Attackers were quick to capitalized on the Shellshock Bash command interpreter bug disclosed yesterday. Constructing a botnet that is rapidly try to infect other servers, according to a security researcher.
The “wopbot” botnet is active and scanning the internet for vulnerable systems, including at the United States Department of Defence, chief executive of Italian security consultancy Tiger Security, Emanuele Gentili, told iTnews.
“We have found a botnet that runs on Linux servers, named “wopbot”, that uses the Bash Shellshock bug to auto-infect other servers,” Gentili said.
Wopbot has so far launched a distributed denial of service (DDOS) attacks against servers hosted by Akamai, and is also aiming for other targets, according to Gentili.
“Analysing the malware sample in a sandbox, we saw that the malware has conducted a massive scan on the United States Department of Defence Internet Protocol address range on port 23 TCP or Telnet for brute force attack purposes,” he said.
The US DoD network in question is the 215.0.0.0/8 range, with approximately 16.7 million addresses.
Gentili said Tiger Security had contacted UK provider M247 and managed to get the wopbot botnet command and control system taken down from that network.
However, the botmaster server for wopbot – hosted by US network Datawagon – is still up and distributing malware, Gentili said.
He was unable to say how many systems are involved in the wopbot botnet, but he believes the number could increase very fast.
“Unfortunately is not easy for us say how many servers has been infected, but in the past I observed that similar botnets were able to infect more than 200,000 zombies in an hour or so,” Gentili said.
The ‘Shellshock’ remotely exploitable vulnerability in the Bash Linux command-line shell was discovered yesterday, with researchers warning of its potential to become larger than the severe Heartbleed OpenSSL flaw uncovered earlier this year.
Millions of Apache webservers around the world could be at risk if their common gateway interface (CGI) scripts invoke Bash.
The ‘Shellshock’ Bash exploit has the potential to affect any using the Bash interface, these include UNIX, Linux and Mac OS X system among the systems utilizing this interface.
More Stories
theHamStop.com Adds 2 New items
theHamStop.com introduces slotted products just in time for FieldDay 2025!!. The announcement from theHamStop.com of the release of theSkyHookx2x6S and...
Choosing a Portable All-Band Radio for Emergencies
After a recent conversation among friends over choosing a portable all-band radio suitable for emergencies....
theHamStop.com Introduces theCleatV
theHamStop.com has a new item in the shop just in time for 2024 Field Day!!. The announcement from theHamStop.com...
theCleatV and theSkyHookx3x8 are available
theHamStop.com has been at it AGAIN!! with 2 new products added to their inventory. The announcement from theHamStop.com of the...
E-beam atomic-scale 3-D ‘sculpting’ could enable new quantum nanodevices
koi phys.org/news/2020-09-e-beam-atomic-scale-d-sculpting-enable.amp
Facebook Paying Social Media Users to Suspend Accounts Ahead of November Elections
Facebook is offering money to those who are willing to stop using Facebook and Instagram in the weeks before the...