Video | Business Headlines | GMOs / Biotech | IT | Science | Scientific Ethics | Technology | More Categories

 


Symantec discovers malicious code

Symantec discovers malicious code targeting Microsoft PCT vulnerability

Wed, 28 April 2004

Symantec has discovered malicious code that targets the Microsoft Windows Private Communications Transport Protocol (PCT) vulnerability. This vulnerability is present on unpatched Windows NT, 2000, XP and Windows Server 2003 systems.

The malicious code -- currently called backdoor.mipsiv -- opens ports on the victim's system, implements a denial-of-service attack against a third-party DNS server system and also receives command/control instructions via Internet Relay Chat (IRC) channels.

Symantec has detected attempts at compromising systems on our monitored global sensor network and has raised its ThreatCon Rating to Level 3 as a precautionary measure. Symantec Security Response experts are currently analyzing the heavily encrypted code and will provide more details as they become available. The team is also determining if the code is a worm or a bot. Bot -- short for roBot -- is a program used on the Internet that performs repetitive functions including searching for news or information.

"Symantec is currently analyzing automated sample code that takes advantage of the MS PCT vulnerability," said Vincent Weafer, senior director, Symantec Security Response. "We're seeing an increase in the number of exploits attempts and an increase in reconnaissance attacks through our DeepSight sensors and Managed Security Services devices . We highly encourage our customers to expedite their patching if they haven't already."

The Microsoft PCT vulnerability affects all IIS Web servers running Microsoft IIS with SSL enabled. Windows 2003 server is not vulnerable unless the PCT protocol has been enabled by the administrator. Users should install the patch immediately. If it is not possible, they can disable the PCT protocol in the registry. Additionally, vulnerability assessment and intrusion detection systems can be deployed to detect the presence of the vulnerability and/or the presence of the exploit. For more information about this vulnerability: http://securityresponse.symantec.com/avcenter/security/Content/10116.html.

ENDS

 
 
Business Headlines | Sci-Tech Headlines

 

The Ice: Antarctic Treaty Meeting Of Experts In Wellington

Around 80 delegates will be attending the meeting which will examine issues surrounding ship-borne tourism in the Antarctic Treaty Area. More>>

Medical: PHARMAC Comes In On Budget By Choosing Pills

Prescriptions for government funded medicines increased by almost 4 percent last year to 36.3 million, but the rate of that growth is slowing, drug buying agency PHARMAC says. More>>

Geography: Scientist Honoured With Frozen Feature

IRL senior scientist Dr Tim Haskell has joined an elite group of Antarctic explorers and scientists by having a geographic feature in the region named after him. More>>

Economic Indicators: Like Curate's Egg, Says English

The Treasury’s latest monthly economic indicators today provide a mixed view of the economy and reinforce risks around the shape of the recovery, Finance Minister Bill English says. More>>

ALSO:

$500,000 Fine: Telecom's Bands Were Not Broad Enough

Telecom New Zealand Limited has pleaded guilty to 17 charges of breaching the Fair Trading Act over claims made in 2006 when promoting Xtra’s Go Large broadband plan. Telecom has been fined $500,000 in the Auckland District Court today. More>>

ALSO:

Environment: Factory Dairy Farming Arrives In New Zealand

New Zealand is on the brink of introducing factory farming of dairy cows, the Green Party said today. Consent applications were recently lodged with Environment Canterbury for factory-style dairy farms in the Mackenzie Basin. More>>

ALSO:

Dairy: Call For Fonterra To Keep More Money

Federated Farmers welcomes Fonterra’s announcement of an annual retention but believes the amount retained by the cooperative is far too small. More>>

Smellie Sniffs The Breeze: The Trouble With Lists

The 2025 taskforce might have created an opportunity to break through to a new willingness to examine policy options, old and new, with fresh eyes. Instead, it was set up to fail... Which is tragic, because much of what the taskforce recommends is still pretty much what needs to happen. More>>

ALSO:

MOST READ HEADLINES

 
 
 
powered by newsagent
NZ independent news