Video | Business Headlines | Internet | Science | Scientific Ethics | Technology | Search

 


Symantec has further analysed the Mydoom.M threat

Wed, 28 July 2004

Symantec has further analysed the Mydoom.M threat and has discovered some previously undocumented functionality. This functionality includes a mechanism that is used to maintain a list of all known infected systems, and permits the worm's author to upload updated binaries while prohibiting others from rapidly taking over the infected systems. This mechanism permits the author to rapidly and automatically update all Mydoom.M-infected systems with new arbitrary malicious code with little risk of its network being hijacked by rival worm authors.

Symantec Security experts have also re-examined W32.Mydoom.L@mm and found it also contains a system designed to maintain a list of all known infected systems, and to permit its author to upload update executables, while making it difficult for others to takeover the infected network.

"Due to the recent release and widespread infection rate of the Mydoom.M worm, we believed that computers infected with Mydoom.L may have been used as a form of peer-to-peer seed network, explaining why Mydoom.M became a high-profile worm so rapidly," said Alfred Huger, senior director, Symantec Security Response. "This process would simply require the author to upload Mydoom.M to one infected host and have it read the stored IP list and upload itself to other systems."

The Symantec Security Response team is currently investigating the functionality available within these worms. Symantec experts believe that the malicious code writer is using these threats to inject other new malicious code into the wild. One such malicious code is W32.Zindos.A.

This new threat discovered by Symantec Security Response this morning is exploiting the backdoor left by Mydoom.M. The new worm, created by the Mydoom virus writer, attempts to perform a DoS attack against the domain, Microsoft.com. W32.Zindos.A was discovered this morning and has been rated as a Category 2 threat. For detailed information on this latest threat, visit http://securityresponse.symantec.com/avcenter/venc/data/w32.zindos.a.html.

Symantec experts believe that the author of these threats is using W32.Zindos.A to update the Mydoom variants. Through Symantec's DeepSight early warning solutions, which include a network of 20,000 sensors monitoring IDS and firewall activity around the globe, Symantec has detected a spike in activity -- three degrees from normal deviation targeting TCP port 1034 and 1042, which are associated with W32.Mydoom.M@mm and W32.Mydoom.L@mm respectively.

Symantec Security Response recommends users to update the AV definitions, block access to TCP port 1034 and 1042 on all systems and deploy attachment filters on all e-mail gateway systems. Additionally, do not open or execute files from unknown sources. Using a firewall or IDS may block or detect back door server communications with the remote client application

ENDS


© Scoop Media

 
 
 
 
 
Business Headlines | Sci-Tech Headlines

 

Sky City : Auckland Convention Centre Cost Jumps By A Fifth

SkyCity Entertainment Group, the casino and hotel operator, is in talks with the government on how to fund the increased cost of as much as $130 million to build an international convention centre in downtown Auckland, with further gambling concessions ruled out. The Auckland-based company has increased its estimate to build the centre to between $470 million and $530 million as the construction boom across the country drives up building costs and design changes add to the bill.
More>>

ALSO:

RMTU: Mediation Between Lyttelton Port And Union Fails

The Rail and Maritime Union (RMTU) has opted to continue its overtime ban indefinitely after mediation with the Lyttelton Port of Christchurch (LPC) failed to progress collective bargaining. More>>

Earlier:

Science Policy: Callaghan, NSC Funding Knocked In Submissions

Callaghan Innovation, which was last year allocated a budget of $566 million over four years to dish out research and development grants, and the National Science Challenges attracted criticism in submissions on the government’s draft national statement of science investment, with science funding largely seen as too fragmented. More>>

ALSO:

Scoop Business: Spark, Voda And Telstra To Lay New Trans-Tasman Cable

Spark New Zealand and Vodafone, New Zealand’s two dominant telecommunications providers, in partnership with Australian provider Telstra, will spend US$70 million building a trans-Tasman submarine cable to bolster broadband traffic between the neighbouring countries and the rest of the world. More>>

ALSO:

More:

Statistics: Current Account Deficit Widens

New Zealand's annual current account deficit was $6.1 billion (2.6 percent of GDP) for the year ended September 2014. This compares with a deficit of $5.8 billion (2.5 percent of GDP) for the year ended June 2014. More>>

ALSO:

Still In The Red: NZ Govt Shunts Out Surplus To 2016

The New Zealand government has pushed out its targeted return to surplus for a year as falling dairy prices and a low inflation environment has kept a lid on its rising tax take, but is still dangling a possible tax cut in 2017, the next election year and promising to try and achieve the surplus pledge on which it campaigned for election in September. More>>

ALSO:

Job Insecurity: Time For Jobs That Count In The Meat Industry

“Meat Workers face it all”, says Graham Cooke, Meat Workers Union National Secretary. “Seasonal work, dangerous jobs, casual and zero hours contracts, and increasing pressure on workers to join non-union individual agreements. More>>

ALSO:

Get More From Scoop

 
 
Standards New Zealand

Standards New Zealand
 
 
 
 
 
 
 
 
Sci-Tech
Search Scoop  
 
 
Powered by Vodafone
NZ independent news