Linux Vulnerability Found in Web Exploit
According to the researchers, the backdoor may have been created with a freely available penetration testing suite known as the Social-Engineer Toolkit.
A hacked Colombian Transport website has been rigged to deliver a malware payload that is able to target Mac OS, Windows and even Linux systems, according to a report from F-Secure.
Users will see a certificate warning, telling them that the website is attempting to run a signed applet with an invalid signature. If that warning is bypassed, F-Secure says, the malware checks the victim's computer, and downloads different malicious files based on what operating system it detects.
Regardless of what OS is present, however, the malware's subsequent behavior is the same -- it downloads additional files from a remote server and creates a backdoor on an infected machine. Interestingly, the Mac OS version is a PowerPC binary, which means that Intel-based Macs are immune in most cases.
According to the researchers, the backdoor may have been created with a freely available penetration testing suite known as the Social-Engineer Toolkit.
The malware, which F-Secure has dubbed GetShell.A, is unusual in a couple of ways. First, attacks against Linux are relatively rare in and of themselves. While some experts say that this is due largely to the framework's comparatively small user base -- at least, in terms of desktop users -- others argue that Linux is intrinsically more difficult to compromise than Mac OS and Windows. What's more, malware that targets multiple platforms at once is uncommon, though it does happen.
Nevertheless, CNET blogger Topher Kessler wrote that it's far from the most dangerous malware on the Web. He says that it's likely that the backdoor is the brainchild of less technically gifted hackers, and noted that the aforementioned PowerPC oversight would dramatically limit the malware's effectiveness against Macs.
LATEST NEWS
Despite Weaker Global Demand, PC Sales Rise In India By Three Percent In Q1 2013: Says IDC
The overall India PC shipments for Q1 2013 stood at 2.71 million units i.e. a year-on-year growth of roughly 3% over Q1 2012 and a quarter-on-quarter growth of about 7.5% over Q4 2012.
Google I/O Update:Three Products Curiously Absent from the Keynote
No new Nexus tablet? Not more than a peep on that groundbreaking Internet-on-your-face technology that Sergey Brin quietly introduced last year?
Google I/O Update:Glass Wearers Say 'Trust Us'
Google is facing some tough questions from Congress over the privacy concerns raised by Glass, its fledgling augmented reality system for recording and receiving information on the fly.
Microsoft Accelerator for Windows Azure Announces Multi-city Coffee Meet-ups
The Accelerator program team will travel to four key startup hubs of India, namely, Delhi, Hyderabad, Pune and Chennai, to meet entrepreneurs and answer all their queries related to the startup ecosystem of India as well as the Microsoft Accelerator for Windows Azure (India) program






























