Assata Shakur Speaks - Hands Off Assata - Let's Get Free - Revolutionary - Pan-Africanism - Black On Purpose - Liberation - Forum  

Assata Shakur Main Forum Portal Arcade Links/Downloads TTDC Search RBG Tube Warrior Chat Store Free Email Donate News
Go Back   Assata Shakur Speaks - Hands Off Assata - Let's Get Free - Revolutionary - Pan-Africanism - Black On Purpose - Liberation - Forum > Help, Suggestions And Security Center > P C Tech Advice & Technology
Forgot Password? Register

P C Tech Advice & Technology Post your PC related problems, share info related to the internet, test your avatars or images here.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 07-02-2008
Jahness's Avatar
OniOni Warrior
 
Join Date: Mar 2005
Location: In amerikkka! Stolen from Afrika!
Posts: 6,819
Thanks: 1,681
Thanked 1,112 Times in 695 Posts
Gender: Sister
Rep Power: 562
Jahness has a reputation beyond reputeJahness has a reputation beyond reputeJahness has a reputation beyond repute
Jahness has a reputation beyond reputeJahness has a reputation beyond reputeJahness has a reputation beyond reputeJahness has a reputation beyond repute
Arrow Trojan Lurks, Waiting to Steal Admin Passwords

Trojan Lurks, Waiting to Steal Admin Passwords

Trojan Lurks, Waiting to Steal Admin Passwords


Robert McMillan,
IDG News Service


Writers of a password-stealing Trojan horse program have found that a little patience can lead to a lot of infections.

They have managed to infect hundreds of thousands of computers-- including more than 14,000 within one unnamed global hotel chain-- by waiting for system administrators to log onto infected PCs and then using a Microsoft administration tool to spread their malicious software throughout the network.

The criminals behind the Coreflood Trojan are using the software to steal banking and brokerage account usernames and passwords. They've amassed a 50G-byte database of this information from the machines they've infected, according to Joe Stewart, director of malware research with security vendor SecureWorks.

"They've been able to spread throughout entire enterprises," he said. "That's something you rarely see these days."

Since Microsoft shipped its Windows XP Service Pack 2 software with its locked-down security features, hackers have had a hard time finding ways to spread malicious software throughout corporate networks. Widespread worm or virus outbreaks soon dropped off after the software's August 2004 release.

But the Coreflood hackers have been successful, thanks in part to a Microsoft program called PsExec, which was written to help system administrators run legitimate software on computers across their networks.

For a widespread infection, attackers must first compromise a system on the network by tricking the user into downloading their program. Then, when a system administrator logs onto that desktop machine-- to perform routine maintenance, for example-- the malicious software tries to run PsExec and install malware on all other systems on the network.

Often the technique succeeds.

Over the past 16 months, Coreflood's authors have infected more than 378,000 computers. SecureWorks has counted thousands of infections in university networks and has found financial companies, hospitals, law firms, and even a U.S. state police agency that have had hundreds of infections. "It's kind of insane how often they are getting on hundreds or thousands of computers at a single company," Stewart said. "They've probably stolen far more accounts than they can use."

The SANS Internet Storm Center reported one of the infections, which affected 600 machines on a 3,000 PC network, on June 25.

Malicious programs have used PsExec for more than five years, said the software's creator, Mark Russinovich, a Microsoft technical fellow. However, this is the first time he had heard of it being used in this fashion. "PsExec doesn't expose anything that a malware author can't code themselves or even accomplish with alternate mechanisms," he said in an e-mail interview. "Once you have credentials that give you local admin rights via remote access, you own that system."

Coreflood, which is also known as the AFcore Trojan, has been around for about six years. It has been used in the past for such things as launching denial-of-service attacks, but not to steal passwords, Stewart said.

Trojan Lurks, Waiting to Steal Admin Passwords - Yahoo! News

Copyright © 2008 PC World Communications, Inc.
__________________
Posted In The Spirit of Learning & Sharing
One Love & Respect Always

***************************************
The Quest for knowledge stops at the grave.
HIM Emperor Haile Selassie I.


If you fail to prepare,
you are preparing to fail!


Mind what you want, because someone wants your mind.

Working together, the ants ate the elephant.

Reply With Quote
Reply

Lower Navigation
Go Back   Assata Shakur Speaks - Hands Off Assata - Let's Get Free - Revolutionary - Pan-Africanism - Black On Purpose - Liberation - Forum > Help, Suggestions And Security Center > P C Tech Advice & Technology

Bookmarks

Tags
admin, lurks, passwords, steal, trojan, waiting


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Art of the Steal Jahness Open Forum 0 11-11-2008 11:48 AM
Is it okay to steal? IfasehunReincarnated Spirituality: Connect with your Center 48 01-29-2008 07:44 AM
Danger Lurks on Government Web Sites Jahness P C Tech Advice & Technology 0 10-07-2007 07:00 AM
Republicans Try Yet Again To Steal From The Poor Nia Imani Breaking Down and Understanding Our Enemies 0 11-29-2005 10:01 PM
Trojan Horse RecoveringAA P C Tech Advice & Technology 3 09-07-2005 08:22 PM


New To Site? Need Help?

All times are GMT -4. The time now is 04:22 PM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.2
The Talking Drum Collective
Page generated in 2.92270 seconds with 16 queries
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147