New Worms Sniff For Passwords

Published: 15 September 2004 y., Wednesday
According to Symantec and Trend Micro, the newest Sdbot variants--Symantec actually calls them "Spybot"--exploit several vulnerabilities in Windows, including the RPC DCOM flaw that was used by last summer's MSBlast and the LSASS vulnerability exploited by 2004's Sasser. Like both Sasser and MSBlast, Sdbot doesn't require user intervention to spread, but propagates across networks by finding unpatched systems. When Sdbot locates a vulnerable PC, it adds backdoor components that let the attacker control the machine. The worms also creates a bot that uses NetBEUI (NetBios Extended User Interface) to capture passwords for such software as the instant messaging clients from Yahoo, AOL and Microsoft. More important, however, is the addition of a network "sniffer" that monitors traffic on the local area network, specifically for log-on usernames and passwords. "If [Sdbot] can successfully transmit the filters packet captures back to the owner they are going to cause problems well beyond typical bot infestation," said Patrick Nolan, a researcher with the Internet Storm Center, in online advisory. The Sdbots can also install more generalized keyboard loggers and steal keys from a number of popular games, including Unreal Tournament 2004, Battlefield 1942 and NASCAR Racing 2003.
Šaltinis: TechWeb
Copying, publishing, announcing any information from the News.lt portal without written permission of News.lt editorial office is prohibited.

Facebook Comments

New comment


Captcha

Associated articles

Finland's Sonera Secures GSM License for Moscow Region

Sonic Duo, the Russian subsidiary of Finland's Sonera, has received a Russian Communications Ministry operator's license for GSM-900/1800 standard cellular services in Moscow and the surrounding region. more »

Outlook Users Bit By Another Love Bug

Just when it seemed safe to get back in the water a new virus is making life difficult for users of Microsoft Corp.'s Outlook e-mail program. more »

search.lt news

search.lt presents newest links more »

AOL 5.0 FINALLY ARRIVES FOR MAC

Mac users can finally stop feeling like second-class citizens if they're users of the world's most popular online provider. more »

Lessig warns of 'war' over Internet control

Professor Lawrence Lessig of Harvard University warned that in the move to broadband technologies, "we are at the beginning of a war" . more »

New worm won't bite most Macs

Mac users can spread the "NewLove" worm via e-mail, however, and it can infect Macs running Windows emulation products. more »

DOJ defends breaking up Microsoft

Justice and 19 states defend Microsoft breakup proposal in legal brief. more »

AltaVista aims to lure eyes from Google

AltaVista Wednesday unveiled Raging Search, a new search engine through which the portal will attempt to lure "high-end" Net veterans to its service. more »

New OS tops agenda for Apple conference

Chief executive Steve Jobs is expected to offer new details about Apple's forthcoming operating system, the OS X, when he kicks off Apple's annual developer forum Monday. more »

search.lt news

search.lt presents newest links more »