Advertisement
Promo

Security threats Toolkit

Sasser attacks provide fodder for new worm

Published: 14 May 2004 09:10 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Computers compromised by the Sasser worm may be vulnerable to a scavenging program that exploits a flaw in the software left behind by the worm, a security researcher said on Thursday.

The worm -- dubbed Dabber -- has started spreading to Microsoft Windows systems, but probably won't have a large impact, said Joe Stewart, senior security researcher with network protection firm Lurhq.

"It is not going to be a big problem for anyone that is paying any attention at all to computer security," he said. "If somebody does get it, they probably already have Sasser and, most likely, Agobot as well."

Dabber is not the first worm to exploit back doors into compromised systems left behind by previous attackers. Two worms, Doomjuice and Deadhat, infected systems already compromised with the MyDoom virus.

However, Dabber may be the first worm to attack systems using a flaw in a previous malicious program. In this case, the file transfer protocol (FTP) server installed by Sasser to enable the worm to transfer itself to new hosts has a buffer-overflow vulnerability. Dabber uses that security flaw to spread to the new machine.

Once it copies itself to a new host, the worm will change the system settings so that operating system runs the malicious program every time it starts up. Dabber will also attempt to block other worms, which may have infected the machine, from running.

Finally, the worm will establish a back door into the software to allow knowledgeable attackers to take control of the system.

The scavenging worm arrives as German police are investigating more leads in the Sasser case. Already, the suspected author has been arrested there, based on information leaked to Microsoft by informants interested in reward money.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
100 out of 153 people found this useful


Full Talkback thread

1 comment

  1. I worked for Virus Force Back in Bulgaria we must... Sergant V. Ivanov

Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

Post a comment

Beware of keeping your head in the clo...

Information security professionals can look forward to a deepening appreciation for their skills as security continues to be recognised as an essential element for doing business in... More

Post a comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters