New Worms Sniff For Passwords

Published: 15 September 2004 y., Wednesday
According to Symantec and Trend Micro, the newest Sdbot variants--Symantec actually calls them "Spybot"--exploit several vulnerabilities in Windows, including the RPC DCOM flaw that was used by last summer's MSBlast and the LSASS vulnerability exploited by 2004's Sasser. Like both Sasser and MSBlast, Sdbot doesn't require user intervention to spread, but propagates across networks by finding unpatched systems. When Sdbot locates a vulnerable PC, it adds backdoor components that let the attacker control the machine. The worms also creates a bot that uses NetBEUI (NetBios Extended User Interface) to capture passwords for such software as the instant messaging clients from Yahoo, AOL and Microsoft. More important, however, is the addition of a network "sniffer" that monitors traffic on the local area network, specifically for log-on usernames and passwords. "If [Sdbot] can successfully transmit the filters packet captures back to the owner they are going to cause problems well beyond typical bot infestation," said Patrick Nolan, a researcher with the Internet Storm Center, in online advisory. The Sdbots can also install more generalized keyboard loggers and steal keys from a number of popular games, including Unreal Tournament 2004, Battlefield 1942 and NASCAR Racing 2003.
Šaltinis: TechWeb
Copying, publishing, announcing any information from the News.lt portal without written permission of News.lt editorial office is prohibited.

Facebook Comments

New comment


Captcha

Associated articles

Microsoft gives details of software-for-rent strategy

Microsoft Friday popped the cork on its plans to sell software through subscriptions, rather than through licenses as it now does. more »

Microsoft ready to send 64-bit Windows 2000 to developers

Microsoft has completed a near-final version of its 64-bit edition of Windows 2000 that will be sent to all software developers with Itanium prototype computers. more »

Intel files suit against Intelnet

The Intel Corporation has filed a trademark legal suit against Intelnet, Inc., a firm which specialises in er... intelligent networks and fingerprint verification. more »

search.lt news

search.lt presents newest links more »

Pig farmer wins top UK dotcom award

A Somerset pig farmer has been crowned Britain's top dotcom business king. more »

Man Charged with Breaking Into NASA Computers

A 20-year-old man was arrested on Wednesday for allegedly breaking into two computers owned by NASA's Jet Propulsion Laboratory and using one to host Internet chat rooms devoted to hacking. more »

Who killed the PC?

Don't bury the beige box yet, analysts say. more »

IBM exceeds expectations with supercomputer

An IBM supercomputer designed for simulating nuclear explosions has turned out to be 23 percent faster than anticipated when the project began. more »

Vodafone boom in Europe

Vodafone AirTouch said Wednesday it added a record 6.6 million mobile phone customers in the second quarter. more »

The $144 Million Woman

Orange said Wednesday it paid 95 million pounds ($144 million) in cash for Web site Ananova, home to the first computer-generated newscaster. more »