IIS worm made to packet Whitehouse.gov

A worm thats attack`s the WhiteHouse sounds like a b-movie story but its true(digitaly then)

The worm attacks what's now called the .ida vulnerability, an unchecked buffer in the IIS Indexing Service ISAPI filter, which, if exploited, can yield system-level access to an intruder. The vulnerability was first reported by eEye Digital Security on 18 June; an attack script was released on 21 June by a Japanese fellow called HighSpeed Junkie; and the worm first appeared on 13 July.

After compromising a victim, the worm scans for other vulnerable IIS machines to infect. The scan is random, but the randomizing seed never changes, so the same IPs will get hit again and again from subsequently infected boxes. Bad news for sleepy admins; but good news overall, as this checks the worm's spread somewhat.

One of the more curious features of the worm is that some of the infected systems (we think those using other than US English versions of Win-NT, but the eEye bulletin is confusing) will periodically send 100k to port 80 at whitehouse.gov.

Read the full story Here

Source: The Register

No posts to display