All the latest UK technology news, reviews and analysis

Net movies open back door for hackers

by John Leyden

09 Jun 2000

Be the first to comment

  • Tweet this

Hackers are poised to attack websites after successfully compromising thousands of computers via a malicious program disguised as a movie clip, security experts have warned the US government.

The hackers have been distributing a Trojan Horse - a piece of malicious code embedded inside a legitimate file - which when activated allows hackers full control of a computer while it is connected to the internet.

The problem was detected by Network Security Technologies (Netsec) when the malicious code placed on its network unsuccessfully tried to contact hackers across the internet.

The company isolated and analysed the Trojan, and later contacted government officials at the FBI. Netsec security engineers then followed the Trojan's communications and monitored internet conversations among hackers.

According to US reports, the FBI plans to meet with Netsec officials today amid fears that the launch of a denial-of-service attack is imminent.

"Due to the widescale nature of the infection, the hackers could easily use the compromised machines to launch a distributed denial-of-service attack," said Jerry Harold, Netsec's president and co-founder.

Netsec has identified more than 2000 computer systems within the last few days that have been compromised by this Trojan, including a major corporation in the US and Europe.

Greg Jones, senior security engineer at Information Risk Management, said the warning represents the first reported case of a malicious program has been spread using a movie file. He said it would be difficult to defend against without having to reject all multimedia files at firewall level and that "users who have followed best practice might still become infected".

The development is particularly worrying because "the integrity of streaming media is never checked by virus scanners", said Jones.

The malicious code hackers have installed is an implementation of a known Trojan called Backdoor.SubSeven21, embedded in a multimedia file. The code has been compressed to avoid detection when the video or host file is executed.

Upon a reboot, the malicious code loads itself in to the system, renames itself by assigning a randomly generated name, modifies the system.ini, win.ini and the Windows Registry, and installs a service that makes an outbound connection to one of two modified Internet Relay Chat servers.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

25%

1%

11%

63%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

Systems Analyst/Architect

Systems Analyst/Architect £30,000 - £40,000 + excellent...

Software Developer

Software Developer Up to £27,000 + excellent...

Software Engineer/Developer (C#, C++)

Software Engineer/Developer (C++) £25,000 - £40...

Web Developer

Web Developer £25,000 - £40,000 (DOE)+ excellent...

To send to more than one email address, simply separate each address with a comma.