13 Mar 2001
Security experts have warned of a new release of the infamous SubSeven backdoor program, just hours after the appearance of a new version of the program that spawned the Kournikova virus.
Late yesterday, security professionals were warning of the increased risk of virus activity that could be brought on by version 2 of the Visual Basic Script Worm Generator. Today, version 2.2 of the SubSeven hacking tool made an appearance.
Security firm Internet Security Systems (ISS) said that the new version makes it much easier for "a malicious user to access your computer system without your knowledge or consent". The company also warned that an attacker could use this backdoor as a remote control and carry out activities as a local user.
ISS said SubSeven is a powerful backdoor program, mostly used against Windows systems. It allows an attacker to retrieve saved and cached passwords, modify the system registry, and upload, download and delete files from a system.
The new version also features SOCKS4/SOCKS5 Proxy Support, which enables an attacker to disguise their identity by connecting from an alternate IP address.
SubSeven also includes a packet sniffer that collects network traffic, such as passwords, and has the ability to connect to a random port every time it is started, making it harder to detect.
SubSeven 2.2 has expanded its notification capabilities, letting the intruder know that a machine is infected through IRC (internet relay chat), ICQ and email as well as being able to log keystrokes and send them via email.
One of the more dangerous capabilities, as pointed out by ISS, is its ability to use common gateway interface scripts, effectively allowing the program to be used as a denial of service tool.
Hackers can trade the IP addresses of infected machines and then use a number of them in a co-ordinated attack on another server.
Latest stories from Security
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
My client is a well established, non profit organisation;...
PHP Web Developer – £30,000 - £35,000 PHP, MySQL, HTML...
HEAD OF DIGITAL - London - £80-95K + Excellent Bens...
Agile C# Developer - (North London) £55,000 - £65,000...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?