New Worms Sniff For Passwords

Published: 15 September 2004 y., Wednesday
According to Symantec and Trend Micro, the newest Sdbot variants--Symantec actually calls them "Spybot"--exploit several vulnerabilities in Windows, including the RPC DCOM flaw that was used by last summer's MSBlast and the LSASS vulnerability exploited by 2004's Sasser. Like both Sasser and MSBlast, Sdbot doesn't require user intervention to spread, but propagates across networks by finding unpatched systems. When Sdbot locates a vulnerable PC, it adds backdoor components that let the attacker control the machine. The worms also creates a bot that uses NetBEUI (NetBios Extended User Interface) to capture passwords for such software as the instant messaging clients from Yahoo, AOL and Microsoft. More important, however, is the addition of a network "sniffer" that monitors traffic on the local area network, specifically for log-on usernames and passwords. "If [Sdbot] can successfully transmit the filters packet captures back to the owner they are going to cause problems well beyond typical bot infestation," said Patrick Nolan, a researcher with the Internet Storm Center, in online advisory. The Sdbots can also install more generalized keyboard loggers and steal keys from a number of popular games, including Unreal Tournament 2004, Battlefield 1942 and NASCAR Racing 2003.
Šaltinis: TechWeb
Copying, publishing, announcing any information from the News.lt portal without written permission of News.lt editorial office is prohibited.

Facebook Comments

New comment


Captcha

Associated articles

E-book challenge at Frankfurt fair

Readers could wave goodbye to carrying around heavy books with one of the portable electronic readers on display at the Frankfurt book fair. more »

Orchestral cellphones in Japan

Mobile phone owners in Japan – which means just about everyone – can now dial-a-concert whenever they feel like improving their mood with a tune or two. more »

Apple's $999 laptop

Apple cut the price of its entry level laptop, and unveiled a new line of aluminum clad machines. more »

Japan's human like new robots

The latest robots on display in Japan is proving machines may replace their human counterparts. Some are even helping save lives. more »

Lithuania Web Portal visited by citizens from states accounting for almost half of the world

The recently launched Lithuania Web Portal www.lietuva.lt has already been visited by the Internet users from ninety states. more »

Lithuania Web Portal visited by citizens from states accounting for almost half of the world

The recently launched Lithuania Web Portal www.lietuva.lt has already been visited by the Internet users from ninety states. more »

New Website to Take the Lead in the Online Live Music Webcast Market

Performancecast.tv is releasing their new website for LIVE Online Music Webcasts allowing bands of any stature to broadcast and promote their music world wide. Viewers watching the show can chat with other fans in real time and in some cases chat with the band all in a simple to use format. more »

No more boring Christian videos

GodTuner.com, a recently launched online Christian video-sharing community has been upgraded and is now offering Christians and ministries world-wide the ability to upload and host very high quality videos on their website. more »

Microsoft CEO in Europe

During a five-city tour of EMEA, encompassing Denmark, the UK, Norway, France, and Portugal, Steve Ballmer will meet with customers, partners, business and government leaders. more »

Wincor Nixdorf expands bank, ATM consulting service

Wincor Nixdorf AG has acquired a 51 percent interest in Bankberatung AG, which is based in Wedemark near Hanover, Germany. more »