Latest Comments
"I too have been a labor voter for many years and will not be voting for them again. The ..."
by maxt | Feb 9, 2010 7:56 PM
 
"I’ve just had a user receive a rehashed version of this with an attached html file containing a ..."
by Owen Lutz | Feb 9, 2010 6:01 PM
 
"hi"
by manish kumar | Feb 9, 2010 4:27 PM
 
"Hey 'hey con-roy' ... from Google Australia's head of policy Iarla Flynn"We don't believe that ..."
by Keep it real | Feb 9, 2010 3:33 PM
 
"@penno Off-site storage is a good solution unless you have some decent backup software to ..."
by Charmgene | Feb 9, 2010 2:36 PM

FTP login credentials at major corporations breached

  • Email a Friend
  • Print Page
By Greg Masters
Jun 29, 2009 12:23 PM
Tags: FTP | login | credentials | data | breach | trojan | BBC | Amazon | Symantec | McAfee | ZBot
A trojan has reportedly been uncovered that is harvesting FTP login data of major corporations, including the Bank of America, BBC, Amazon, Cisco, Monster.com, Symantec and McAfee.

According to a report in The Register, Jacques Erasmus, CTO at UK-based Prevx, discovered a site where a trojan is uploading FTP login credentials from more than 68,000 websites.

Once an individual's PC is infected with the trojan, that user's stored FTP login credentials are harvested. An attacker can then log in to the FTP site. The logins are believed to have been stolen during the last two weeks and some are thought to still be valid.

Erasmus said the compromised sites would then be vulnerable for hackers to upload drive-by download scripts and other malware. A variant of the ZBot trojan, hosted on a server in China, is said to be receiving the uploaded FTP credentials in plain text, making it simple for cybercriminals to gather up the data.

First detected in September 2007, ZBot is already notorious for capturing keystrokes to obtain login credentials, along with credit card or other sensitive information.

"It's a never-ending battle," Ivan Macalintal, threat researcher manager at Trend Micro, told SCMagazineUS.com.

Zbot, aka Zeus, is an infamous information-stealer that usually comes via a drive-by download on a compromised website, he said.

"We're also seeing it being deployed by email with a malicious link or attachment," Macalintal added.

Recent variants came disguised as an email that claimed to be a critical update for Microsoft Outlook. Some variants of the trojan are also capable of getting snapshots of an infected user's system, Macalintal said.

The rise in this type of trojan may be due to the fact that kits are being sold in the cyber underground that allow attackers to create their own trojans and customize them to configure what stored information they need, and how it will be sent back to the creator, Macalintal said.

As far as what can be done to defend against attacks, Macalintal listed the traditional antidotes: don't click on suspicious, unsolicited links; browse safely and securely using good web filtering; update patches; and use safe computing practices. In the case of last week's scam involving Microsoft updates, he said that end-users should remember that vendors do not send updates via email.


See original article on scmagazineus.com

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
 
Vulnerabilities & Exploits Whitepapers