Last night we received reports of a worm exploiting Solaris machines. The worm attempts to log into Solaris 10 systems by taking advantage of a security hole in its Telnet service, this bug was disclosed earlier this month in the famous security list Full-Disclosure.
According to US-CERT, the Telnet Daemon in Sun Solaris may accept authentication information through the USER environment variable.
The Problem lies in the daemon not being able to properly sanitize information before passing it to the login program, this login program can makes false interpretation of this information.
Because of this, a remote attacker may be able to bypass the login authentication and telnet. The sad thing with this exploit is that it is not need any exploit knowledge to be used for mass attacks.
We have already submitted the sample for detection and we will update you as soon as possible.
Update 03/01/2007 12:10 PM: The malware will be detected as WORM_WANUK.A.