VIRUS NAME: Linux/Exploit-Woot

Trojan Characteristics

The Linux/Exploit-Woot trojan was included inside a virus collector set that was sent to AVERT. The exploit code has not been encountered "in the wild".

This code is meant for the x86 Linux environments. It's portscanning a specified IP range for vulnerable targets.

Comments inside the source indicate that the exploit was written back in 2000.

Usually Unix malware is very flavor/version/kernel specific, newer versions and/or security updates address many exploits.

