The Web    www.100share.com    Google
 
4/13: Spybot-NLX Worm Has DDoS Abilities
 

4/13: Spybot-NLX Worm Has DDoS Abilities
April 13, 2005

W32.Spybot.NLX is a worm that has distributed denial of service and back door capabilities. The worm spreads through network shares protected by weak passwords and by exploiting the following vulnerabilities:

  • The Microsoft Windows DCOM RPC Interface Buffer Overrun Vulnerability (described in Microsoft Security Bulletin MS03-026).
  • The Microsoft Windows Local Security Authority Service Remote Buffer Overflow (as described in Microsoft Security Bulletin MS04-011).
  • The Microsoft Windows SSL Library Denial of Service Vulnerability (described in Microsoft Security Bulletin MS04-011).
  • The Vulnerabilities in the Microsoft SQL Server 2000 or MSDE 2000 audit (as described in Microsoft Security Bulletin MS02-061) using UDP port 1434.
  • The UPnP NOTIFY Buffer Overflow vulnerability (as described in Microsoft Security Bulletin MS01-059).
  • The Workstation Service Buffer Overrun vulnerability (as described in Microsoft Security Bulletin MS03-049) using TCP port 445. Windows XP users are protected against this vulnerability if Microsoft Security Bulletin MS03-043 has been applied. Windows 2000 users must apply MS03-049.
  • The DameWare Mini Remote Control Server Pre-Authentication Buffer Overflow vulnerability (described in CAN-2003-0960.)

    Technical details can be found at Symantec page.


  •  
  • 9/8: IRCBot-G Trojan Opens Backdoor
  • 10/28: Backdoor.Futro a Server Program
  • 4/7: Rbot-AAF Worm Hits Network Shares
  • 10/21: Rbot-NG Worm Spreads Remotely
  • 11/30: SymbOS/Skulls-B is a Trojan
  • Feds Bag Warez Convictions
  • 6/7: Spybot-BZ Copies Itself to Folder
  • 11/1: Fakepatch-A an Elf Executable
  • 6/11: W32/Zafi-B Sets Registry Entry
  • 10/27: Anpes Mass-Mailing Worm Uses Outlook
  • 11/23: Backdoor.Sdbot.AH a Network-Aware Worm
  • Computer security background information