22 Nov 2001
The ninja Trojan discovered earlier this month may now be attacking Microsoft SQL server systems.
Experts suggest that someone somewhere is building a network of zombie machines that could be used en masse in a distributed denial of service attack.
An advisory released yesterday by SecurityFocus Attack Registry and Intelligence Services (ARIS) warned of "a new hybrid tool that combines distributed denial of service (DDoS) tools, with the automated propagation techniques previously seen only in worms".
The tool propagates by attacking incorrectly configured SQL servers with System Administrator accounts using a blank password.
The advisory said yesterday that ARIS had "identified a rapidly growing network of controlled agents or 'bots', increasing 600 per cent in the last 6 hours".
Apparently the tool, named 'Voyager Alpha Force', is a modified and enhanced version of the DDoS tool, 'Kaiten', and is manually controlled over an IRC network. Once installed, the program may display worm-like tendencies by using the host to scan for other vulnerable machines.
Other analysis from security experts on the SecurityFocus mailing list found that the program connects to an IRC server at bots.kujikiri.net to receive instructions. The word 'kujikiri', a method of esoteric teaching used by the ninja, was also used by the Linux-infecting Limpninja Trojan to identify its commanding IRC channel.
When Limninja emerged a few weeks ago, security watchers suggested that hackers were building an army of compromised machines with the potential to cause a devastating distributed denial of service attack.
It's possible that the same person or persons is responsible for building both a Linux version and a Windows version of a Trojan, to create a huge cross-platform army of zombies.
As a precaution SecurityFocus recommends that admins verify that the System Administrator 'sa' account does not have a blank password if running Microsoft SQL server, and uses a firewall to block ports 1433 and 6669.
Latest stories from Security
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Sneak peek at the forthcoming glass-based machine
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
Danish Speaker Required. Helpdesk. Liverpool. £11-£12...
Solution Network Engineer / Network Engineer - Docklands...
ROLE: Web Developer - Market Leader LOCATION: Watford...
Test Engineer Payments (UAT) - Leading IT Consultancy...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?