Welcome | Sign In
LinuxInsider.com
Applications

E-Mail Scam Targets Red Hat Users

Print Version
E-Mail Article
Reprints
E-Mail Scam Targets Red Hat Users

Despite widespread attention, Ken Dunham, Director of Malicious Code at iDefense, characterizes the Linux Trojan as a low threat. "It looks like there was a low volume of e-mails that spread over a period of several days," he said.


Microsoft (Nasdaq: MSFT) users may feel as though they're the only ones constantly under attack from hackers, but they're not alone with that dubious distinction. Late last week, Red Hat (NYSE: RHT), the Raleigh, North Carolina-based Linux provider, was also hit.

The threat came in the form of a fake security warning. The e-mail alerts were sent from the address security@redhat.com, with a subject line that reads "RedHat: Buffer Overflow in 'Is' and 'mkdir.'" Recipients are directed to download an alleged patch, which in fact enables a remote attacker to execute malicious code with root privileges.

Warning to Users

Red Hat spokeswoman Leigh Cantrell Day provided the company's statement about the attack: "Official messages from the Red Hat security team are never sent unsolicited, are always sent from the address secalert@redhat.com, and are digitally signed by GPG. All official updates for Red Hat products are digitally signed and should not be installed unless they are correctly signed and the signature is verified." More details are available on Red Hat's Web site.

Despite widespread attention, Ken Dunham, Director of Malicious Code at iDefense, which provides security intelligence to governments and Fortune 500 organizations, characterizes the Linux Trojan as a low threat. "It looks like there was a low volume of e-mails that spread over a period of several days," he says.

Unfocused Attack

"While it does show that Linux is always on the mind of some, this attack seems to be fairly opportunistic and unfocused," Dunham added. Even non-Red Hat customers have reportedly received the e-mails.

According to Dunham, an attack such as this is not nearly as serious as ones that allow viruses to be downloaded from known, trusted sites. The update link given in the messages is "www.fedora-redhat.com." Red Hat sponsors The Fedora Project, a community-supported open-source project, but it is not a company product.

This is, Dunham said, by no means "the kind of organized, targeted, methodical attack that we've seen just seen in Brazil," where officials arrested more than 50 people in what they called a US$30 million Internet fraud. That scam involved infected e-mail Increase Customer Sales with Email Marketing -- Free Trial from VerticalResponse attachments that could store online bank account information and divert funds. Brazilian police have called the country home to eight out of 10 of the world's hackers.

The approach is nothing new, either. Last fall, Windows users were targeted with a mass-emailing about a security patch from Microsoft. These messages contained a virus that had the ability to steal account information and e-mail server details.


Print Version E-Mail Article Reprints More by Tina Harlan


More by Tina Harlan

Nintendo, Sony Add Audio, Video Features To Lure Gamers
December 15, 2004
The DS is currently a game-only device, but Nintendo said today that it will offer an adapter that allows an inserted memory card to play music in the MP3 format and video in the MPEG-4 format. The adapter, which will sell for about $47, will go on sale in February in Japan.
Apple Supplier Toshiba Builds 80 GB 'Perpendicular' Drive
December 14, 2004
Perpendicular recording places bits of data end-to-end, instead of using the traditional method of storing them flat on the disk surface. Since the bits essentially stand upright, they take up less space, allowing greater storage capabilities.
Home Theater Maker Kaleidescape Hit with Copyright Suit
December 09, 2004
Gartner's research indicates that U.S. consumers have certain expectations as to what fair use really is. "When we've surveyed teens and adults, we've found that at least 60 percent of both groups think that making a copy of a DVD or a CD for a personal backup or use in another device is legal," said Gartner analyst Mike McGuire.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network