The Web    www.100share.com    Google
 
4/13: Spybot-NLX Worm Has DDoS Abilities
 

4/13: Spybot-NLX Worm Has DDoS Abilities
April 13, 2005

W32.Spybot.NLX is a worm that has distributed denial of service and back door capabilities. The worm spreads through network shares protected by weak passwords and by exploiting the following vulnerabilities:

  • The Microsoft Windows DCOM RPC Interface Buffer Overrun Vulnerability (described in Microsoft Security Bulletin MS03-026).
  • The Microsoft Windows Local Security Authority Service Remote Buffer Overflow (as described in Microsoft Security Bulletin MS04-011).
  • The Microsoft Windows SSL Library Denial of Service Vulnerability (described in Microsoft Security Bulletin MS04-011).
  • The Vulnerabilities in the Microsoft SQL Server 2000 or MSDE 2000 audit (as described in Microsoft Security Bulletin MS02-061) using UDP port 1434.
  • The UPnP NOTIFY Buffer Overflow vulnerability (as described in Microsoft Security Bulletin MS01-059).
  • The Workstation Service Buffer Overrun vulnerability (as described in Microsoft Security Bulletin MS03-049) using TCP port 445. Windows XP users are protected against this vulnerability if Microsoft Security Bulletin MS03-043 has been applied. Windows 2000 users must apply MS03-049.
  • The DameWare Mini Remote Control Server Pre-Authentication Buffer Overflow vulnerability (described in CAN-2003-0960.)

    Technical details can be found at Symantec page.


  •  
  • 8/20: Rbot-GS Exploits Vulnerabilities
  • 6/28: Agobot-KE Exploits Weak Passwords
  • Another University Suffers Security Breach
  • Windows Server 2003: Hardware-Based Security
  • 9/2: Trojan Yipid Sends Chinese Email
  • Symantec Offers Enhanced Portal for Enterprises
  • HP Cuts to the Middle of Disaster Recovery
  • 4/5: Bdoor-ZAT Trojan Opens Backdoor
  • 11/4: Rbot-OX Worm Has IRC Functions
  • Sun, Partners Develop Security Appliances
  • New Tool Streamlines Management of Personal Identity Data
  • Computer security background information