New Worms Sniff For Passwords

Published: 15 September 2004 y., Wednesday
According to Symantec and Trend Micro, the newest Sdbot variants--Symantec actually calls them "Spybot"--exploit several vulnerabilities in Windows, including the RPC DCOM flaw that was used by last summer's MSBlast and the LSASS vulnerability exploited by 2004's Sasser. Like both Sasser and MSBlast, Sdbot doesn't require user intervention to spread, but propagates across networks by finding unpatched systems. When Sdbot locates a vulnerable PC, it adds backdoor components that let the attacker control the machine. The worms also creates a bot that uses NetBEUI (NetBios Extended User Interface) to capture passwords for such software as the instant messaging clients from Yahoo, AOL and Microsoft. More important, however, is the addition of a network "sniffer" that monitors traffic on the local area network, specifically for log-on usernames and passwords. "If [Sdbot] can successfully transmit the filters packet captures back to the owner they are going to cause problems well beyond typical bot infestation," said Patrick Nolan, a researcher with the Internet Storm Center, in online advisory. The Sdbots can also install more generalized keyboard loggers and steal keys from a number of popular games, including Unreal Tournament 2004, Battlefield 1942 and NASCAR Racing 2003.
Šaltinis: TechWeb
Copying, publishing, announcing any information from the News.lt portal without written permission of News.lt editorial office is prohibited.

Facebook Comments

New comment


Captcha

Associated articles

search.lt news

search.lt presents newest links more »

Microsoft Spent $100M on Trustworthy Computing

Microsoft's push to make its Windows operating system more secure cost the company more than $100 million so far this year more »

Computer Security Standards Ready

U.S. Agencies, Technology Firms Set Guidelines to Protect Against Hacking more »

Microsoft Set To Launch Windows XP Media Center

In another effort to encroach upon Apple's computer-as-entertainment strategy, Microsoft has announced its Windows XP Media Center Edition more »

Someone's Watching You: The Web's Secret Police

So far this year, the Motion Picture Association of America has sent nearly 50,000 complaints to ISPs worldwide and anticipates that number will reach 100,000 by the end of 2002 more »

search.lt news

search.lt presents newest links more »

Baltic Utilities X

Baltic Utilities X, a software package that provides Estonian, Latvian and Lithuanian language support for computers running the new Macintosh OSX operating system, has been released by DekSoft more »

Intel 2.8GHz Pentium 4 to Ship Early

Intel Corp. is pushing up the release of a 2.8GHz Pentium 4 to this summer in hopes of boosting sagging sales of its flagship PC processor, sources close to the company say more »

The Clouds of Digital War

Will the Next Terrorist Attack Be Delivered Via Cyberspace? more »

How One Spam Leads to Another

The quantity of e-mailed advertising pitches for different opportunities is about to increase dramatically more »