Perl Bot Infecting Web Servers

Looks like the bad guys are still using Perl bots and known exploits to infiltrate Web servers.

ITPro Today

November 12, 2007

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Looks like the bad guys are still using PERL bots and known exploits to infiltrate Web servers.

I found some log records that indicate a scan is in progress looking for weaknesses in various PHP apps. I've been seeing this activity for over a week on various Web servers.

After looking at the script it tries to inject into the server I noticed that it connects to IRC at hackbsd.net on port 6667, channel #owned. So I decided to login.

When you login to that IRC server you'll see a long list of "users" with the name prefixed with "zx". All of those zx system are servers that are now infected with the PERL bot, and the channel operators can issue system-level commands to the bots. Ouch.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like