On MovieTome: First Look: Jessica Alba in 'Machete'!
BNET Business Network:
BNET
TechRepublic
ZDNet

By Robert Lemos
Posted on ZDNet News: May 13, 2004 11:30:00 PM

Computers compromised by the Sasser worm may be vulnerable to a scavenging program that exploits a flaw in the software left behind by the worm, a security researcher said Thursday.

The worm--dubbed Dabber--has started spreading to Microsoft Windows systems, but likely won't have a large impact, said Joe Stewart, senior security researcher with network protection firm Lurhq.

"It is not going to be a big problem for anyone that is paying any attention at all to computer security," he said. "If somebody does get it, they probably already have Sasser and, most likely, Agobot as well."


Get Up to Speed on...
Enterprise security
Get the latest headlines and
company-specific news in our
expanded GUTS section.


Dabber is not the first worm to exploit back doors into compromised systems left behind by previous attackers. Two worms, Doomjuice and Deadhat, infected systems already compromised with the MyDoom virus.

However, Dabber may be the first worm to attack systems using a flaw in a previous malicious program. In this case, the file transfer protocol (FTP) server installed by Sasser to enable the worm to transfer itself to new hosts has a buffer-overflow vulnerability. Dabber uses that security flaw to spread to the new machine.

Click here to Play

David Berlind, executive editor, ZDNet

Once it copies itself to a new host, the worm will change the system settings so that operating system runs the malicious program every time it starts up. Dabber will also attempt to block other worms, which may have infected the machine, from running.

Finally, the worm will establish a back door into the software to allow knowledgeable attackers to take control of the system.

The scavenging worm arrives as German police are investigating more leads in the Sasser case. Already, the suspected author has been arrested in that country, based on information leaked to Microsoft by informants interested in reward money.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 25 Talkback(s)
hum, ho
okay, another anti-microsoft rant. what's new? (Read the rest)
Posted by: Valis Keogh Posted on: 05/15/04 You are currently: a Guest | | Terms of Use
it's like the ideal microsoft worm...  ryusen | 05/13/04
LOL!  Confused by religion | 05/13/04
Full marks ZZ  Franklin_z | 05/13/04
ZZ, I proudly doff the Fedora too you  Squawkbox | 05/13/04
*takes a bow*  ryusen | 05/14/04
Oh man...this whole thing is a big mess.  Linux_Developer | 05/13/04
this not a 'new' hole  toadlife | 05/13/04
Smug ignorance  jellyclock | 05/14/04
I think you're late for...  toadlife | 05/14/04
but.. in this case,  ryusen | 05/14/04
M$ a THREAT to world order! Use Linux now!  LinuxLover74 | 05/14/04
step away  Avatar28 | 05/14/04
If you disagree with me, you must be a paid criminal monopolist M$ shill!  LinuxLover74 | 05/14/04
oh yes  Avatar28 | 05/14/04
Got You!  John Dulles | 05/14/04
Ah, but if you disagree with me, you must be communist, anti-US, Muslim...  Sniper_z | 05/14/04
you must be new here...  ryusen | 05/14/04
Thats because....  LinuxLover74 | 05/14/04
now you are starting to sound microsoftish...  ryusen | 05/14/04
Ho, hum  Linux_Developer | 05/14/04
hum, ho  Valis Keogh | 05/15/04
Worms usually feed on dead things.. Like Microsoft's business model  Xunil_Sierutuf | 05/14/04
The Stats  john public | 05/14/04
Yup!  Linux User 147560 | 05/14/04
Hey, be careful what you say!  Linux_Developer | 05/14/04

What do you think?

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
Click Here