<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; ms06-40</title>
	<atom:link href="http://www.darknet.org.uk/tag/ms06-40/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Bot Herders Go After MS06-40 Exploit</title>
		<link>http://www.darknet.org.uk/2006/08/bot-herders-go-after-ms06-40-exploit/</link>
		<comments>http://www.darknet.org.uk/2006/08/bot-herders-go-after-ms06-40-exploit/#comments</comments>
		<pubDate>Thu, 17 Aug 2006 00:05:20 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[bots]]></category>
		<category><![CDATA[darknet]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[ms06-40]]></category>
		<category><![CDATA[trojans]]></category>
		<category><![CDATA[viruses]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[worms]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/08/bot-herders-go-after-ms06-40-exploit/</guid>
		<description><![CDATA[Malware herders are speeding up, the first wave is already here for MS06-40. It&#8217;s basically a variant of some old malware suited to the new vulnerability. Same old story then, same packer, technique, new exploit. Same as the days of autorooters. It&#8217;s basically the Mocbot trojan that was used in the Zotob worm attack in [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Malware herders are speeding up, the first wave is already here for MS06-40.</p>
<p>It&#8217;s basically a variant of some old malware suited to the new vulnerability. Same old story then, same packer, technique, new exploit.</p>
<p>Same as the days of autorooters.</p>
<p>It&#8217;s basically the Mocbot trojan that was used in the Zotob worm attack in August 2005.</p>
<blockquote><p>The first wave of malicious attacks against the MS06-040 vulnerability is underway, using malware that hijacks unpatched Windows machines for use in IRC-controlled botnets.</p>
<p>The attacks, which started late Aug. 12, use a variant of a backdoor Trojan that installs itself on a system, modifies security settings, connects to a remote IRC (Internet Relay Chat) server and starts listening for commands from a remote hacker, according to early warnings from anti-virus vendors.</p></blockquote>
<p>I hope the AV first are on top of things, people are patching their machines in a timely fashion (especially in corporate environments &#8211; come on people, get SUS!) and awareness is going up.</p>
<blockquote><p>&#8220;Amazingly, this new variant of Mocbot still uses the same IRC server hostnames as a command-and-control mechanism after all these months. This may be partially due to the low-profile it has held, but also may be due to the fact that the hostnames and IP addresses associated with the command-and-control servers are almost all located in China,&#8221; LURHQ said in an advisory.</p>
<p>Historically, Chinese ISPs and government entities have been less than cooperative in taking action against malware hosted and controlled from within their networks, the company said.</p>
<p>On Aug. 13, a second variant of the Trojan was detected, confirming fears that botnet herders are already playing cat-and-mouse with anti-virus vendors.</p></blockquote>
<p>Quite surprising in a way, but also not really as it&#8217;s China and they are notoriously un co-operative.</p>
<p></p>
<p>Source: <a href="http://www.eweek.com/article2/0,1895,2002966,00.asp">Eweek</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Bot+Herders+Go+After+MS06-40+Exploit+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D315+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/08/bot-herders-go-after-ms06-40-exploit/&amp;t=Bot+Herders+Go+After+MS06-40+Exploit" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/08/bot-herders-go-after-ms06-40-exploit/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/08/bot-herders-go-after-ms06-40-exploit/&amp;title=Bot+Herders+Go+After+MS06-40+Exploit" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/08/bot-herders-go-after-ms06-40-exploit/&amp;title=Bot+Herders+Go+After+MS06-40+Exploit" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/08/bot-herders-go-after-ms06-40-exploit/&amp;title=Bot+Herders+Go+After+MS06-40+Exploit" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/08/bot-herders-go-after-ms06-40-exploit/&amp;title=Bot+Herders+Go+After+MS06-40+Exploit" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F08%2Fbot-herders-go-after-ms06-40-exploit%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/08/bot-herders-go-after-ms06-40-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

