ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

IM users hit by widespread 'social hack'

Matthew Broersma ZDNet.co.uk

Published: 20 Mar 2002 13:04 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security experts have warned that a wave of hack attacks is striking tens of thousands of PCs via instant messenger (IM) or Internet Relay Chat (IRC) clients, using nothing more high-tech than old-fashioned social engineering.

Hackers are using automated tools to send messages to random IM and IRC users, offering them a piece of software they might want or need, such as antivirus protection, improved music downloads or pornography, according to an advisory posted on Tuesday by CERT, a US government-funded security research body.

When the file is downloaded, however, it turns out to be malicious software that may expose confidential data or allow a hacker to take control of the victim's PC to help attack other Web servers, in what is known as a distributed denial-of-service (DDoS) attack.

A sample message runs as follows: "You are infected with a virus that lets hackers get into your machine and read ur files, etc. I suggest you to download [malicious url] and clean ur infected machine. Otherwise you will be banned from [IRC network]."

The downloaded software allows the hacker to take remote control of the victim's system, exposing confidential data, installing other malicious programs, and changing or deleting files. It also can co-opt the system into a DDoS attack, which uses a large number of computers distributed over the Internet to overload a target Web server with traffic, slowing or halting ordinary service on that Web site.

The tactics sound simple, and success depends on the user's decision to download the software. Even so, CERT says large numbers of systems have recently succumbed to the attacks, demonstrating that in some cases the oldest methods are the best. "Although this activity is not novel, the technique is still effective, as evidenced by reports of tens of thousands of systems being compromised in this manner," wrote CERT's Allen Householder.

"It's a part of every new threat we see," said Jack Clark, european product marketing manager for antivirus vendor Network Associates. "If you give anybody something they feel they need, it's plain old human nature to download it. The way we try to tackle it is just education."

In the early days of the Internet, for example, convicted hacker Kevin Mitnick famously stole confidential code from large companies by simply tricking staff into revealing network passwords. More recently, the rampant LoveLetter virus spread around the world in 2000 by posing as a valentine from a friend. And in a reversal to the usual form of socially engineered virus, last May a hoax email was passed on by well-meaning people warning recipients that their PCs may contain a virus called sulfnbk.exe. In fact, this file is not a virus but an essential part of the Windows operating system.

CERT recommends keeping antivirus software up to date, as well as general caution about downloading unknown files. "Users of IRC and IM services should be particularly wary of following links or running software sent to them by other users, as this is a commonly used method among intruders attempting to build networks of DDoS agents," Householder wrote.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
47 out of 108 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:













Related Jobs

C/C++ Software Engineer - 60,000 - London - C/C++ Software Engineer

The products owned by this team are used by tens of thousands of clients a day for analysis of securities of all asset-classes including Equities and ...

SAP PY Admin Manager - Central London

You will be responsible for running payroll for tens of thousands of employees and will be managing a team of approximately 4-5 consultants (you will ...

Support Engineer

Support and maintenance of the CSIS domain Software including: UNIX and Microsoft OS, SAN, Exchange, SQL and Antivirus software. Support Engineer - ...

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains