You are here: silicon.com > Software > Security Strategy

Security Strategy

Virus warning: Dabber picks up Sasser's scraps

Scavenger moves in...

By Robert Lemos

Published: 14 May 2004 09:05 GMT

Computers compromised by the Sasser worm may be vulnerable to a scavenging program that exploits a flaw in the software left behind by the worm, a security researcher said Thursday.

The worm - dubbed Dabber - has started spreading to Microsoft Windows systems, but likely won't have a large impact, said Joe Stewart, senior security researcher with network protection firm Lurhq.

"It is not going to be a big problem for anyone that is paying any attention at all to computer security," he said. "If somebody does get it, they probably already have Sasser and, most likely, Agobot as well."

Dabber is not the first worm to exploit back doors into compromised systems left behind by previous attackers. Two worms, Doomjuice and Deadhat, infected systems already compromised with the MyDoom virus.

However, Dabber may be the first worm to attack systems using a flaw in a previous malicious program. In this case, the file transfer protocol (FTP) server installed by Sasser to enable the worm to transfer itself to new hosts has a buffer-overflow vulnerability. Dabber uses that security flaw to spread to the new machine.

Once it copies itself to a new host, the worm will change the system settings so that operating system runs the malicious program every time it starts up. Dabber will also attempt to block other worms, which may have infected the machine, from running.

Finally, the worm will establish a back door into the software to allow knowledgeable attackers to take control of the system.

The scavenging worm arrives as German police are investigating more leads in the Sasser case. Already, the suspected author has been arrested in that country, based on information leaked to Microsoft by informants interested in reward money.

Robert Lemos writes for News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
Graduate Lead Generation Sales Executive

Regular in-house product and sales training, a sustained professional development programme and the potential to transfer to one of our overseas ...

1st / 2nd line support

Ensure incident records are updated regularly with events and action plans* Ensure customers are satisfied before resolving their requests* ...

Programme Manager - Solvency ll (Insurance)

Develop the detailed design, assessment and risk allocation processes for solvency capital and economic capital; to work closely with Finance, Risk ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: