New Worms Sniff For Passwords

Published: 15 September 2004 y., Wednesday
According to Symantec and Trend Micro, the newest Sdbot variants--Symantec actually calls them "Spybot"--exploit several vulnerabilities in Windows, including the RPC DCOM flaw that was used by last summer's MSBlast and the LSASS vulnerability exploited by 2004's Sasser. Like both Sasser and MSBlast, Sdbot doesn't require user intervention to spread, but propagates across networks by finding unpatched systems. When Sdbot locates a vulnerable PC, it adds backdoor components that let the attacker control the machine. The worms also creates a bot that uses NetBEUI (NetBios Extended User Interface) to capture passwords for such software as the instant messaging clients from Yahoo, AOL and Microsoft. More important, however, is the addition of a network "sniffer" that monitors traffic on the local area network, specifically for log-on usernames and passwords. "If [Sdbot] can successfully transmit the filters packet captures back to the owner they are going to cause problems well beyond typical bot infestation," said Patrick Nolan, a researcher with the Internet Storm Center, in online advisory. The Sdbots can also install more generalized keyboard loggers and steal keys from a number of popular games, including Unreal Tournament 2004, Battlefield 1942 and NASCAR Racing 2003.
Šaltinis: TechWeb
Copying, publishing, announcing any information from the News.lt portal without written permission of News.lt editorial office is prohibited.

Facebook Comments

New comment


Captcha

Associated articles

Study: Interactive revolution will be televised

Infrastructure advances, coupled with growing consumer demand, are fostering a revolution in the emerging interactive television market more »

Philippines drops charges in 'ILOVEYOU' virus case

The Philippines on Monday dropped all charges against a computer school drop-out suspected of being responsible for the "love bug" virus. more »

search.lt news

search.lt presents newest links more »

Banner in Lithuania – the Same or Different?

Successful advertising of a website cannot be possible without small picture – banner. Western countries know this principle very well but to Lithuania it came recently. more »

Oracle steps up its e-business battle

Oracle will announce its next-generation flagship applications suite at a company event next week. more »

2 Firms To Offer Visa Cards On Web

LifeMinders, the Herndon-based provider of e-mail-based information and direct marketing services, announced a deal yesterday with the nation's largest Visa-card issuer to offer credit cards online. more »

Colleges spurn Metallica request to ban Napster

At least three renowned universities have decided against banning the use of the popular Napster digital music file-swapping software on their college campuses. more »

California governor vetoes Internet tax bill

California Gov. Gray Davis vetoed a bill that would have required sales tax on online purchases made by state residents. more »

10 Interesting and Useful Links about Lithuania

Some links about legislature and economy, culture, media, sports more »

InfoBalt Report

Infobalt Association organizes a special meeting more »