Forum Index

It appears you have not yet registered with our community which limits what you can do & see. It's Free To register, please click here.





Security Alerts and vulnerabilities Lets keep abreast on the latest threats by posting those findings here..

Reply
 
Thread Tools Display Modes
  #1  
Old 03-08-2005, 09:05 AM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,587
Send a message via ICQ to Mobo Send a message via AIM to Mobo Send a message via MSN to Mobo Send a message via Yahoo to Mobo Send a message via Skype™ to Mobo
By Gregg Keizer, TechWeb News

New worms spreading through MSN Messenger -- and its bundled-with-Windows Windows Messenger version -- via links to a malicious site are infecting users and leaving their PCs open to hacker hijack, security vendors reported Monday.

The new worms, tagged as Kelvir.a and Kelvir.b, appeared over the weekend and on Monday, respectively, anti-virus vendors said. Both use the same mechanism to attract users and infect Windows-based PCs: they include a link in the instant message. That link, in turn, downloads a malicious file -- the actual worm, a variant of the long-running Spybot -- which opens a backdoor to the compromised machine.

Kelvir spreads by sending itself to all the MSN/Windows Messenger contacts on the infected PC, and poses as cryptic messages such as "lol! see it! u'll like it!" and "omg this is funny!" The link opens a .pif-formatted file.

.pif files are also often a format-of-choice for mass-mailed worms.

Also on Monday, another worm -- dubbed Sumon.a by U.K.-based Sophos -- was discovered spreading via MSN/Windows Messenger. Sumon, which propagates over peer-to-peer file-sharing networks as well, is much more aggressive. It disables a long list of security software, tries to overwrite the HOSTS file so commonly-accessed security Web sites can't be reached, and picks from a large number of links, including "Fat Elvis! lol!" and "Crazy frog gets killed by train!" to entice downloads.

The boom in IM worms shouldn't come as a surprise: most security companies that made prognostications in late 2004 cited instant messaging as the next big attack avenue.

"The number of threats is increasing," said John Sakoda, the chief technology officer at IMLogic, an IM security and management vendor. "In January we had four high- or medium-risk IM threats, and in February, we had 11. So far in March, we've had four, which puts on a pace for well over 20."

IM, said Sakoda, is an unprotected channel in many enterprises, something hackers know and exploit. "For them, it's the path of least resistance."

Worse, IM exploits can spread extremely fast, faster than mass-mailed threats, and on par with the network-attacking exploits such as MSBlast of 2003 and Sasser of 2004. "Once [hackers] get it right, the speed with which the attack spreads is very quick."

Nor is it any surprise to Sakoda that MSN Messenger (and its Windows Messenger sibling) are the most frequent targets. "You have to remember where a lot of these worms originate," he said. "Overseas. And although AOL and Yahoo have much bigger market share here in the U.S., MSN is really the only one with a major global network."

But another reason -- one less well-known, said Sakoda -- is that Microsoft's IM clients, and its network, can be accessed through APIs. "They're embedded in the operating system, and allow experienced hackers a way to take over the MSN client." The experience hackers have in breaking down Windows also helps explain the high number of IM worms that exploit Microsoft's clients and network.

That's not what happened Monday. The Kelvir and Sumon worms are simple social-engineered worms; "low-hanging fruit," Sakoda called them. But earlier attacks, such as the Bropia worm, have used MSN Messenger's already-in-use processes to automatically execute worms. "That's very, very dangerous," said Sakoda.

Those are the kinds of threats that keep security experts like Sakoda up nights.

"It's as if the hackers got together and decided that this will be the year to try to add IM to their arsenal," he said.

IMLogic runs the IM Threat Center, a site that, in cooperation with anti-virus vendors including Symantec and Sophos, has been listing emerging IM and P2P exploits since December, 2004. The company also offers a free IM threat analyzer, called IM Detector Pro, for download from its site.
Reply With Quote
Posted


Reply

  • Submit Thread to Digg Digg
  • Submit Thread to del.icio.us del.icio.us
  • Submit Thread to StumbleUpon StumbleUpon
  • Submit Thread to Google Google
  • Bookmarks

    Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
     
    Thread Tools
    Display Modes

    Posting Rules
    You may not post new threads
    You may not post replies
    You may not post attachments
    You may not edit your posts

    BB code is On
    Smilies are On
    [IMG] code is On
    HTML code is Off
    Forum Jump

    Similar Threads
    Thread Thread Starter Forum Replies Last Post
    Msn Messenger 7.5.0299 23-8-05 LJM Master Software Update Alerts 0 08-27-2005 08:17 AM
    Worms Hellokitty_123 Spyware / Virus Removal 7 06-30-2005 07:47 AM
    Yahoo Messenger #2 Mobo Security Alerts and vulnerabilities 0 02-18-2005 02:00 PM
    Windows Messenger Mobo Software 0 12-17-2004 12:06 AM
    Windows Messenger Mobo Software Update Alerts 0 12-02-2004 05:58 PM



    All times are GMT -5. The time now is 02:22 PM.


    Firefox 2