• Starting today August 7th, 2024, in order to post in the Married Couples, Courting Couples, or Singles forums, you will not be allowed to post if you have your Marital status designated as private. Announcements will be made in the respective forums as well but please note that if yours is currently listed as Private, you will need to submit a ticket in the Support Area to have yours changed.

  • CF has always been a site that welcomes people from different backgrounds and beliefs to participate in discussion and even debate. That is the nature of its ministry. In view of recent events emotions are running very high. We need to remind people of some basic principles in debating on this site. We need to be civil when we express differences in opinion. No personal attacks. Avoid you, your statements. Don't characterize an entire political party with comparisons to Fascism or Communism or other extreme movements that committed atrocities. CF is not the place for broad brush or blanket statements about groups and political parties. Put the broad brushes and blankets away when you come to CF, better yet, put them in the incinerator. Debate had no place for them. We need to remember that people that commit acts of violence represent themselves or a small extreme faction.

Network Worm, uses weak Windows Passwords!

OLDoMiNiON

Senior Member
Feb 20, 2003
444
1
40
The North!
Visit site
✟23,108.00
Faith
Christian
Marital Status
Single
Source:[/b] The Register

Say hello to a network worm which attempts to compromise and spread through Windows machines with weak, default passwords. Called Deloder, the worm also tries to drop a backdoor component.

And yes the worm is spreading through vulnerable machines - albeit modestly, according to Symantec.

The worm spreads by scanning random IP addresses, trying to connect on Port 445. Port 445 (Microsoft SMB over TCP/IP) allows outsiders to access Windows file shares.

This should normally be blocked by a firewall, of course, so home users (or universities with weak security in place) are probably more at risk here.

If a successful connection is made, Deloder drops a called INST.EXE in the Windows Start folder. This is a Trojan designed to open a backdoor access to compromised computer.

Deloder then copies a file called DVLDR32.EXE, a copy of the worm itself, onto infected machines.

It then tries to obtain a list of computers connected to the same network and attempts to access them using default passwords, as explained in an advisory by Finnish AV specialist F-Secure.

Finally, Deloder disables shared network resources and places entries in the Windows Registry of compromised machines to make sure it is always run. This action has the side-effect of disabling network sharing.

AV vendors are in the process of updating signature definitions to detect the worm. As well as updating AV tools, users may want to check they're not using easily guessed or default passwords and to consider whether to disable network sharing.

You know it makes sense.