Advertisement
Promo

Security threats Toolkit

Latest Phatbot angles for SQL server

Dawn Kawamoto CNET News

Published: 20 Apr 2004 09:25 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A new variant of the Phatbot worm may be on the loose and attempting to attack SQL Server ports, according to a warning that the SANS Institute issued on Monday.

Last month, Phatbot made the rounds, attacking Windows systems by acting as a Trojan horse. Phatbot would then link infected computers into an underground network for sending spam or launching other attacks. SANS is currently in the process of attempting to capture a full packet of data -- or an executable file -- for further analysis of Phatbot.

The worm probes Transmission Control Protocol ports 2745, 1025, 3127, 6129, 5000, 80 and 1433, as well as Microsoft's NetBIOS, according to the SANS report.

"There has also been conjecture that the port 1981 increase is potentially also connected to another variant of Phatbot," SANS noted in its handler's diary.

Phatbot relies on "peer to peer" technology, which makes it more difficult to eliminate, because there is no central command centre for its network.

"The Phatbot has been morphing and changing daily," said Marcus Sachs, director of SANS Internet Storm Centre. "We're conjecturing that this is another version of Phatbot."

Microsoft, meanwhile, said it has not received any new reports of the Phatbot worm, a company representative said.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
72 out of 125 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:



Video icon

Video

Sentry Posts Blog

DNA details of innocent will be kept f...

The government has announced that it plans to keep innocent people's DNA details for up to six years. In response to a consultation it launched last December, the government said... More

5 comments

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters