Skip to content

Biting the hand that feeds IT

The Register ®

Security:


Related Whitepapers

[Print][Mobile][Alerts]

Hackers control bot client over P2P

Nugache

Published Tuesday 2nd May 2006 14:38 GMT

Security watchers are warning of a new worm that's propagating over instant messenger networks run by both AOL and MSN. Nugache-A is also spreading (albeit modestly) as an infected email that uses a variety of well-known Windows exploits to infect vulnerable Windows PCs.

If successful, the worm opens a back door that leaves compromised PCs as zombies under the control of hackers. The command and control channel technique used by the worm is unusual. Instead of a static list, the worm connects to infected peers, web security firm Websense reports. The SANS Institute's Internet Storm Centre (ISC) adds that the bots talk to each other via port 8/TCP over an encrypted P2P channel.

"A peer-to-peer command and control channel makes it more difficult to block commands issued to the bot. The traffic over this channel also uses obfuscation in an attempt to bypass intrusion detection systems," Websense reports. Additional information on the worm, and how to guard against attack, can be found in ISC's advisory here. ®

Track this type of story as a custom Atom/RSS feed or by email.
Previous Article Next Article
  • Microsoft System Center - Designed For Big
  • Meet the fast-growing demand for notebooks with HP
  • Find out how to eradicate 99.7% of spam, click here
  • From small embedded OS to the world's most used open mobile OS
whitepaper title

Gartner Paper: US Data Centers - The Calm Before the Storm

U.S. enterprise data centers face considerable space and energy constraints over the next few years. Download this free independent report to read more..
whitepaper title

Making Green IT a Reality

Customer Perspectives on the Impact of Storage Vendor Decisions on Power, Cooling, & Space in Enterprise Data Centers.
Whitepapers Jobs

Top 20 storiesAll The Week’s HeadlinesArchiveSearch