Some dangerous trojans and their information
Scale: What it Means:
Hoax Deliberate Mis-information. No truth whatsoever.
Hype Some truth, but not worth any end user or IT manager cycles.
Fact True, but average systems security already deals with it.
Important True, you should plan on addressing this & related issues in next month.
Hot True, and most sites should do something in the next 2-3 days.
Red Hot True, stop whatever you are doing to address this in 1-2 hours.
Most recent Security Issues at top
RDS Vulnerability [More]
Initial Assessment: 10/19/99 15:30 Important
Most Current: 01/05/00 08:00 Important
In Brief: ICSA.net notes Windows NT RDS Attack is number one attack against web sites Defense is easy, and should be applied to all NT based web servers.
Y2K Hacking & Viruses [More]
Initial Assessment: 12/22/99 10:30 Hype
Most Current: 12/24/99 1400 Hype
In Brief: Though there will be both significant virus writing and virus release activity and significant hacking activity over the Y2K changeover period (12/20/1999 through 01/15/2000), ICSA does not expect that this activity will exceed seasonally adjusted projections unrelated to the Y2K transition.
Distributed Network Attacks [More]
Initial Assessment 10/19/99 15:30 Important
Most Current: 12/23/99 1400 Important
In Brief: In Brief: AKA: trin00 and Tribe Flood Network (TFN). Denial of Service attack tools are in circulation where an attacker controls several master controllers, each of which in turn controls up to hundreds of compromised systems that are then used to launch packet-based denial of service attacks against a victim host or network. The final stage of the attack includes spoofed addresses so the victim may be in the position least able to understand where the attack originated. The attack uses Internet protocol features not easily blocked without affecting general-purpose network operations, thus are both difficult to detect and defend against.
W32.NewApt.Worm [More]
Initial Assessment 12/14/99 Important
Most Current: 12/14/99 Important
In Brief: This new Worm has been reported in the wild. The worm arrives in a users Inbox with the subject "Just for your eyes", and makes references to MessageMates website and programs. This new threat will forward itself to other users and make changes to the registry.
Babylonia Virus [More]
Initial Assessment 11/28/99 08:23 Fact
Most Current 12/04/99 11:17 Fact
In Brief: This virus is real, but has little chance of rapid spread. Has no known presence in the wild, and therefore any malicious trigger is irrelevant.
Explore.zip.Pac Worm [More]
Initial Assessment 11/21/99 09:17 Important
Most Current 11/23/99 22:13 Important
In Brief: This virus is based on the Hot Explore.zip virus, but is hidden in a compressed format. Once expanded old anti-virus software is effective. Update AV is effective as of 11/22/99.
Filter for: Email: subject: 'xxyyzz yymmqq'
Filter for attachments with name: 'mmxxnnyyxx.pac'
RDS / MDAC Hack [More]
Initial Assessment 11/12/99 09:17 Hot
Most Current 11/29/99 22:13 Hot
In Brief: This is the number one, most common successful attack against NT, IIS web servers. Several automated tools and cook-book instructions exist and are shared widely. Root control is easily achieved.
ICSA SecuritySnapshot identifies vulnerability
Follow MSFT Recommendations
Or delete MSDACS.DLL
Elf Bowling [More]
Initial Assessment 11/12/99 09:17 Hoax
Most Current 11/29/99 22:13 Hoax
In Brief: Various messages warn that the game "Elf Bowling" contains a virus that will rewrite the system BIOS on Dec 25,1999. There is no evidence at ICSA that there is any truth whatsoever to this.
W32.Mypics.Worm [More]
Initial Assessment 12/03/99 08:23 Important
Most Current 12/03/99 11:17 Important
In Brief: ICSA urges users to watch out for unsolicited email attachments.
This worm arrives in a users Inbox with a message stating "Here's some pictures for you!". If the user executes the attached pics4you.exe the attachment and message will be sent out to the first 50 users in the original users Outlook address book.
BubbleBoy [More]
Initial Assessment 11/10/99 08:00 Fact
Most Current 12/15/99 Important
In Brief: "BubbleBoy" is a Proof of Concept worm written to affect Microsoft Outlook and Microsoft Outlook Express running on Windows 95 and 98, Windows NT, Windows 2000 and possibly other email clients tied to Visual Basic Scripting.
The status of this virus was moved to Important after it was listed on the WildList as spreading.
W32/FunLove.4099 [More]
Initial Assessment 11/09/99 08:23 Important
Most Current 11/09/99 08:23 Important
In Brief: This virus, infects both desktop computers and network servers running Windows 95, 98 and Windows NT 4.0 / 2000.
It has some unique attributes, which, over time, allow it to gain administrative rights in NT domains and could give administrative access to all LAN users in an organization.
|