Lion worm

SANS:
Lion is a new worm, that is very similar to the Ramen worm. However, this worm is much more dangerous and should be taken seriously. It infects Linux machines with the BIND DNS server running. It is known to infect bind version(s) 8.2, 8.2-P1, 8.2.1, 8.2.2-Px, and all 8.2.3-betas. The bind vulnerability is the TSIG vulnerability that was reported back on January 29, 2001.

The Lion worm spread via an application called randb. randb scans random class B networks probing TCP port 53. Once it hits a system, it then checks to see if that system is vulnerable. If so it then exploits the system using the exploit called name. It then installs the t0rn rootkit.

Leave a Reply