MSBLAST virus portable to Linux?

From: Mats (spamenot.mog.pettersson_at_telia.com)
Date: 08/13/03


Date: Wed, 13 Aug 2003 18:42:10 GMT

Since the MSBLAST virus uses an exploit in Windows RPC which is drived from
the OSF protocol (Open Software Foundation), is there any risk of getting a
virus ported to Linux/*NIX systems or is the exploit only in available in
the MS Windows binary? I mean, they might have *borrowed* some OSF code?

I quote Microsoft below:

----8<---
Remote Procedure Call (RPC) is a protocol used by the Windows
operating system. RPC provides an inter-process communication
mechanism that allows a program running on one computer to
seamlessly execute code on a remote system. The protocol itself
is derived from the OSF (Open Software Foundation) RPC protocol,
but with the addition of some Microsoft specific extensions.

There is a vulnerability in the part of RPC that deals with
message exchange over TCP/IP. The failure results because of
incorrect handling of malformed messages. This particular
vulnerability affects a Distributed Component Object Model (DCOM)
interface with RPC, which listens on TCP/IP port 135. This
interface handles DCOM object activation requests sent by client
machines (such as Universal Naming Convention (UNC) paths) to the
server.
---8<---



Relevant Pages

  • Re: MSBLAST virus portable to Linux?
    ... they might have *borrowed* some OSF code? ... ]"> Remote Procedure Call (RPC) is a protocol used by the Windows ... ]"> is derived from the OSF (Open Software Foundation) RPC protocol, ...
    (comp.os.linux.misc)
  • Re: MSBLAST virus portable to Linux?
    ... they might have *borrowed* some OSF code? ... "> Remote Procedure Call (RPC) is a protocol used by the Windows ... "> is derived from the OSF (Open Software Foundation) RPC protocol, ...
    (comp.os.linux.misc)
  • Re: rpc service
    ... Remote Procedure Call (RPC) is a protocol used by the Windows operating ... RPC is used by several components in Windows Server 2003 and Windows 2000 ...
    (microsoft.public.windows.server.setup)
  • [NEWS] Buffer Overrun In RPCSS Service Could Allow Code Execution
    ... Remote Procedure Call (RPC) is a protocol used by the Windows operating ... There are three newly identified vulnerabilities in the part of RPCSS ... Service that deals with RPC messages for DCOM activation- ...
    (Securiteam)
  • Re: Windows update failing
    ... Either malware is causing this, there's interference with the update servers and RPC due to a 3rd party add-on, or the entire issue was caused by Trend OR leftover files from McAfee. ... Can I download a BITS installer and overright? ... I don't think you can move system files from one Vista system to another as in previous Windows OS' due to security descriptors. ... 2/ I think I mentioned that I tried to do a BITS repair and that the repair tool advised that BITS repair was not required - sfc/scannow returns: ...
    (microsoft.public.windowsupdate)