Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Bridex worm bites computer security company

November 11, 2002 12:00 PM ET

IDG News Service - In a bold move, a group of hackers launched a successful attack on the Web server of Russian computer security company Kaspersky Labs Ltd., managing to implant and distribute a copy of the recently discovered Bridex worm in the company's e-mail newsletter.
The successful exploitation of Kaspersky's e-mail list followed what the company described in a statement as a "massive attack" against its Web server Friday evening, according to Denis Zenkin, head of corporate communications at the Moscow-based company.
A statement posted on Kaspersky's Web site said the attack began Thursday night.
According to Zenkin, the attackers used a sophisticated and "exotic" attack to compromise the company's Web server and gain access to a folder containing mail messages sent out by Kaspersky.
From those messages, the attackers were able to obtain the distribution list for the company's e-mail newsletter. A copy of that newsletter was distributed to Kaspersky's customers along with an attached executable file containing the Bridex worm.
"Our IT security people were amazed that hackers got the idea for this kind of hack attack," Zenkin said.
Zenkin refused to provide details on the attack, citing concerns that other hackers would use that information to carry out further attacks. Zenkin did disclose that Kaspersky's Web server runs the FreeBSD operating system, which is a version of Unix, and the common Postfix e-mail server software.
Hackers weren't able to gain access to Kaspersky's e-mail address book, nor were they able to penetrate areas of the Web server containing virus signatures for Kaspersky's antivirus software, Zenkin said.
Zenkin declined to say whether antivirus definitions were posted in a more secure area of the server, however, saying only that they were located in different "territories" of the server that weren't affected by the attack.
Kaspersky's virus definitions use digital signatures that are verified by the company's software before they are installed and used. Tampering with Kaspersky's virus definitions -- for example, attempting to substitute malicious code for a signature -- would be detected and rejected by the company's software, Zenkin said.
According to Zenkin, Kaspersky knows of no customers who were infected by the newsletter. Nonetheless, the company advised users to install the IFrame-vulnerability patch available from Microsoft Corp.
Kaspersky staff first noticed the attack and took corrective action within minutes of the exploit, Zenkin said. Nevertheless, the attack produced the unusual scenario of an antivirus vendor's software being used to thwart an attack launched from its own servers. It was an embarrassing fact that more than a few of Kaspersky's customers brought to the company's attention, Zenkin admitted.
Since the attack, Kaspersky has closed the security loophole exploited by the attackers and taken other steps to ensure that future attacks are unsuccessful. In addition, the company inspected the entire contents of its Web server and claimed that the e-mail newsletter was the only affected component of its Web site, Zenkin said.
The company traced the attacks to a group of hackers in Mexico, but so far it has no concrete evidence pointing to specific individuals, Zenkin said.
The Bridex worm, also known as "W32/Braid.A" or "I-Worm.Bridex," was first identified early this month and arrives in an e-mail message, typically contained in an attachment named README.EXE.
When recipients double-click on the attachment, the worm copies a variant of the FunLove virus to the local system with the name BRIDE.EXE, alters the machine's system registry so that the virus is relaunched each time Windows starts, scans the user's Outlook address book and e-mails copies of itself to any addresses it finds.
Antivirus software vendors including Kaspersky have published updated virus signatures to detect Bridex.








Reprinted with permission from

IDG.net
Story copyright 2009 International Data Group. All rights reserved.

Jump to comments

Cybercrime/Hacking

Additional Resources

Microsoft
Here are some of the key reasons why you would want to run Unified Access Gateway with DirectAccess.
Microsoft
Review how one energy firm tightened protection and simplified IT work using business-ready security solutions.
Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.

Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.

White Papers & Webcasts

Gene Kim's Practical Steps to Achieve and Maintain NERC Compliance
Learn seven steps operators can take to meet IT configuration requirements set forth in the NERC-CIP standards.  

The Workday User Experience Video
Watch Workday's Creative Director, Scott Lietzke, discuss the business-centered design philosophy at Workday.

Business Process Framework Demo
Learn about Configurable Business Processes and Calculated Fields. Watch Now!

Manager Experience Demo
Go beyond self-service solutions to perform more effectively. Watch Now.


IT Jobs