LinuxWorld: Stopping the Ramen worm | Linux Today

LinuxWorld: Stopping the Ramen worm

Written By
Web Webster
Web Webster
Feb 7, 2001

“The Ramen worm targets Red Hat Linux systems specifically. It
searches the Internet piece by piece, looking for vulnerable Red
Hat boxes, and when it finds one it intrudes through a
vulnerability in one of three Linux programs: the Remote Procedure
Call service, the default file transfer protocol (FTP) service, or
the print service. Once inside, the worm installs a malicious
program on the compromised server, and spreads from there to other
Red Hat computers.”

“That sounds common enough. That’s how all worms work — a
specific vulnerability in a specific operating system is targeted,
and once a worm is let loose on the Internet, it compromises as
many computers running the operating system with that vulnerability
as it can find. What makes Ramen unique, though, is what the
program it installs does. Among other things, Ramen looks for
index.html files that it can overwrite.”

“How can the Ramen worm be stopped? The same way any other
worm is stopped: starve it. Administrators of all Linux and other
Unix-based systems must take the time to secure all servers in
their care.
While the Ramen worm targets Red Hat, the
vulnerabilities it exploits are present in other Linux
distributions, as well as in certain *BSD distributions. It is of
paramount importance that administrators stop putting Linux servers
on the Internet in a default installation. Basic hardening and
security measures must be taken first. If Linux administrators
cannot be more responsible in the future than those who are still
running a vulnerable rpc.statd, then the Ramen worm will continue
to flourish.”


Complete Story

Web Webster

Web Webster

Web Webster has more than 20 years of writing and editorial experience in the tech sector. He’s written and edited news, demand generation, user-focused, and thought leadership content for business software solutions, consumer tech, and Linux Today, he edits and writes for a portfolio of tech industry news and analysis websites including webopedia.com, and DatabaseJournal.com.

Linux Today Logo

LinuxToday is a trusted, contributor-driven news resource supporting all types of Linux users. Our thriving international community engages with us through social media and frequent content contributions aimed at solving problems ranging from personal computing to enterprise-level IT operations. LinuxToday serves as a home for a community that struggles to find comparable information elsewhere on the web.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.