427 Botnet fm qxd



Download 6,98 Mb.
Pdf ko'rish
bet95/387
Sana03.12.2022
Hajmi6,98 Mb.
#878307
1   ...   91   92   93   94   95   96   97   98   ...   387
Bog'liq
Botnets - The killer web applications

www.syngress.com
110
Chapter 4 • Common Botnets
Continued
427_Bot_ch04.qxt 1/9/07 3:03 PM Page 110


Table 4.6 continued 
Known Vulnerabilities Commonly Exploited by RBot
Variants 
Microsoft Windows WINS replication packet memory overwrite
vulnerability (TCP port 42)
RealSystem Server SETUP buffer overflow vulnerability
Microsoft SQL Server 2000 Resolution service buffer overflow vulnerability
Microsoft Windows Plug and Play service buffer overflow vulnerability
Source: CA (www3.ca.com/securityadvisor/virusinfo/virus.aspx?ID=39437)
Exploiting Malware Backdoors
Some variants of RBot take the easy route and let other malware do the hard
work.These variants are programmed to seek out the default backdoors
opened by other malware such as the Bagle or Mydoom worms. Malware
backdoors known to be targeted by some RBot variants include:

Bagle worm (TCP port 2745)

Mydoom worm (TCP port 3127)

OptixPro Trojan (TCP port 3410)

NetDevil Trojan (TCP port 903)

Kuang Trojan (TCP port 17300)

SubSeven Trojan (TCP port 27347)
Agobot
Agobot, also commonly referred to as 
Gaobot
or 
Phatbot
, depending on the
variant and the AV vendor naming it, introduced the idea of modular func-
tionality to the world of malicious bots. Rather than infecting a system with
all the Agobot functionality at once, this threat occurs in three distinct stages.
First, Agobot infects the computer with the bot client and opens a back-
door to allow the attacker to communicate with and control the machine.
The second phase attempts to shut down processes associated with antivirus
and security programs, and the final phase tries to block access from the
infected computer to a variety of antivirus and security-related Web sites.

Download 6,98 Mb.

Do'stlaringiz bilan baham:
1   ...   91   92   93   94   95   96   97   98   ...   387




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish