlims trying to kill them)
[ Post Reply | Private Reply | To 4 | View Replies]

To: dayglored; Utilizer; ShadowAce; unixfox
I will repeat (in compressed form) my message of caution with regard to the infamous "Doctor Web".

1. DW sells a product (anti-malware) and through an amazing coincidence, also "discovers" malwares in places no one else finds them, that can be fixed by their products. Amazing.

2. DW has "discovered" malwares that are claimed to be widespread, but even after months or years, has failed to provide hard evidence of their existence. But in the meantime, the announcements make for great notoriety and bazillions of page hits for the tech web journalists whores. They love Doctor Web.

3. Skepticism is advised. Just sayin'.

4. That said, of course it's worth taking the usual precautions to harden your servers and do off-host backups.

5. Anyone who runs their webservice (e.g. Apache) as root deserves everything they get.

7 posted on 11/10/2015 11:10:30 PM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 4 | View Replies]

To: Utilizer

Okay, now I’m really going offline. Nighty-night all, and God Bless.


8 posted on 11/10/2015 11:12:27 PM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 6 | View Replies]

To: Utilizer
Ransomware whatever. Only one patch and done, just forget about it.

Did they successfully intrude in OS X yet?

9 posted on 11/11/2015 12:03:34 AM PST by hamboy
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored
. Anyone who runs their webservice (e.g. Apache) as root deserves everything they get. ,

If I am not mistaken most, if not all, pre-compiled binaries do not support Apache running as root.

I have built and manage a few Linux servers and I know of no reason one would want to run Apache as root?

Apache always starts as root to bind to privileged ports but immediately changes to user context.

10 posted on 11/11/2015 12:27:14 AM PST by sand88 (We can never legislate our way back to Liberty)
[ Post Reply | Private Reply | To 7 | View Replies]

To: Utilizer; rdb3; Calvinist_Dark_Lord; JosephW; Only1choice____Freedom; amigatec; ...

11 posted on 11/11/2015 3:28:35 AM PST by ShadowAce (Linux - The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: sand88
> ... I know of no reason one would want to run Apache as root? Apache always starts as root to bind to privileged ports but immediately changes to user context.

Correct.

But I have seen instances where the person who set it up, having an incomplete understanding of how to properly allow a web visitor write into a filesystem, simply configured Apache to run as root so it didn't encounter any problems writing.

As you might expect, hilarity ensued.

12 posted on 11/11/2015 6:44:16 AM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 10 | View Replies]

To: hamboy; Swordmaker
> Ransomware whatever... Did they successfully intrude in OS X yet?

YEP. Proof of concept, but verified.

http://motherboard.vice.com/read/we-now-have-proof-that-macs-can-get-ransomware

https://www.linkedin.com/pulse/mabouia-born-first-mac-osx-ransomware-poc-rafael-salema-marques

http://www.symantec.com/connect/blogs/proof-concept-threat-reminder-os-x-not-immune-crypto-ransomware

13 posted on 11/11/2015 6:54:15 AM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 9 | View Replies]

To: sand88
Apache always starts as root to bind to privileged ports but immediately changes to user context.

Yup. Generally runs as 'nobody', and that user shouldn't have write access to anything important.

14 posted on 11/11/2015 7:15:35 AM PST by zeugma (Teach your child a love for motorcycles, and he'll never have money for drugs.)
[ Post Reply | Private Reply | To 10 | View Replies]

To: dayglored
Trojan or so called ransomware need to emulate 'root' as 'superuser do'. OS X may be vulnerable being a client device but not servers.

Simple patch will eradicate the threat.

I'd not gonna buy some mcaffee nor symantec whatever in my Linux and apple devices, gimme a break.

In fact I don't even use any in my Windoze devices except for Malwarebytes that does most I need.

15 posted on 11/12/2015 5:25:21 PM PST by hamboy
[ Post Reply | Private Reply | To 13 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson