New User? Need help? Click here to register for free! Registering removes the advertisements.

Computer Cops
image image image image image image image image
Donations
If you found this site helpful, please donate to help keep it online
Don't want to use PayPal? Try our physical address
image
Prime Choice
· Head Lines
· Advisories (All)
· Dnld of the Week!
· CCSP News Ltrs
· Find a Cure!

· Ian T's (AR 23)
· Marcia's (CO8)
· Bill G's (CO11)
· Paul's (AR 5)
· Robin's (AR 2)

· Ian T's Archive
· Marcia's Archive
· Bill G's Archive
· Paul's Archive
· Robin's Archive
image
Security Central
· Home
· Wireless
· Bookmarks
· CLSID
· Columbia
· Community
· Downloads
· Encyclopedia
· Feedback (send)
· Forums
· Gallery
· Giveaways
· HijackThis
· Journal
· Members List
· My Downloads
· PremChat
· Premium
· Private Messages
· Proxomitron
· Quizz
· RegChat
· Reviews
· Google Search
· Sections
· Software
· Statistics
· Stories Archive
· Submit News
· Surveys
· Top
· Topics
· Web Links
· Your Account
image
CCSP Toolkit
· Email Virus Scan
· UDP Port Scanner
· TCP Port Scanner
· Trojan TCP Scan
· Reveal Your IP
· Algorithms
· Whois
· nmap port scanner
· IPs Banned [?]
image
Survey
How much can you give to keep Computer Cops online?

$10 up to $25 per year?
$25 up to $50 per year?
$10 up to $25 per month?
$25 up to $50 per month?
More than $50 per year?
More than $50 per month?
One time only?
Other (please comment)



Results
Polls

Votes: 979
Comments: 19
image
Translate
English German French
Italian Portuguese Spanish
Chinese Greek Russian
image
image trj: Advisories!: New Trojan appears to attack VeriSign image
Trojans
New Trojan appears to attack VeriSign
Andrew Colley
ZDNet Australia
October 02, 2003, 14:50 BST

A Trojan program has emerged in Australia that may be triggering a concerted assault on VeriSign's domain name

Sophos' antivirus team has confirmed that it is in the preliminary stages of analysing a new Trojan that may be linked to an organised attack on VeriSign's domain name servers. Paul Ducklin, head of technology, Sophos Asia-Pacific, said the Trojan, dubbed Qhost1, seduces the user into going to a Web site that exploits a security vulnerability in Internet Explorer and inserts malicious code onto the victim's personal computer.

Sophos's revelation coincides with unconfirmed reports from a source within the technical ranks of one Australia's major ISPs of a spike in support calls from customers whose DNS server settings had been tampered with, in what appears to be an orchestrated attack on Internet security giant VeriSign.

It's changing the IP address of the DNS servers from ours [domain name] across to VeriSign's to launch a DoS attack on them, said the source.


The source told ZDNet Australia that the activity appeared to be promoted by a virus or Trojan-like entity targeting Windows 2000 and Windows XP systems.


Ducklin said was unable to confirm that the new Trojan was implicated in the activity described by the source but confirmed it appeared that Qhost1 was designed to alter the DNS setting of its victim PCs.


This particular Trojan messes up your DNS so in theory it could be targeted against anyone, said Ducklin


What I can say is that in the light of what [ZDNet Australia] has told us, it has made us interested in looking at this particular sample so that we can match it up if further samples come in and, if appropriate, there will be further notifications on our Web site, he said.


Sophos expected to have a new definition file posted to its Web site within the hour.

ZDN
Posted on Friday, 03 October 2003 @ 08:26:31 EDT by phoenix22
image

 
Login
Nickname

Password

· New User? ·
Click here to create a registered account.
image
Related Links
· TrackBack (0)
· Microsoft
· HotScripts
· W3 Consortium
· ZDNet News
· More about Trojans
· News by phoenix22


Most read story about Trojans:
Lover Spy

image
Article Rating
Average Score: 0
Votes: 0

Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


image
Options

Printer Friendly Page  Printer Friendly Page

image
"Login" | Login/Create an Account | 0 comments
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register