PDA

View Full Version : SDBot worm evolves with network sniffer



globalhostinggroup
09-14-2004, 11:01 AM
Virus deviants have enhanced the SDBot with a network sniffer now called SDBot-UH
The sniffing capabilities of SDBot-UH worm focus on phrases associated with network logins and Paypal accounts. It also tries to steal the CD keys of games, according to an advisory by AV firm Trend Micro. Patrick Nolan, a security researcher at the Internet Storm Center, warns: "If the Trojans described by Trend can successfully transmit the filter's packet captures back to the owner, they are going to cause problems well beyond typical bot infestation issues."
SDBot-UH uses a variety of well-known Microsoft exploits to spread. It also looks for weak usernames and passwords to gain access to target machines. Malicious sniffers can be difficult to detect but Netcraft points to a number of tools such as Sentinel and AntiSniff that can be used to detect sniffers on a network. Individual users would do well to check that their network card is not set in promiscuous (sniffing) mode.

mikmik
09-14-2004, 11:40 AM
Globalhostinggroup, I appreciate the info, but could you provide the source for this stuff? It looks like you got this from an article. Maybe not, I don't know, but if so, do you have the link?

Thanks, man :O)

mushroom
09-14-2004, 01:27 PM
mikmik try these;
http://isc.sans.org/diary.php?date=2004-09-12
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.UH&VSect=T
http://news.netcraft.com/archives/2004/09/13/new_worm_installs_network_traffic_sniffer.html

mikmik
09-14-2004, 05:10 PM
Excellent!

Thanks, my man :O)