4 ms·
This would make heartbleed and similar look like childsplay - this is a worm level attack if it's as bad as the title sounds. But given that redhat has so far
by problems 9y ago
This would make heartbleed and similar look like childsplay - this is a worm level attack if it's as bad as the title sounds.
But given that redhat has so far labelled themselves not vulnerable, I'm guessing there's more to it than the title lets on.
- sp332 9y agoWhat does worm level mean? I heard it in relation to heartbleed [or something] but couldn't figure out why it's worse than non-wormable.
- problems 9y agoBy worm level I mean it's a remote code execution attack which can be propagated over the internet. Someone can write a little piece of code that scans for random hosts, runs the attack and installs itself on the target system which then does the same until it's taken over all vulnerable hosts. It can self-replicate extremely fast. This was a huge issue back in the Blaster/Sasser days of early Windows XP when plugging in a machine to the internet directly was common. Servers and home routers are often plugged into the internet directly and often run Linux. So if this is easily exploitable it could turn into a real disaster. Heartbleed can't be turned into a worm because there's no code execution, just information disclosure, with this there is.
- cookiecaper 9y agoWorms are viruses that worm their way in to connected computers through the network without any action on the user's part, and then use newly-infected computers to worm through to others. Unlike many other viruses, you don't have to visit a page that runs an exploit, download a trojan, open an attachment, or do anything else to trigger it. Any computer that can contact the exploitable service can infect you (and will, if it has the worm too). "Worm-level" would call back to classic worm attacks where any computer connected to the internet and running Windows 2000/XP was at real risk of infection just by being connected. LAN/corporate networks could be infected if someone plugged an infected computer into the LAN, or if it spread through the DMZ. This type of attack doesn't happen very often anymore, as almost all home connections are firewalled by default, vendors have become more careful with security, etc.
- baq 9y agoThe original worm: https://en.m.wikipedia.org/wiki/Morris_worm https://en.m.wikipedia.org/wiki/Morris_worm
- jandrese 9y agoFrom what I can tell this is a local privilege escalation bug, not a "worm level" attack.