main
Report a problem

New Worm Targets Weak Windows Passwords

Mr magoo   on 10 March 2003 - 20:46 · 21 comments & 2856 views

Advertisement (Why?)
A new worm on the Internet targets computers running the Microsoft Windows operating system, using easy-to-guess passwords for the Administrator account, according to alerts posted by a number of antivirus companies. The new worm, W32/Deloder-A (Deloder), appeared on Sunday and is considered a low risk for infection, according to an alert posted by F-Secure of Helsinki, Finland.

Deloder is believed to have originated in China, F-Secure said. The worm attempts to connect to other computers on a network through TCP (Transmission Control Protocol) port 445, randomly generating IP addresses to locate vulnerable machines. Port 445 is used to access shared files on Windows machines with the Server Message Block protocol.

When a vulnerable Windows machine is located, the worm attempts to log on to the machine's Administrator account by trying 50 likely passwords such as "admin," "password," "12345," and "administrator," F-Secure said. If the worm succeeds in breaking the Administrator account password, it places copies of a backdoor, (trojan) program known as "inst.exe" in several locations on the infected machine.

View: Article @ Pcworld.com

Post a comment · Send to friend Comments · There are 21 additional comments
#1 vetMr magoo on 10 Mar 2003 - 21:00
or hello1 another genius password and lets not forget qwerty,asdf,1234, and that age old classic of fuck you

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)