Skip to content
EntityQ127101· pop 9· linked from 65 articles

Staog was the first computer virus written for the Linux operating system. It was discovered in the autumn, October 20, of 1996, and the vulnerabilities that it exploited were fixed soon after. It has not been detected in the wild since its initial outbreak. The vulnerabilities exploited by Staog have been patched in all major Linux distributions, making the virus no longer a threat.

Wikidata facts

Show 2 more facts
publication date
1996-10-20
Sources (3)

via Wikidata · CC0

~1 min read

Article

3 sections
Contents
  • See also
  • References
  • External links

Staog was the first computer virus written for the Linux operating system. It was discovered in the autumn, October 20, of 1996, and the vulnerabilities that it exploited were fixed soon after. It has not been detected in the wild since its initial outbreak. The vulnerabilities exploited by Staog have been patched in all major Linux distributions, making the virus no longer a threat.

Staog manages to undermine the root access of the infected Linux system via three known kernel vulnerabilities: mount buffer overflow, tip buffer overflow and one suidperl bug, which allow it to remain resident on the system. Then, it would infect executed binaries. For tip command, since in early versions of Linux, it was often installed as a setuid root binary, which means it ran with root privileges even when executed by a normal user. Staog took advantage of that, along with the buffer overflow in tip to gain root privilege access to the system.

Available in 9 languages

via Wikidata sitelinks · CC0

Connections

Categories