Search

  
 
Antivirus Firms Warn Of Growing 'Bot' Networks


May 13 2004

Antivirus Firms Warn Of Growing 'Bot' Networks

 

While the recent Sasser worm attacks caught the attention of security professionals, security experts are warning that a more lethal and stealthy class of malicious applications are running amok throughout the Internet.

Known by many names, including "Agobot," "Polybot," and "Phatbot," these hacker-attack tools sometimes act as worms or even as backdoors into users' systems so hackers can control the systems or steal information. They're also often connected through what are known as "bot" networks, which are networks hackers can control to launch powerful denial-of-service attacks.

These bots use many software vulnerabilities within various versions of Microsoft's Windows operating system to infect unpatched systems. Many systems that weren't patched for the security flaw Sasser used to infect systems, the Windows Local Security Authority Service Remote Buffer Overflow, were also infected with various versions of these bots.

Internet security researchers say it's difficult to pinpoint how many systems are infected with these applications. Alfred Huger, senior director of engineering at Symantec Security Response, said Thursday that one such bot network has reached up to 400,000 infected systems. "That's massive," says Huger, adding that if the hackers who control that network decided to attack a network or a Web site, the impact could be devastating. "I don't think you could so easily protect yourself against an attack of that magnitude," he says.

Craig Schmugar, virus research manager at McAfee Avert, said he estimates there are bot networks of between 10,000 and 100,000 infected systems.

Both Schmugar and Huger say these bots are more difficult to spot that typical viruses and worms, and anyone who was infected with the Sasser worm should be sure to thoroughly check their systems for potential infections from these bots.

"It's a big concern for businesses," Huger says. "These types of infections cross the lines of businesses and consumers. These bot networks can be used to steal confidential information from the infected machines, and it's a gapping security hole for anyone that telecommutes."

Schmugar says the virus writers have been prolific in creating variants of these bots. For instance, he says there are 1,200 variants of Gaobot and more than 50 variants of Phatbot known to exist, and 50 new variants of Gaobot appearing each week.


 

Reproduced from an article published by Internet Week
© Internet Week

The original article can be viewed here:
http://www.internetwk.com/breakingNews/showArticle.jhtml?articleID=20300962

 Bookmark Digg this story

RSS feed  |  About RSS feeds

Get the Industry's top stories delivered straight to your inbox...
Firstname:

Surname:

Email:

Frequency:
 Daily  Weekly
 
 
Industry News
Case Studies
White Papers
Press Releases
Vulnerability Advisories
Monthly Newsletter Archive
Bandwidth Management
Consultancy Products
Content Control
Desktop Protection
Email Management
Encryption Solutions
Firewall/VPN Solutions
Identity and Security
Intrusion Management
Network Optimisation
Secure Remote Access
SIEM (Event correlation)
Strong Access Control
Vulnerability Management
Web Services Security
Wireless Security
About GSS
Supported Charities
Partner Accreditations
Exhibitions & Events
Contact Details
Location
Careers
Terms & Conditions of Sale
Network Penetration Testing
Web Application Testing
Managed Vulnerability Scanning
Citrix ESA
Wireless Scanning
GCSx ITHC Testing
Vulnerability Advisories
ICS Catalogue