Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

New trojan being used to launch attacks, send spam (Phatbot)
The Age ^ | 3/18/2004 | Sam Varghese

Posted on 03/18/2004 8:04:35 AM PST by Born Conservative

Malicious attackers have embraced a new tool that uses the peer-to-peer concept employed by file-sharing software to create bigger networks under their command, using which they can flood people with either malware or spams.

The new tool is a trojan which is being called Phatbot by security researchers. It links each computer it infects into a network and the attacker can then issue commands to the bot through any of the commandeered machines.

This effectively means that unless all the infected machines are shut down, the attacker can continue to issue instructions through those which have not been taken down.

The bot disables a large number of anti-virus software packages and commonly used firewalls. It tests the available bandwidth by posting large files to a number of web sites, according to an analysis by security services provider LURHQ.

The bot can steal AOL logins and passwords, steal CD keys for several popular games, harvest email both from the web and locally for the purpose of sending spam.

LURHQ senior security researcher Joe Stewart said in a posting to the incidents mailing list maintained by Security Focus, that he had heard reports that led him to believe that infections may be in the low hundreds of thousands.

"The question I would pose is: are those hundreds of thousands infected hosts actually part of the botnet at any given time? The WASTE P2P protocol the botnet uses is not built for large numbers of peers," he wrote.

Stewart said he had connected to some clients, examined the traffic passing through the node and found about 1000 unique nicknames in about an hour or so. "So, even though total infections may be high, the actual number of bots available to the owner at any one time is still in question in my mind," he wrote.


TOPICS: Business/Economy; Crime/Corruption; Technical
KEYWORDS: computersecurity; lowqualitycrap; microsoft; phatbot; spam; windows; worm

1 posted on 03/18/2004 8:04:37 AM PST by Born Conservative
[ Post Reply | Private Reply | View Replies]

FREE PC PROTECTION:
(Not an exhaustive list. Your results may vary. Void where prohibited. For entertainment purposes only. No wagering, please. Whattayawantfernuthin'.)

2 posted on 03/18/2004 8:06:02 AM PST by martin_fierro (Let's kill all the lawyers -- except mine)
[ Post Reply | Private Reply | To 1 | View Replies]

To: martin_fierro
I didn't know there was a miss internet.
3 posted on 03/18/2004 8:06:53 AM PST by cyborg (In die begin het God die hemel en die aarde geskape.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Born Conservative
BTTT
4 posted on 03/18/2004 8:07:11 AM PST by Fiddlstix (This Space Available for Rent or Lease by the Day, Week, or Month. Reasonable Rates. Inquire within.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Born Conservative
I thought Trojans(tm) were supposed to protect against viruses
5 posted on 03/18/2004 8:07:34 AM PST by rface (Ashland, Missouri -)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Born Conservative
Hope this one doesn't get to me before I ca
6 posted on 03/18/2004 8:10:05 AM PST by Liberty Valance (Keep a simple manner for a happy life :o)
[ Post Reply | Private Reply | To 1 | View Replies]

To: cyborg
I'm still tryin' to figure out what one has to do to become Miss Internet.

But you've got my vote. <|:)~

7 posted on 03/18/2004 8:12:19 AM PST by martin_fierro (Let's kill all the lawyers -- except mine)
[ Post Reply | Private Reply | To 3 | View Replies]

To: martin_fierro
LOL okay!
8 posted on 03/18/2004 8:14:11 AM PST by cyborg (In die begin het God die hemel en die aarde geskape.)
[ Post Reply | Private Reply | To 7 | View Replies]

To: martin_fierro
The new release 9.1 of Suse Linux is being discussed on Slashdot now.

The personal edition will come with a bootable CD so you can try out Linux without installing it. The list price will be $29.95. How can anyone resist?

(Note: Availble soon, but not yet)
9 posted on 03/18/2004 9:06:57 AM PST by proxy_user
[ Post Reply | Private Reply | To 2 | View Replies]

To: Born Conservative

10 posted on 03/18/2004 9:51:16 AM PST by Thoro (Gridlocked government is better than active government.)
[ Post Reply | Private Reply | To 1 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson