Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Information-Security-News
[Top] [All Lists]

[ISN] Virus writers add network sniffer to worm

Subject: [ISN] Virus writers add network sniffer to worm
Date: Wed, 15 Sep 2004 00:56:57 -0500 (CDT)
http://www.theregister.co.uk/2004/09/14/network_sniffer_worm/

By John Leyden
14th September 2004 

Virus writers have grafted a network sniffer into the latest variant
of the SDBot worm series.

So far there are no reports of SDBot-UH in the wild but the inclusion
of selective network sniffing along with keystroke logging features
and other backdoor capabilities has security researchers worried.

Sniffers are designed to monitor network traffic. They are widely used
for network performance diagnostics but in this instance their
function has been turned to malign purposes. Bundling a network
sniffer with an auto-propagating worm makes it easier for hackers to
harvest usernames and passwords than would otherwise be the case.

The sniffing capabilities of SDBot-UH worm focus on phrases associated
with network logins and Paypal accounts. It also tries to steal the CD
keys of games, according to an advisory by AV firm Trend Micro.  
Patrick Nolan, a security researcher at the Internet Storm Center,
warns: "If the Trojans described by Trend can successfully transmit
the filter's packet captures back to the owner, they are going to
cause problems well beyond typical bot infestation issues."

SDBot-UH uses a variety of well-known Microsoft exploits to spread. It
also looks for weak usernames and passwords to gain access to target
machines. Malicious sniffers can be difficult to detect but Netcraft
points to a number of tools such as Sentinel and AntiSniff that can be
used to detect sniffers on a network. Individual users would do well
to check that their network card is not set in promiscuous (sniffing)  
mode.



_________________________________________
Donate online for the Ron Santo Walk to Cure Diabetes - 
http://www.c4i.org/ethan.html

<Prev in Thread] Current Thread [Next in Thread>
  • [ISN] Virus writers add network sniffer to worm, InfoSec News <=