Thousands 'trojaned' through net shares: CERT

CERT/CC, a US based group responsible for alerting the Internet community to security threats, has today warned that an increase in network share-based attacks may be paving the way for a distributed denial of service (DDoS) attack.

"Using these [network share based] techniques, many attackers have built sizeable networks of DDoS agents, each comprised of thousands of compromised systems," the advisory said.

The attacks have consisted of both manual and self-propagating worm style assaults. One worm to have used the technique is Deloder, which first began spreading over the weekend.

Although it barely popped up on the corporate radar as a direct threat, its success in compromising home user systems has been widespread. The worm uses poorly protected Windows network shares to compromise the targeted system, and then installs two Trojans.

It's the IRC "bot" Trojan that should be of serious concern to the online community, according to Matthew McGlashan, a security analyst with the University of Queensland's AusCERT security organisation.

An Internet Relay Chat (IRC) bot automatically connects back to an IRC chat channel and awaits commands from whoever created the worm.

"This is a total turn-around, [malicious hackers are] bringing the worms to them...the bot nets is where the action is at the moment," McGlashan said.

The author of the Deloder worm may have access to thousands upon thousands of DDoS "zombies" on the Internet waiting for the command to strike out at a target of choice. But McGlashen believes there would undoubtedly be turf wars over control of the slave systems, with rival malicious hacking groups trying to wrestle control of the networks from each other.

Although the exploitation of weak network shares is nothing new, the practice has in the past primarily targeted Windows 95/98/ME machines. The most recent attacks are taking aim at Windows NT/2000/XP machines, which according to CERT has "...resulted in the successful compromise of thousands of systems, with home broadband users' systems being a prime target". A plethora of these are becoming infected and pre-loaded with DDoS tools, they say.

McGlashan said that malicious hackers building networks of DDoS agents have become much better at taking aim on 'soft' targets, such as home users, because network shares are invariably firewalled at corporate network boundaries.

According to the CERT advisory, the "...problem is exacerbated by... intruders specifically targeting Internet address ranges known to contain a high density of weakly protected systems".

McGlashan said that although those infecting hosts with IRC bots are doing so with fairly new techniques, the number of hosts loaded up with them is on the rise.

"They haven't been able to distribute them this efficiently before," he said.

Advertisement

Talkback 1 comments

  1. Your article "Thousands 'trojaned' through net shares: CERT" is totally useless without a link to either CERT or somewhere that describes how to detect and remove this 'trojan'. Your article raises fears, but never references anything Full name -- 14/03/03

    Your article "Thousands 'trojaned' through net shares: CERT" is totally useless without a link to either CERT or somewhere that describes how to detect and remove this 'trojan'.

    Your article raises fears, but never references anything about how to find out more, how to protect oneself, or anything else.

    You might as well had run a headline "Be afraid now!" and nothing else.

    Don't waste my time or anyone else's with such crap.


ZDNet's CIO Vision Series

Customs | Murray Harrison, CIO

Australian Customs CIO Murray Harrison dislikes SLAs and runs away if a vendor talks to him about innovation. In this interview, he also explains why getting excited about gadgets can be dangerous and talks about how Customs' outsourcing strategy has evolved.

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Munir Kotadia iPhone suckers test our patience
    So how many of you have bought a 3G iPhone? Do you feel like a sucker? If you don't, maybe you will once your first bill arrives.
  • Array Westpac bank: AVG's toughest competitor
    The next time you're buying antivirus software, don't go direct to Symantec or McAfee. Don't download free antivirus. And definitely don't see Harvey Norman. Ask your bank — they're quite literally giving the stuff away.
  • Array Will you manage in the exabyte era?
    Mammoth growth in storage volumes is a fact of life, but even so it's helpful to pause occasionally and try and work out whether our information strategies have fallen hopelessly out of step with the pace of technological growth and changes in costs.
  • More blogs »

Tags

Back to top

Featured