Skip to main content

JBellz

Classification

Category:

Malware

Type:

Trojan

Aliases:

  • JBellz
  • Trojan.Linux.JBellz

Summary

JBells is a trojan embedded into malformed MP3 files. The trojan uses a vulnerability in mpg123 which is a command-line MP3 player for Linux and other *NIX systems. When the trojanized MP3 is played with a vulnerable version of mpg123 a routine is started that deletes the current user's home directory and it's content.

The latest development version of mpg123 (0.59s) was tested and found to be vulnerable to this attack, while the latest stable version (0.59r) is not vulnerable.

The original exploit code generates ready to distribute trojanized MP3s for Suse 8.0 and Slackware 8.0 distributions.

Removal

Technical Details

The exploit code generates an MP3 file with malformed header that causes a buffer overflow in mpg123's header parsing code. The malicious buffer is constructed so that it calls a command shell with a one-line command that removes the user's home directory recursively.

Even though the original exploit contains settings for the distributions mentioned above it is unfortunately easy to modify the exploit code to affect other Linux distributions and versions as well. Because of this users of vulnerable mpg123 versions are advised to change their mpg123 to a non-vulnerable version, regardless of their distribution.

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.