Linux vulnerabilities have the "mining" Worm

Source: Internet
Author: User
The Linux Shell (ShellShock) vulnerability is causing a global information security crisis. hackers have developed a worm that automatically spreads through the shell (ShellShock) vulnerability. According to an analysis from Kingsoft drug overlord's Security Center, the main purpose of the worm virus is to intrude a DVR (hard drive video recorder) device in China, hackers use these devices to dig for litecoin (a digital currency similar to Bitcoin), and the worm can also use the attacked DVR device to launch DDoS attacks on any target computer. A hard drive video recorder made in China is widely used.

The Linux Shell (ShellShock) vulnerability is causing a global information security crisis. hackers have developed a worm that automatically spreads through the shell (ShellShock) vulnerability. According to an analysis from Kingsoft drug overlord's Security Center, the main purpose of the worm virus is to intrude a DVR (hard drive video recorder) device in China, hackers use these devices to dig for litecoin (a digital currency similar to Bitcoin), and the worm can also use the attacked DVR device to launch DDoS attacks on any target computer.

A hard drive video recorder made in China is widely used in security devices in supermarkets, streets, and buildings. After successful Shell cracking, hackers have obtained full control, which means they have been cracked) DVRs attacked by the Vulnerability worm will be exposed to the risk of information leakage.

Hackers can easily gain full control over the target liunx host by exploiting the Linux Shell vulnerability. This vulnerability was defined by security experts as level 10 (highest level) and OpenSSL (heartbleed) outbreak in April this year) the vulnerability is only 5 levels. Statistics show that the number of affected linux Hosts in the world is as large as one million.

Researchers at Kingsoft overlord Security Center found that if an attacker happened to have successfully intruded into a DHCP server (automatically assigned an IP address for a LAN device), the attacker could exploit the Linux Shell (ShellShock) vulnerability to write scripts, when other linux Hosts in the LAN use Bash scripts to obtain IP addresses through the DHCP server, they will be instantly intruded.

At present, the Linux Shell (ShellShock) vulnerability mainly affects linux systems with vulnerabilities in enterprises and authorities. Common Internet users are not affected for the time being. It is more time for intruders to compare with CEN. If the network administrator does his/her best, hacker intrusion will be prevented. On the contrary, if intruders are more diligent than the defender, the corresponding enterprise network will inevitably be infiltrated, which will eventually cause the information of Common Internet users stored on the server to fall into the hands of attackers.

Glossary:

Litecoin: similar to Bitcoin, litecoin is a digital currency, which is obtained by computers online computing based on specific algorithms. Bitcoin transactions are prohibited in China.

Mining: due to the limited amount of bitcoin, litecoin and other digital currencies, the more difficult the acquisition process is, the more it is called mining by the industry image.

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.