From today’s SANS NewsBites Vol. 9 Num. 39
WORMS, ACTIVE EXPLOITS, VULNERABILITIES & PATCHES
--Attackers Using BITS to Download Malware
(May 10, 11 & 14, 2007)
Attackers are using the Background Intelligent Transfer Service (BITS)
to circumvent firewalls and plant malware on computers. Microsoft uses
BITS, an asynchronous file transfer service, to deliver patches through
Windows Update. BITS has "automatic throttling so downloads don't
impact other network chores. It automatically resumes if the connection
is broken." Because BITS is "baked in" to some versions of Windows, it
is considered a trusted program and therefore avoids the firewall. In
late March 2007, a trojan infected computers using BITS causing mny
computers to be infected.
http://www.computerworld.com/action...cleBasic&articleId=9019118&source=rss_topic17
http://www.theregister.co.uk/2007/05/11/vxers_subverts_windows_update/print.html
http://www.scmagazine.com/us/news/article/657068/windows-update-used-download-malware-updates/
Doc
From SANS NewsBites Vol. 9 Num. 40 (5/18/2007), this correction was published:
Regarding the story we ran in the last edition of NewsBites about
attackers using BITS (Background Intelligent Transfer Service) as a
vector of infection: We would like to clarify that for a computer to
become infected with the Trojan through BITS, there must already be
malware present on that machine. We regret our omission and apologize
for any problems it may have caused.
WORMS, ACTIVE EXPLOITS, VULNERABILITIES & PATCHES
--Attackers Using BITS to Download Malware
(May 10, 11 & 14, 2007)
Attackers are using the Background Intelligent Transfer Service (BITS)
to circumvent firewalls and plant malware on computers. Microsoft uses
BITS, an asynchronous file transfer service, to deliver patches through
Windows Update. BITS has "automatic throttling so downloads don't
impact other network chores. It automatically resumes if the connection
is broken." Because BITS is "baked in" to some versions of Windows, it
is considered a trusted program and therefore avoids the firewall. In
late March 2007, a trojan infected computers using BITS causing mny
computers to be infected.
http://www.computerworld.com/action...cleBasic&articleId=9019118&source=rss_topic17
http://www.theregister.co.uk/2007/05/11/vxers_subverts_windows_update/print.html
http://www.scmagazine.com/us/news/article/657068/windows-update-used-download-malware-updates/
Doc
From SANS NewsBites Vol. 9 Num. 40 (5/18/2007), this correction was published:
Regarding the story we ran in the last edition of NewsBites about
attackers using BITS (Background Intelligent Transfer Service) as a
vector of infection: We would like to clarify that for a computer to
become infected with the Trojan through BITS, there must already be
malware present on that machine. We regret our omission and apologize
for any problems it may have caused.
Last edited: