Portal IT :: News, download, directory


Search: Friday 4 July 2008









Add to Google Add to My Yahoo!


  Add to Favorites   Set Home Page





« july 2008
s m t w t f s
29 30 1 2 3 4 5
6 7 8 9 10 11 12
13 14 15 16 17 18 19
20 21 22 23 24 25 26
27 28 29 30 31 1 2
3 4 5 6 7 8 9







Anti-Tibet Trojan Now Revealed
Published on Security  |  April 11, 2008, 13:03

Pro-Tibet sites have been under attack recently with an unknown SQL-based Trojan leading the charge. Now, the secrets of the malware have been revealed.

The Trojan was dubbed “Fribet” and, according to McAfee researchers Shinsuke Honjo and Geok Meng Ong, was able to spread by embedding itself in pro-Tibet web sites by using an SQL injection.

The next step was to exploit a a browser vulnerability to remotely install and execute.

A posting on the McAfee blog warns readers that the Fribet Trojan is quite capable of both of remotely controlling and installing software on victim PCs, as well as receiving SQL instructions:

“our reverse engineering of the malicious code shows it is more than capable of the following:
- Bind and connect to local or remote databases from the victim machine
- Query and steal data from local or remote databases
- Insert arbitrary data into local or remote databases, including web data such as hosting a web exploit”

The researchers also warn that even the administrators of secure web sites “should ensure database backends are equally secure to defend against such a penetration vector”, as the trojan can be used as an alternate to SQL Injection attacks.




Rate this       Low   High
Curent Rating: 3.1/5 by 7 users
 Print       Email      IM 




 
More Security News
 
Daily News Alert

 
Advertising
 
Top Rated Security News This Month