New Worms Sniff For Passwords

Published: 15 September 2004 y., Wednesday
According to Symantec and Trend Micro, the newest Sdbot variants--Symantec actually calls them "Spybot"--exploit several vulnerabilities in Windows, including the RPC DCOM flaw that was used by last summer's MSBlast and the LSASS vulnerability exploited by 2004's Sasser. Like both Sasser and MSBlast, Sdbot doesn't require user intervention to spread, but propagates across networks by finding unpatched systems. When Sdbot locates a vulnerable PC, it adds backdoor components that let the attacker control the machine. The worms also creates a bot that uses NetBEUI (NetBios Extended User Interface) to capture passwords for such software as the instant messaging clients from Yahoo, AOL and Microsoft. More important, however, is the addition of a network "sniffer" that monitors traffic on the local area network, specifically for log-on usernames and passwords. "If [Sdbot] can successfully transmit the filters packet captures back to the owner they are going to cause problems well beyond typical bot infestation," said Patrick Nolan, a researcher with the Internet Storm Center, in online advisory. The Sdbots can also install more generalized keyboard loggers and steal keys from a number of popular games, including Unreal Tournament 2004, Battlefield 1942 and NASCAR Racing 2003.
Šaltinis: TechWeb
Copying, publishing, announcing any information from the News.lt portal without written permission of News.lt editorial office is prohibited.

Facebook Comments

New comment


Captcha

Associated articles

DoCoMo On Track For 3G Launch Oct. 1

Japan's biggest wireless operator, NTT DoCoMo, Monday said it has formally asked the Japanese government for permission to begin the world's first commercial third-generation (3G) service on Oct. 1. more »

SirCam worm still a serious threat

Chalk one up for the bad guys. more »

An Escalation of the E-Book Battle

The battle over e-book sales heated up as Internet portal Yahoo! Inc. signed an e-book sales deal with four major publishing houses. more »

search.lt news

search.lt presents newest links more »

The debate

Public Interest Groups Clash With ICANN Over Governance more »

IBM Reaches Out to Small Businesses With $700 Server Offering

IBM threw its hat in the sub-$1,000 server ring with its release of the eServer x200VL, an entry-level server priced at $699. more »

XP Given Green Light in Europe

Despite increased pressure from the European Commission over antitrust concerns, Microsoft confirmed that the Commission will not seek to block the launch of Windows XP. more »

Hong Kong Police Arrest Porn Site Webmaster

Hong Kong police have arrested a 29-year-old Webmaster suspected of operating a pornographic Web site more »

European Commission changes tack on e-commerce law

Officials at the European Commission have made a spectacular turnabout on a proposed law governing cross-border Internet commerce in Europe more »

Data for Dollars...or Marks Resurfaces in Germany

Wireless customers in Germany will soon have the option of paying for wireless data as a premium service. more »