lilu ransomware for Linux servers

For interesting topics. But remember this is a Linux Forum. Do not post offensive topics that are meant to cause trouble with other members or are derogatory towards people of different genders, race, color, minors (this includes nudity and sex), politics or religion. Let's try to keep peace among the community and for visitors.

No spam on this or any other forums please! If you post advertisements on these forums, your account may be deleted.

Do not copy and paste entire or even up to half of someone else's words or articles into posts. Post only a few sentences or a paragraph and make sure to include a link back to original words or article. Otherwise it's copyright infringement.

You can talk about other distros here, but no MX bashing. You can email the developers of MX if you just want to say you dislike or hate MX.
Post Reply
Message
Author
User avatar
Richard
Posts: 1577
Joined: Fri Dec 12, 2008 10:31 am

lilu ransomware for Linux servers

#1 Post by Richard »

There is a new menace for Linux servers.
Looks like Linux has reached critical mass.

https://www.securitynewspaper.com/2019/ ... e-variant/

Since May, some 6700 servers have been held ransom for €294.xx Almost 2 million Euros.

What's the cure? So far, pay the ransom.
Thinkpad T430 & Dell Latitude E7450, both with MX-21.3.1
kernal 5.10.0-26-amd64 x86_64; Xfce-4.18.0; 8 GB RAM
Intel Core i5-3380M, Graphics, Audio, Video; & SSDs.

User avatar
Pierre
Posts: 310
Joined: Thu Apr 19, 2007 9:23 am

Re: lilu ransomware for Linux servers

#2 Post by Pierre »

Please use the check-mark icon to include [SOLVED] - when your problem is solved!
and DO LOOK at those Unanswered Topics - - you may be able to answer some!.

User avatar
JayM
Qualified MX Guide
Posts: 6793
Joined: Tue Jan 08, 2019 4:47 am

Re: lilu ransomware for Linux servers

#3 Post by JayM »

Here's the actual vulnerability that permits the ransomware to run as root and encrypt the files:
http://exim.org/static/doc/security/CVE-2019-15846.txt
It affects only mail servers using Exim that also have TLS enabled. Exim comes with TLS disabled by default but many distros' packages configure it as enabled.

So this isn't some kind of dire emergency situation that ordinary Linux desktop users need to worry about. It may possible affect your email service provider's server however, unless their sysadmins are keeping up with the latest security notices and patching their servers accordingly as they should be doing.
Please read the Forum Rules, How To Ask For Help, How to Break Your System and Don't Break Debian. Always include your full Quick System Info (QSI) with each and every new help request.

User avatar
Head_on_a_Stick
Posts: 919
Joined: Sun Mar 17, 2019 3:37 pm

Re: lilu ransomware for Linux servers

#4 Post by Head_on_a_Stick »

Richard wrote: Sun Sep 08, 2019 9:46 pm What's the cure?
Restore your backup. Any sysadmin who gets caught out by this deserves to pay, IMO.

The Debian exim4 package is fixed in stable & oldstable: https://security-tracker.debian.org/tra ... 2019-15846
mod note: Signature removed, please read the forum rules

User avatar
Richard
Posts: 1577
Joined: Fri Dec 12, 2008 10:31 am

Re: lilu ransomware for Linux servers

#5 Post by Richard »

Maybe that's why they aren't charging so much?
Thinkpad T430 & Dell Latitude E7450, both with MX-21.3.1
kernal 5.10.0-26-amd64 x86_64; Xfce-4.18.0; 8 GB RAM
Intel Core i5-3380M, Graphics, Audio, Video; & SSDs.

Post Reply

Return to “General”