Sophos

Talk to our experts

Find your local press contact

Resources

Info feeds

What are info feeds?

1 March 2007

Solaris worm blasts its way through telnet flaw Companies urged to patch to protect against Froot worm

Experts at SophosLabs™, Sophos's global network of virus, spyware and spam analysis centers, have warned of an internet worm that is exploting a recently announced vulnerability on Sun Solaris servers.

The Unix/Froot-A worm (also known as Wanuk) exploits a vulnerability in both x86 and SPARC versions of version 10 of Sun's operating system, attempting to open a backdoor which could allow hackers to gain remote access to computers.

Under certain conditions the Froot worm can send system broadcast messages via the 'wall' command. These can take a variety of forms, including ASCII art and the phrase:

Hi, I'm Casper, I am a bored Sun developer and I wrote this piece of code.

One of the ASCII art messages that can be broadcast displays an offensive message:

WORMS AGAINST NUCLEAR KILLERS. Your System Has Been Officically WANKed. You talk of times of peace for all, and then prepare for war.

Another shows a picture of a talking turkey:

Nope... Just a talking turkey.

"Most attacks today are targeted at computers running Microsoft Windows, but that doesn't mean that businesses running UNIX and other operating systems don't need to take security seriously," said Graham Cluley, senior technology consultant at Sophos. "This worm takes advantage of a security hole in Solaris's telnet service that was first disclosed last month. Vulnerable businesses would be wise to install the vulnerability fix from Sun, and consider disabling telnet."

"Although all new malware attacks are serious, it doesn't seem like that Sun Solaris threats will eclipse the virus problem on Windows anytime soon," continued Cluley. "The correct response is not to panic, but to take sensible action to ensure defenses are in place, software is patched whenever a new vulnerability is announced."

Sophos recommends companies automatically update their corporate virus protection, and run a consolidated solution to defend against viruses, spyware and spam.

About Sophos

Sophos enables enterprises all over the world to secure and control their IT infrastructure. Sophos's network access control, endpoint, web and email solutions simplify security to provide integrated defenses against malware, spyware, intrusions, unwanted applications, spam, policy abuse, data leakage and compliance drift. With over 20 years of experience, Sophos protects over 100 million users in nearly 150 countries with its reliably engineered security solutions and services. Recognized for its high level of customer satisfaction and powerful yet easy-to-use solutions, Sophos has received many industry awards, as well as positive reviews and certifications.

Sophos is headquartered in Boston, US and Oxford, UK. More information is available at www.sophos.com

See also: