NEWS A new worm, called Deloder, is showing signs of spreading via the internet - leaving two Trojan horse programs in its wake. The worm has raised fears among security experts that the infection is paving the way for a potentially crippling distributed denial of service (DDoS) attack. Although the experts are not yet rating the Deloder worm as a high risk to users, the technical make-up of the Trojans it leaves behind is of concern. They consist of a commonly used piece of network administration software called Virtual Network Computing (VNC), and an internet Relay Chat (IRC) "bot". The VNC component allows an attacker to connect to an infected system and control it as if they were in front of it. They have full access through a graphical user interface. The IRC bot, when activated, connects to a remote server and waits for commands, which could mean that infected systems are going to be used for a massive DDoS attack. This worm, unlike others such as Klez, requires no user interaction to spread - it exploits common passwords, such as "password" and "computer", in share directories in Windows NT/2000/XP machines and hence spreads automatically. However because the virus attacks through weak share directory passwords, the effect on corporations has been minimal because share directories are typically firewalled. Daniel Zatz, a security spokesman from Computer Associates, says that they haven't received any reports of their customers being infected yet. "Very little has been reported to the [antivirus] vendors themselves... I haven't spoken to any customers that have been impacted yet," he said. Aside from potential DDoS implications, Zatz says that end users may be stung through identity theft - even a novice malicious hacker can access an infected system with ease. "This is one of the ways that identity theft occurs," he said. Despite this, Melbourne-based security consultant Adam Pointon says that the worm is hitting home users hard. "It's been increasing threefold over the last few days," he said. The SANS Institute's Internet Storm Centre, a research group that monitors the internet for attacks, have lifted its alert status from green to yellow. More information is available on SANS' website.
Virus warning: Deloder targets password idiocy
There's never been a better time to change your password from 'password'...
Post your comment
In order to post a comment you need to be registered and logged in.
You can also log in with Facebook. Log in or create your silicon.com account below
Get silicon.com's daily newsletter
-

Enter your email to register
Featured white papers
-
Why is encryption important?
Data protection has become a hot topic, but where is the real threat and what can you do to protect your business? How...
-
CIO challenges: Bringing your iPad to work
The arrival of personal technology in the office is a challenge for all organisations. The technology is here, but not...
-
2012 Olympics: Is your business prepared?
Athletes prepare for all kinds of conditions and problems in competition. With the London-hosted Olympics fast...
Keep in touch with silicon.com
-
Connect with silicon.com on Facebook
Discuss the news of the day with the silicon.com team
-
Follow silicon.com on Twitter
Get regular updates from the silicon.com editors
-
Join the silicon.com LinkedIn networking group
Network with your peers and share expertise
Latest jobs
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
silicon.com newsletters
-
Stay up to date with silicon.com newsletters
Keep up with the latest news and analysis from silicon.com with our free email newsletters





