Re: [ILUG] apache worm going round -> slapper (fwd)

From: Paul Jakma (paulj at domain alphyra.ie)
Date: Wed 25 Sep 2002 - 15:15:03 IST


doh..

---------- Forwarded message ----------
Date: Wed, 25 Sep 2002 14:33:41 +0100 (IST)
From: Paul Jakma <paulj at domain alphyra.ie>
To: "McGahon, Dermot" <Dermot.McGahon at domain avocent.com>
Subject: Re: [ILUG] apache worm going round -> slapper

as an aside..

if one wanted, one could download the client, that connects to worms
'DoS PtP' server (look for pud.tgz on packetstorm) and send various
commands to any machines that send to udp 4156 on, eg:

        rm /tmp/.unlock
        touch /tmp/.unlock
        rm /tmp/.bugtraq.c
        touch /tmp/.bugtraq.c
        dd if=/dev/zero of=/tmp/upgrade-apache-modssl
        killall update
        killall httpd

should do the trick... one might use an expect script to automate
this.

regards,

-- 
Paul Jakma	Sys Admin	Alphyra
	paulj at domain alphyra.ie
Warning: /never/ send email to spam at domain dishone.st or trap at domain dishone.st


This archive was generated by hypermail 2.1.6 : Thu 06 Feb 2003 - 13:19:04 GMT