All the latest UK technology news, reviews and analysis

Expert warns of Trojan explosion

by James Middleton

08 Apr 2002

Be the first to comment

  • Tweet this

A technology researcher at Berkeley, University of California, has described distributed computing systems that connect to a central server as security blunders waiting to happen.

The warning follows the news last week that peer-to-peer file sharing software Kazaa contains a Trojan that puts millions of machines at risk.

In a federal securities filing last week, it was revealed that Kazaa contains another program designed to create a second underlying distributed computing network made up of unwitting Kazaa users.

Brilliant Digital Media, the company behind the stealth peer-to-peer software, known as Altnet, plans to activate the software on users' machines in the next few weeks to be used for distributed computing.

The terms and conditions included with Kazaa read: "You hereby grant [Brilliant] the right to access and use the unused computing power and storage space on your computer/s and/or internet access or bandwidth for the aggregation of content and use in distributed computing."

But Nicholas Weaver, a technology security researcher at Berkeley, attacked Kazaa for bundling the "small Trojan program".

Weaver said that any distributed or peer-to-peer network client that periodically connected back to a central server posed a security risk.

"The recent revelation that Brilliant has bundled a small Trojan with Kazaa has underscored another means by which an attacker could gain control of so many machines: poorly secured automatic updaters. If an attacker can distribute his own code as an update, he can take control of millions of machines," he warned.

Kazaa has been downloaded by around three million people to date.

"Any program which connects back to the server to gain updates should be scrutinised very heavily because, as a program becomes widespread, the update server and mechanisms become highly attractive targets for attack," said Weaver.

"Each new program with an automatic update feature is a new point where an attacker can gain control of a huge number of machines."

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Desktop Deployment Support Analyst (Worksite, SQL)

Desktop Deployment Support Analyst (Worksite, SQL...

Project Manager

Project Manager is required by Bank in Germany Suitable...

Web Developer / Web Designer Mobile & Social Media Application

Mobile & Social Media Application Web Developer...

CCVP Consultant

CCVP Consultant - Telecoms Cisco Certified Voice Professional...

To send to more than one email address, simply separate each address with a comma.