New Worms Sniff For Passwords

Published: 15 September 2004 y., Wednesday
According to Symantec and Trend Micro, the newest Sdbot variants--Symantec actually calls them "Spybot"--exploit several vulnerabilities in Windows, including the RPC DCOM flaw that was used by last summer's MSBlast and the LSASS vulnerability exploited by 2004's Sasser. Like both Sasser and MSBlast, Sdbot doesn't require user intervention to spread, but propagates across networks by finding unpatched systems. When Sdbot locates a vulnerable PC, it adds backdoor components that let the attacker control the machine. The worms also creates a bot that uses NetBEUI (NetBios Extended User Interface) to capture passwords for such software as the instant messaging clients from Yahoo, AOL and Microsoft. More important, however, is the addition of a network "sniffer" that monitors traffic on the local area network, specifically for log-on usernames and passwords. "If [Sdbot] can successfully transmit the filters packet captures back to the owner they are going to cause problems well beyond typical bot infestation," said Patrick Nolan, a researcher with the Internet Storm Center, in online advisory. The Sdbots can also install more generalized keyboard loggers and steal keys from a number of popular games, including Unreal Tournament 2004, Battlefield 1942 and NASCAR Racing 2003.
Šaltinis: TechWeb
Copying, publishing, announcing any information from the News.lt portal without written permission of News.lt editorial office is prohibited.

Facebook Comments

New comment


Captcha

Associated articles

Experts: Don't dismiss cyberattack warning

Security experts and two former CIA officials said today that warnings of cyberattacks by al-Qaeda against western economic targets should not be taken lightly more »

Intel, AMD Air Chip Advancements

Intel hit the ground running Monday by unveiling a dozen new additions to its Intel Xeon processor lineup more »

search.lt news

search.lt presents newest links more »

Feds Want to Extradite British Hacker

In an unusual move in an international hacking case, the U.S. government wants to extradite Gary McKinnon, a 36-year-old unemployed British computer administrator more »

BrideX worm bites Kaspersky Labs

In a bold move, a group of hackers launched a successful attack on the Web server of Russian computer security firm Kaspersky Labs Ltd. on Friday more »

search.lt news

search.lt presents newest links more »

A rapidly growing sector

Lithuania - a Perfect Place to Start for U.S. Businessmen in CEE Countries more »

Internet sites harry debtors

Frustrated firms use Web to shame clients who fail to pay bills more »

IBM relaunches PC division

Computing giant IBM has a new name and a new strategy for capturing market share in the PC business more »

search.lt news

search.lt presents newest links more »