New Worms Sniff For Passwords

Published: 15 September 2004 y., Wednesday
According to Symantec and Trend Micro, the newest Sdbot variants--Symantec actually calls them "Spybot"--exploit several vulnerabilities in Windows, including the RPC DCOM flaw that was used by last summer's MSBlast and the LSASS vulnerability exploited by 2004's Sasser. Like both Sasser and MSBlast, Sdbot doesn't require user intervention to spread, but propagates across networks by finding unpatched systems. When Sdbot locates a vulnerable PC, it adds backdoor components that let the attacker control the machine. The worms also creates a bot that uses NetBEUI (NetBios Extended User Interface) to capture passwords for such software as the instant messaging clients from Yahoo, AOL and Microsoft. More important, however, is the addition of a network "sniffer" that monitors traffic on the local area network, specifically for log-on usernames and passwords. "If [Sdbot] can successfully transmit the filters packet captures back to the owner they are going to cause problems well beyond typical bot infestation," said Patrick Nolan, a researcher with the Internet Storm Center, in online advisory. The Sdbots can also install more generalized keyboard loggers and steal keys from a number of popular games, including Unreal Tournament 2004, Battlefield 1942 and NASCAR Racing 2003.
Šaltinis: TechWeb
Copying, publishing, announcing any information from the News.lt portal without written permission of News.lt editorial office is prohibited.

Facebook Comments

New comment


Captcha

Associated articles

China terminates 700 sites in porn crackdown

China's crackdown on pornograhy is gathering pace following reports that 700 Web sites have been shut down and 220 people arrested as authorities try to censor XXX sites more »

Clock speeds up

AMD to release Sempron early more »

Jabber Chats Up Gateway to IBM

Instant messaging software firm Jabber has outlined plans for an XMPP-to-SIP Gateway that opens the door for interoperability with IBM's Lotus IM product more »

Sloppy banks open the door to phishermen

A new vulnerability makes it easier for fraudsters to pass off content from bogus websites as the real thing more »

search.lt news

search.lt presents newest links more »

Microsoft's Ballmer hits out at "cloned" open source

Microsoft CEO Steve Ballmer has criticised the lack of innovation in open source software more »

Indian offshoring no threat yet to Europe's R&D

European 'variations' will prevent Indian players enjoying same success as in US more »

Internet Speaks and Shows

Speaking about an on-line broadcast we mean not only television, we speak about Internet too. In comparison to television the Internet allows us not only to see and hear on-line program broadcast, it allows to realize all our ideas and thoughts in practice. With only one button press we can enjoy a real time view of the wild Africans’ dances or the choppy Baltic Sea via Internet.

more »

Hungarian virus writer avoids jail

A Hungarian virus writer escaped prison yesterday after he was convicted of writing a virus that infected tens of thousands of Windows PCs more »

Ericsson delivers EDGE infrastructure in Estonia

Swedish telecomms solutions provider Ericsson said on Monday (28 June) that the Estonian mobile operator EMT had launched its commercial EDGE service by using infrastructure supplied by Ericsson more »