4/13: Spybot-NLX Worm Has DDoS Abilities |
 |
|
|
|
4/13: Spybot-NLX Worm Has DDoS Abilities April 13, 2005
W32.Spybot.NLX is a worm that has distributed denial of service and back door capabilities. The worm spreads through network shares protected by weak passwords and by exploiting the following vulnerabilities:
The Microsoft Windows DCOM RPC Interface Buffer Overrun Vulnerability (described in Microsoft Security Bulletin MS03-026).
The Microsoft Windows Local Security Authority Service Remote Buffer Overflow (as described in Microsoft Security Bulletin MS04-011).
The Microsoft Windows SSL Library Denial of Service Vulnerability (described in Microsoft Security Bulletin MS04-011).
The Vulnerabilities in the Microsoft SQL Server 2000 or MSDE 2000 audit (as described in Microsoft Security Bulletin MS02-061) using UDP port 1434.
The UPnP NOTIFY Buffer Overflow vulnerability (as described in Microsoft Security Bulletin MS01-059).
The Workstation Service Buffer Overrun vulnerability (as described in Microsoft Security Bulletin MS03-049) using TCP port 445. Windows XP users are protected against this vulnerability if Microsoft Security Bulletin MS03-043 has been applied. Windows 2000 users must apply MS03-049.
The DameWare Mini Remote Control Server Pre-Authentication Buffer Overflow vulnerability (described in CAN-2003-0960.)
Technical details can be found at Symantec page.
|
|
|
|
8/20: Rbot-GS Exploits Vulnerabilities
6/28: Agobot-KE Exploits Weak Passwords
Another University Suffers Security Breach
Windows Server 2003: Hardware-Based Security
9/2: Trojan Yipid Sends Chinese Email
Symantec Offers Enhanced Portal for Enterprises
HP Cuts to the Middle of Disaster Recovery
4/5: Bdoor-ZAT Trojan Opens Backdoor
11/4: Rbot-OX Worm Has IRC Functions
Sun, Partners Develop Security Appliances
New Tool Streamlines Management of Personal Identity Data
Computer security background information
 |