Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Information-Security-News
[Top] [All Lists]

[ISN] Accused Zotob Hacker May Be Behind 21 Other Worms

Subject: [ISN] Accused Zotob Hacker May Be Behind 21 Other Worms
Date: Wed, 31 Aug 2005 03:02:05 -0500 (CDT)
http://informationweek.com/story/showArticle.jhtml?articleID=170101991

By Gregg Keizer 
TechWeb News 
Aug. 30, 2005 

More details are emerging about the hacker history of one of the two
men arrested last week on suspicion of creating and distributing the
Zotob bot worm earlier in August.

According to the analysis conducted by U.K.-based security vendor
Sophos, Farid Essebar, 18, also known as "Diabl0," may have written 20
variations of the Mytob mass-mailed worm and one version of the MyDoom
worm.

"It is not unusual for malware authors to leave their handles inside
their malicious code, sometimes alongside other messages," said Sophos
in a statement. The company said its researchers had found 21 other
worms with the Diabl0 handle included in their code.

Of the 21, 20 are Mytob variants, ranging from Mytob.a to Mytob.gz;  
two of Sophos' most recent Top 10 list of viruses and worms appear to
have been authored by Essebar, said Sophos.

"The Mytob worms have made a significant impact on the virus outbreak
charts this year, so anything which may prevent future variants from
being developed and released must be welcomed," said Graham Cluley,
senior technology consultant for Sophos, in a statement.

However, Cluley cautioned -- as have other analysts -- that it's
probable other hackers have access to the Mytob source code, a fact
that many think is the root cause of the more than 200 variants seen
so far this year.

"It appears whoever wrote Zotob had access to the Mytob source code,
ripped out the email-spreading section and plugged in the Microsoft
exploit," added Cluley.



_________________________________________
Attend ToorCon 
Sept 16-18th, 2005
Convention Center
San Diego, California
www.toorcon.org 

<Prev in Thread] Current Thread [Next in Thread>
  • [ISN] Accused Zotob Hacker May Be Behind 21 Other Worms, InfoSec News <=