Troj/RSTDoor-A is a backdoor Trojan for Unix based platforms running PHP and HTTPD.
The Trojan accepts commands via HTTP request strings and allows remote attackers the ability to access and control the infected computer. Troj/RSTDoor-A also allows web based interface to control the backdoor functionality.
Troj/RSTDoor-A carries additional Perl and C source files that can be compiled or interpreted on command.
The Trojan can be instructed by remote attackers to perform various tasks, including:
- collect information from the infected computer, such as database servers, directory structures, files and permissions, etc.
- open a remote shell (BASH)
- upload/download arbitrary files
- execute arbitrary files
- scan for vulnerabilities
- change file attributes (owner, permissions)
- run arbitrary SQL commands
- send email
- start and FTP server
http://www.sophos.com/security/analy...jrstdoora.html
http://www.symantec.com/security_res...217-99&tabid=2