New Worms Sniff For Passwords

Published: 15 September 2004 y., Wednesday
According to Symantec and Trend Micro, the newest Sdbot variants--Symantec actually calls them "Spybot"--exploit several vulnerabilities in Windows, including the RPC DCOM flaw that was used by last summer's MSBlast and the LSASS vulnerability exploited by 2004's Sasser. Like both Sasser and MSBlast, Sdbot doesn't require user intervention to spread, but propagates across networks by finding unpatched systems. When Sdbot locates a vulnerable PC, it adds backdoor components that let the attacker control the machine. The worms also creates a bot that uses NetBEUI (NetBios Extended User Interface) to capture passwords for such software as the instant messaging clients from Yahoo, AOL and Microsoft. More important, however, is the addition of a network "sniffer" that monitors traffic on the local area network, specifically for log-on usernames and passwords. "If [Sdbot] can successfully transmit the filters packet captures back to the owner they are going to cause problems well beyond typical bot infestation," said Patrick Nolan, a researcher with the Internet Storm Center, in online advisory. The Sdbots can also install more generalized keyboard loggers and steal keys from a number of popular games, including Unreal Tournament 2004, Battlefield 1942 and NASCAR Racing 2003.
Šaltinis: TechWeb
Copying, publishing, announcing any information from the News.lt portal without written permission of News.lt editorial office is prohibited.

Facebook Comments

New comment


Captcha

Associated articles

SMART Comp. to Install Fiber-to-the-Home Optical Infrastructure in 6,600 Brno Homes with Cisco Technology

FTTH Network Provides High-Speed Internet, IPTV and VoIP Telephony in One. more »

Security guards trapped inside cash machine in Erdington

FIRE crews came to the rescue of two security guards who were trapped inside a cash machine for nearly two hours. more »

Wincor Nixdorf names new U.S. CEO

Wincor Nixdorf International has named Patrick Wright its new chief executive officer for the U.S. division. more »

Motorola and Deutsche Telekom Collaborate on IPTV

Deutsche Telekom selects Motorola’s IPTV set-tops for T-Home Entertain Services; users to receive compelling, rich media experiences. more »

Microsoft Unveils Its First Windows Embedded R&D Center in Europe

New regional development center in Germany is part of $75 million global investment by Windows Embedded Business. more »

Cisco Executive Promises Wave of Change at Meeting of Portuguese National Association for the Development of Telecommunications

Diogo Vasconcelos, the newly elected President of the Portuguese National Association for the Development of Telecommunications (APDC), has promised to transform the organisation's role in driving forward the country's digital agenda. more »

Microsoft Working to Make Political Conventions Unconventional

Microsoft is helping transform the upcoming Democratic and Republican national conventions into the most technologically advanced and inclusive conventions ever held. more »

Real-time fraud alerts notify Visa cardholders of ID theft

Visa and leading North American financial institutions have agreed to launch a pilot with up to 2,000 participants to test the delivery of real-time notification alerts on Visa accounts. more »

Wincor Nixdorf to provide ATMs to Australia's Banktech

Wincor Nixdorf International has secured a deal to provide ATMs to Banktech, an independent ATM provider in Australia. more »

Branch, ATM security moves toward more holistic solutions

Financial breaches and identity theft cases seem to be in the headlines on an almost regular basis. Just last month, hackers broke into a Citibank-branded ATM network and stole millions. more »