OpenOffice worm hits Mac, Linux and Windows

update Malware targeting OpenOffice documents is spreading through multiple operating systems including Mac OS, Windows and Linux, according to Symantec.

According to the Symantec Security Response Web site, the worm is capable of infecting multiple operating system platforms and is spreading.

The advisory said: "A new worm is being distributed within malicious OpenOffice documents. The worm can infect Windows, Linux, and Mac OS X systems. Be cautious when handling OpenOffice files from unknown sources".

In an interview with ZDNet Australia on Thursday, Dr Jan Hruska, who co-founded rival antivirus firm Sophos and was one of the first ever PC antivirus experts, said that Apple Mac's are not a virus-free platform.

"Viruses on the Mac are here and now. They are available and they are moving around -- it is not as though the Mac is in some miraculous way a virus free environment.

"In terms of numbers, the number of viruses coming out for non-Mac platforms is higher. It gives a false impression that somehow Apple Macs are all virus free," said Hruska.

The worm was first spotted late last month but at the time, it was not thought to be "in the wild".

Once opened the OpenOffice file (badbunny.odg) launches a macro that behaves in several different ways depending on the user's operating system.

On Windows systems, it drops a file called drop.bad which is moved to the system.ini in the user's mIRC folder, while executing the Javascript virus badbunny.js that replicates to other files in the folder.

On Apple Mac systems, the worm drops one of two Ruby script viruses in files called badbunny.rb and badbunnya.rb.

On Linux systems, the worm drops both badbunny.py as an XChat script and badbunny.pl as a Perl virus.

Symantec rates the worm "Medium Risk".

Advertisement

Talkback 5 comments

    Bill Gates is behind thisJeffrey Henderson -- 09/06/07

    I'm pretty sure M$ is getting really desperate, and attacking OpenOffice is part of their new offensive strategy.

    Bad Bunny?Neil Anderson -- 10/06/07

    I'm pretty sure I dated her back in college.

    Neil Anderson
    http://www.cyclelogicpress.com

    Open Source is for the birdsAnonymous -- 12/06/07

    More proof that we need to avoid all open source offerings

    More proof that we need to avoid all open source offeringsAnonymous -- 24/01/09 (in reply to #320080869)

    NONSENS !
    the free World has to survive!

    Very IgnorantAnonymous -- 21/06/07

    Mac users hate hate hate OpenOffice for Mac, its stable version still runs under X11. No Mac users I know uses OpenOffice, they mostly use Microsoft Office, iWork, and NeoOffice. As for worms and viruses, how does this actually affect the host? It's 90% Java. Scripts are not viruses, they're scripts that automate things. On UNIX-based systems the damage is only to the user that runs the program, and since OpenOffice.org is userland, there is no doubt in my mind that the worm as you claim it is, is useless. It's easy to cleanup. Windows XP and 2000 users heed warning though, default administrator privileges are what'll get you. Unfortunately, until Vista has there been less emphisis on needing administrative ability.

Add your opinion


Latest Videos

Blogs

  • David Braue Will Rudd's bush backhaul bonanza deliver?
    Rural areas will be welcoming the government's decision to put its money where its politicising is, funnelling $250m into a regional fibre upgrade to six rural centres. Remedying over a decade of near-neglect at the hands of telecoms privatisation, the investment could be the firmest step yet for Labor's NBN dream — but with inevitable political questions and a looming election, Rudd and Conroy need to deliver, and quickly, to preserve the NBN's credibility.
  • Array Doing for AV what VoIP did for telephony
    Sydney-based start-up Audinate is making traditional analog cabling obsolete in favour of TCP/IP-based networking technology. And it's doing a pretty good job so far, with its technology used by World Youth Day and the Sydney Opera House.
  • Array WiMax in Australia: Part two
    WiMax could be the standard that drives the next phase of mobile broadband, it provides an opportunity for players wanting to establish a pure IP network to carry voice and data effectively — but is this what operators want?
  • More blogs »

Tags

Back to top

Featured