Network Security Library
Javascript Feeds    RSS Feed    Security Dashboard    SearchSecurity.com
About | Contact | Advertise | Site Map
intrusion detection E-mail      Save Save This

An Analysis of the Slapper Worm Exploit


{LANG_NAVORIGIN} Malicious Code
By: Frédéric Perriot and Peter Szor, 04/22/2004



Linux/Slapper spreads to Linux machines by exploiting the long SSL2 key argument buffer overflow in the libssl library, which the mod_ssl module of the Apache 1.3 Web servers used. When attacking a machine, the worm attempts to fingerprint the system by first sending an invalid GET request to the http port—port 80—and expecting Apache to return its version number, as well as the Linux distribution on which it was compiled with an error status.

Read Entire Paper















E-Mail Link

Your IP address will be sent with this e-mail
From e-mail to e-mail



152 Views
0/5 Rating
0 Votes
Newest
Highest Rated
Most Viewed
Reference

Javascript Feeds
RSS (New Papers)
Security Dashboard

About SecurityDocs
Advertise
Contact

Valid HTML 4.01!
Valid CSS!


Unless otherwise noted, all paper copyrights are owned by the author. The rest copyright 2003-2005 TechTarget

Privacy : Contact