New Worms Sniff For Passwords

Published: 15 September 2004 y., Wednesday
According to Symantec and Trend Micro, the newest Sdbot variants--Symantec actually calls them "Spybot"--exploit several vulnerabilities in Windows, including the RPC DCOM flaw that was used by last summer's MSBlast and the LSASS vulnerability exploited by 2004's Sasser. Like both Sasser and MSBlast, Sdbot doesn't require user intervention to spread, but propagates across networks by finding unpatched systems. When Sdbot locates a vulnerable PC, it adds backdoor components that let the attacker control the machine. The worms also creates a bot that uses NetBEUI (NetBios Extended User Interface) to capture passwords for such software as the instant messaging clients from Yahoo, AOL and Microsoft. More important, however, is the addition of a network "sniffer" that monitors traffic on the local area network, specifically for log-on usernames and passwords. "If [Sdbot] can successfully transmit the filters packet captures back to the owner they are going to cause problems well beyond typical bot infestation," said Patrick Nolan, a researcher with the Internet Storm Center, in online advisory. The Sdbots can also install more generalized keyboard loggers and steal keys from a number of popular games, including Unreal Tournament 2004, Battlefield 1942 and NASCAR Racing 2003.
Šaltinis: TechWeb
Copying, publishing, announcing any information from the News.lt portal without written permission of News.lt editorial office is prohibited.

Facebook Comments

New comment


Captcha

Associated articles

Net Access Through The TV Looking Glass

At last week's Western Cable Show, Microsoft's Ultimate TV and America Online's AOLTV made it clear that the future is here. more »

Net use growing for campaign news

Readers prefer traditional news outlets to campaigns’ sites more »

search.lt news

search.lt presents newest links more »

Antivirus firm says Shockwave virus spreading quickly

An email computer virus that comes concealed as a Net movie hit several U.S.-based companies Friday afternoon, leading at least one antivirus company to upgrade its threat assessment from "medium" to "high" risk. more »

Two-way pager designed by AOL

America Online Inc. unveiled a two-way paging device designed for access to AOL e-mail and instant messaging services. more »

Internet use rising fast in Europe

Japan attempts online expansion to boost lagging economy more »

Expert Confirms WAP Users' Fears

In a report published Thursday, usability expert Jakob Nielsen has confirmed what WAP users have long suspected -- WAP doesn't work. more »

Europe Taking Part in Holiday E-Commerce

Forrester Research expects European consumers will spend 2.6 billion Euros online during the 2000 holiday season more »

Pentium 4 fails to outpace Athlon, testers say

Intel's initial Pentium 4 chips released Monday don't provide a real performance advantage and are often slower when compared with the fastest Athlon chips from Advanced Micro Devices, benchmark testers and analysts say. more »

search.lt news

search.lt presents newest links more »