Skip to main content

Worm Targets October Windows Flaw

posted onDecember 15, 2005
by hitbsecnews

The first worm that successfully attacks an October vulnerability in Microsoft Windows was spotted in the wild Thursday, a pair of security organizations said.

Both F-Secure and the SANS Institute's Internet Storm Center (ISC) said that the worm, dubbed Dasher.b, had been nabbed by the Honeypot Project, a German group that deploys exposed PCs to attract malicious code and capture samples. The worm exploits the MSDTC vulnerability disclosed by Microsoft in its October patch batch.

In late November, Microsoft issued a security advisory that acknowledged proof-of-concept code against the MSDTC bug was circulating, but said that the code couldn't actually execute remotely.

Dasher.b, however, uses that proof-of-exploit code to infect Windows 2000 and XP PCs, and then to download a keylogger from a remote server. The keylogger is cloaked by a rootkit, said F-Secure in an online alert. As of mid-Thursday, the remote server was online and operating.

Source

Tags

Viruses & Malware

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th