Newsletter:

Skip Navigation LinksHome > News > Security > Tibet attack Trojan identified

Tibet attack Trojan identified

By Shaun Nichols
14 April 2008 07:35AM
Tags: tibet | attack | trojan | identified

A new SQL-based Trojan has been connected to the recent attacks on pro-Tibet websites as well as the outbreak of site infections uncovered last month..

A pair of researchers are reporting that the 'Fribet' Trojan has spread among users by embedding itself in pro-Tibet websites by way of an SQL injection and then exploiting a browser vulnerability to remotely install and execute.

McAfee researchers Shinsuke Honjo and Geok Meng Ong reported on a company blog posting that the Trojan not only gives the attacker the ability to remotely control and perform installations on infected PCs, but it also provides the ability to receive SQL instructions.

This, the researchers say, can allow the attacker to use infected machines to host other web exploits.

"This Trojan apparently can be used as an alternate to SQL Injection attacks, but in a more direct way," they wrote.

"Even the administrators of secure websites, protected against common SQL injection attacks, should ensure database backends are equally secure to defend against such a penetration vector."

There are, however, some mitigating factors. At the time of the posting, the server that the infected machines connected to was not active, so computers running the Trojan were not being sent commands.

The researchers also noted that in order to host web exploits on a machine, an attacker would need extensive information on a machine's network configuration and user credentials. Researchers do, however, believe that such information could be obtained through Fribet's info-stealing components.

Copyright © 2008 vnunet.com

   


Ads by Google


Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 


Tripwire - Click here to win an iTouch



Product Reviews

Star Rating
The Lieberman Software Enterprise Random Pass­word Manager is a full-on password manager and randomiser for...
Star Rating
Proginet SecurForce is a little bit of a horse of a different color for this month's Group Test.
Star Rating
On the surface, RoboForm Enterprise starts out looking like a single sign-on product, but that is just on the...
Star Rating
The Symark PowerBroker is a policy-driven, privileged access control application.
Star Rating
The Symark PowerKeeper is a hardened appliance. It comes with a sealed operating system that provides a...
iTnews 2009 Job Survey

TopTopics
(6851) -  top
(3304) -  microsoft
(2306) -  broadband
(2173) -  content
(2132) -  company
(2129) -  data
(1915) -  terria
(1862) -  isp
(1813) -  nbn
(1726) -  filtering
(1698) -  telstra
(1585) -  internode
(1542) -  voip
(1445) -  centre
(1215) -  consumers