| 1.Summary:
w00w00 is a Trojan Horse utilizing Telnet. This event is
generated when
an attacker attempts to connect to a w00w00 server using Telnet.
2.Impact:
Possible theft of data and control of the targeted machine
leading to a
compromise of all resources the machine is connected to. This
Trojan
also has the ability to delete data, steal passwords and disable
the
machine.
3.Detailed Information:
This Trojan affects UNIX operating systems:
Due to the nature of this Trojan it is unlikely that the
attacker's
client IP address has been spoofed.
4.Attack Scenarios:
This Trojan may be delivered to the target in a number of
ways. This
event is indicative of an existing infection being activated.
Initial
compromise may be due to the exploitation of another
vulnerability and
the attacker is leaving another way into the machine for further
use.
5.Ease of Attack:
This is Trojan activity, the target machine may already be
compromised.
6.Corrective Action:
Disallow Telnet access from external sources.
Delete the Trojan and kill any associated processes. |