Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [ISN] 'Playboy' Virus Dropping Dangerous Backdoor |
|---|---|
| Date: | Mon, 13 Dec 2004 03:56:33 -0600 (CST) |
http://www.eweek.com/article2/0,1759,1738912,00.asp By Ryan Naraine December 10, 2004 Anti-virus vendors have raised the alarm for a new mass-mailing worm with a dangerous backdoor component. The worm, called W32.Maslan.C@mm, arrives as an attachment promising naked photos of Playboy models but, if executed, drops an IRC (Inter Relay Chat) bot capable of transmitting passwords and sensitive information back to the virus writer. According to an alert from McAfee, the backdoor is powerful enough to terminate the processes of various anti-virus security applications. The worm also spreads itself via poorly secured network shares and weak passwords and takes advantage of two known exploits?LSASS and RPC-DCOM?affecting Microsoft Windows users. Patches for both exploits have been available for some time, but unpatched machines are vulnerable to worm infection. According to Sophos, Maslan-C copies itself to the Windows system folder and creates a number of other files on the computer which make up the components of the worm. It constructs messages using its own SMTP engine and harvests target e-mail addresses from the victim's machine. The worm uses several masking techniques including spoofed sender addresses and has been programmed to monitor Internet Explorer browser sessions to capture data relating to various financial sites. An advisory from Symantec rates the risk as low, but distribution remains high. The use of naked celebrity images as a virus infection tactic is nothing new. In the past, virus writers have attached the names of celebrities such as Anna Kournikova, Britney Spears and Halle Berry to mass-mailing worms. _________________________________________ Open Source Vulnerability Database (OSVDB) Everything is Vulnerable - http://www.osvdb.org/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [ISN] DOD organizes network command, InfoSec News |
|---|---|
| Next by Date: | [ISN] Linux Advisory Watch - December 10th 2004, InfoSec News |
| Previous by Thread: | [ISN] DOD organizes network command, InfoSec News |
| Next by Thread: | [ISN] Linux Advisory Watch - December 10th 2004, InfoSec News |
| Indexes: | [Date] [Thread] [Top] [All Lists] |