• The move to the new server is done. There are some software and database maintenance updates in process. This has us passing the hat around to help out. We appreciate any donations. Seriously, even a dollar helps. The payment page may be found here - https://www.audiokarma.org/support.html

Attackers Using BITS to Download Malware

Dr. Strangelove

Super Member
Banned
From today’s SANS NewsBites Vol. 9 Num. 39

WORMS, ACTIVE EXPLOITS, VULNERABILITIES & PATCHES
--Attackers Using BITS to Download Malware
(May 10, 11 & 14, 2007)
Attackers are using the Background Intelligent Transfer Service (BITS)
to circumvent firewalls and plant malware on computers. Microsoft uses
BITS, an asynchronous file transfer service, to deliver patches through
Windows Update. BITS has "automatic throttling so downloads don't
impact other network chores. It automatically resumes if the connection
is broken." Because BITS is "baked in" to some versions of Windows, it
is considered a trusted program and therefore avoids the firewall. In
late March 2007, a trojan infected computers using BITS causing mny
computers to be infected.
http://www.computerworld.com/action...cleBasic&articleId=9019118&source=rss_topic17
http://www.theregister.co.uk/2007/05/11/vxers_subverts_windows_update/print.html
http://www.scmagazine.com/us/news/article/657068/windows-update-used-download-malware-updates/

Doc

From SANS NewsBites Vol. 9 Num. 40 (5/18/2007), this correction was published:

Regarding the story we ran in the last edition of NewsBites about
attackers using BITS (Background Intelligent Transfer Service) as a
vector of infection: We would like to clarify that for a computer to
become infected with the Trojan through BITS, there must already be
malware present on that machine. We regret our omission and apologize
for any problems it may have caused.
 
Last edited:
Register to hide this ad
Back
Top Bottom