Computerworld
Quick Menu
Search



Ads by TechWords

See your link here


Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Finance
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
Computerworld 2007Subscribe to Computerworld
40 years of the most authoritative source of news and information for IT leaders.

Experts downplay Phatbot danger

 

Sign up to receive Security Resource Alerts

March 18, 2004 (IDG News Service) -- Security experts downplayed the danger of a Trojan horse program named Phatbot that uses peer to peer (P-to-P) technology to create a network of infected zombies for carrying out attacks or spreading malicious code.
Antivirus experts at two security companies said that Phatbot was a low level threat, one day after a Washington Post report warned of hundreds of thousands of infections from the program and cited an alert issued by the U.S. Department of Homeland Security (DHS).
"I think there are a lot of people getting very excited about something that's not very important," said Graham Cluley, senior technology consultant at Sophos PLC.
The DHS did not respond to a request for comment on Phatbot.
Trojan horse is a term used to describe malicious computer programs that hide inside other, benign software or run surreptitiously on a computer. Trojans can give remote attackers access to the machines on which they run or receive and respond to remotely issued commands.
Phatbot spreads by infecting computers running vulnerable versions of Microsoft Corp.'s Windows operating system. Phatbot can spot machines with a number of high profile Windows holes, including the DCOM (Distributed Component Object Model) vulnerability that spawned the Blaster worm. It can also find and infect machines that have an open "back door" created by the MyDoom worm, according to managed security services company Lurhq Corp.
When installed on infected machines, the Phatbot Trojan joins a P-to-P network similar to Kazaa or Gnutella. The network uses a specially developed communications protocol that allows infected computers to identify and communicate with each other, transmit commands and share infected files, said Joe Stewart, a senior security researcher at Lurhq.
The Phatbot software supports a long list of commands that can be used by remote attackers to cause infected machines to launch a denial of service attack, scan the Internet for vulnerable Windows computers to infect or update their Phatbot software. Phatbot-infected systems find each other using the same servers that clients running the Gnutella P-to-P software use, but use a different communications protocol and listen on a different communications port, which keeps them separate from the Gnutella clients, he said.
The remote control aspect of Phatbot makes it very similar to so-called "IRC bots," that use Internet Relay Chat software and servers to communicate, he said. However, unlike IRC bots, the Phatbot software does not rely on IRC servers to communicate with each other and coordinate their efforts, Stewart said.
"It gives [the Phatbot authors] the ability to be a little bit more discreet, because they don't have to connect to an IRC server where an administrator could notice and shut down their channel,"

Continued...
1 | 2 | NEXT  

Reprinted with permission from

IDG.net
Story copyright 2008 International Data Group. All rights reserved.


Print this Story Send Us Feedback E-mail this Story Digg! Digg this Story Slashdot this Story
"Yes, NASA has confirmed that some laptops taken to the International Space Station were infected with an online-gaming password stealing..." Read more...
"Linux is more secure than most operating systems, but Not if you don't practice basic security measures..." Read more...
Read more Security posts or See all Blogs
Microsoft warns of IE8 lock-in with XP SP3
Malware infects space station laptops
European court won't stop U.K. hacker's extradition to U.S.
Update: Google may let users comment on, rearrange search results
Apple forgets to fix iPhone passcode bug
Air traffic network glitch cleared up -- for now
As SSD factories explode, memory prices plummet
Judge lets privacy advocate keep Social Security numbers on Web site
Opinion: After the Core 2 Duo chip, what's next for Apple laptops?
Closing of EDS deal brings HP closer to rivals
More top stories...
Terror threat system crippled by technical flaws, says Congress
Microsoft reveals IE8 Beta 2
Veoh ruling bolsters YouTube effort to fend of $1 billion Viacom suit
Solid-state disk lackluster for laptops, PCs
iPhone gets two AT&T data plans for international travelers
Microsoft Office Live Small Biz suffers outage, possibly lost e-mail
McCain's online reach surges in days before Dem convention
Gold-medal cyclist leaned on Google Earth in training
Microsoft adds privacy tools to IE8
Here are 15 devices and add-ons that make the back-to-school computing experience extraordinary.
As Facebook-like apps infiltrate the enterprise, they're integrating the workforce in unforeseen ways.
If you want to expand the visual capabilities of your laptop, you can add two monitors without spending a lot of time or money.
The latest iteration of Asus' groundbreaking mini-notebook adds a faster CPU, a larger display and a better keyboard.
Reviews, analyses, how-tos, visual tours, hot issues and predictions about Microsoft's new OS.
Four years from now, the IT field will be a vastly different place. Will you be ready?
All Zones
Application Performance Zone
Business Continuity Zone
The File Data Management Zone
Security Management Zone
ITIL Best Practices Zone
The SAS Zone
Business Intelligence and Analytics Zone
Windows Protection Zone
Identity & Security Management Zone

Ads by TechWords

See your link here
From Laggard to Leader: Transforming the Data Center
From Laggard to Leader: Transforming the Data Center
Register for this complimentary live webcast today!
Go to the webcast 
Computerworld Executive Bulletin: Building a Robust Antivirus Defense
Download this Executive Bulletin (a $49.95 value) for free, compliments of MessageLabs.
(Source: MessageLabs) Antivirus software alone isn't enough to prevent today's speedy, sophisticated virus attacks. Security managers should consider multitiered approaches that include behavior scanning, appliances that check e-mail for worms, and restricting user access to dangerous Web sites. Download this Executive Bulletin (a $49.95 value) for free, compliments of MessageLabs, to learn more.
Download this executive briefing download
Online Security Issues in Regulated Industries
Download this research paper, free for a limited time, compliments of Webroot!
(Source: Webroot Software) In June 2008, Computerworld invited IT and business leaders to participate in a survey on online security initiatives at their organizations. The goal of the survey was to better understand Web and e-mail security issues faced today within the regulated education, financial services, government and health care industries. The following report represents top-line results of that survey.
Download this white paper go
White Papers
Read up on the latest ideas and technologies from companies that sell hardware, software and services.
Cut Data Center Energy Costs
Powering Change in the Data Center
Five Technologies Simplifying Infrastructure Management
View more whitepapers