ninja
ninja

Ninja strikes back

Microsoft SQL stalked by Trojan

Written by James Middleton

The ninja Trojan discovered earlier this month may now be attacking Microsoft SQL server systems.

Experts suggest that someone somewhere is building a network of zombie machines that could be used en masse in a distributed denial of service attack.

An advisory released yesterday by SecurityFocus Attack Registry and Intelligence Services (ARIS) warned of "a new hybrid tool that combines distributed denial of service (DDoS) tools, with the automated propagation techniques previously seen only in worms".

The tool propagates by attacking incorrectly configured SQL servers with System Administrator accounts using a blank password.

The advisory said yesterday that ARIS had "identified a rapidly growing network of controlled agents or 'bots', increasing 600 per cent in the last 6 hours".

Apparently the tool, named 'Voyager Alpha Force', is a modified and enhanced version of the DDoS tool, 'Kaiten', and is manually controlled over an IRC network. Once installed, the program may display worm-like tendencies by using the host to scan for other vulnerable machines.

Other analysis from security experts on the SecurityFocus mailing list found that the program connects to an IRC server at bots.kujikiri.net to receive instructions. The word 'kujikiri', a method of esoteric teaching used by the ninja, was also used by the Linux-infecting Limpninja Trojan to identify its commanding IRC channel.

When Limninja emerged a few weeks ago, security watchers suggested that hackers were building an army of compromised machines with the potential to cause a devastating distributed denial of service attack.

It's possible that the same person or persons is responsible for building both a Linux version and a Windows version of a Trojan, to create a huge cross-platform army of zombies.

As a precaution SecurityFocus recommends that admins verify that the System Administrator 'sa' account does not have a blank password if running Microsoft SQL server, and uses a firewall to block ports 1433 and 6669.

Tags:

Further reading

'Limpninja' Trojan horse emerges

Hackers make ninja-style swoop on Linux boxes   More...

SSH flaw puts Unix users on alert

Secure Shell encryption protocol at risk, users warned.   More...

Related articles

New threats top April malware charts

Malware showed 'renewed vigour' last month   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

09 May 2008

2.51 MBWiMax muddle, Google tactics and asteroid bunkum More...

08 May 2008

3.26 MBBroadband Anywhere, phone-free transport and Web 3.0 More...

07 May 2008

3.19 MBUK success, a paucity of IT women and robot wars More...

Poll

DATA ENCRYPTION

DATA ENCRYPTION

Should encryption be mandatory for all personal data held by companies and governments?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Ofcom

Ofcom outlines future wireless vision

Wi-Fi healthcare and intelligent car brakes in the pipeline   More...

HP

HP Labs opens doors to academia

Innovation Research Program invites proposals related to current research   More...

Advertisement

Asteroid

Nasa plans manned mission to asteroid

Bruce Willis thankfully not going   More...

MySpace

MySpace offers opt-in data sharing

Deals signed with Photobucket, Twitter, eBay and Yahoo   More...

Advertisement