4/13: Spybot-NLX Worm Has DDoS Abilities |
 |
|
|
|
4/13: Spybot-NLX Worm Has DDoS Abilities April 13, 2005
W32.Spybot.NLX is a worm that has distributed denial of service and back door capabilities. The worm spreads through network shares protected by weak passwords and by exploiting the following vulnerabilities:
The Microsoft Windows DCOM RPC Interface Buffer Overrun Vulnerability (described in Microsoft Security Bulletin MS03-026).
The Microsoft Windows Local Security Authority Service Remote Buffer Overflow (as described in Microsoft Security Bulletin MS04-011).
The Microsoft Windows SSL Library Denial of Service Vulnerability (described in Microsoft Security Bulletin MS04-011).
The Vulnerabilities in the Microsoft SQL Server 2000 or MSDE 2000 audit (as described in Microsoft Security Bulletin MS02-061) using UDP port 1434.
The UPnP NOTIFY Buffer Overflow vulnerability (as described in Microsoft Security Bulletin MS01-059).
The Workstation Service Buffer Overrun vulnerability (as described in Microsoft Security Bulletin MS03-049) using TCP port 445. Windows XP users are protected against this vulnerability if Microsoft Security Bulletin MS03-043 has been applied. Windows 2000 users must apply MS03-049.
The DameWare Mini Remote Control Server Pre-Authentication Buffer Overflow vulnerability (described in CAN-2003-0960.)
Technical details can be found at Symantec page.
|
|
|
|
9/8: IRCBot-G Trojan Opens Backdoor
10/28: Backdoor.Futro a Server Program
4/7: Rbot-AAF Worm Hits Network Shares
10/21: Rbot-NG Worm Spreads Remotely
11/30: SymbOS/Skulls-B is a Trojan
Feds Bag Warez Convictions
6/7: Spybot-BZ Copies Itself to Folder
11/1: Fakepatch-A an Elf Executable
6/11: W32/Zafi-B Sets Registry Entry
10/27: Anpes Mass-Mailing Worm Uses Outlook
11/23: Backdoor.Sdbot.AH a Network-Aware Worm
Computer security background information
 |