Feeds

Kazaa and eDonkey brace for NetSky-Q onslaught

Zombie Nightmare

  • alert
  • submit to reddit

Next gen security for virtualised datacentres

Zombie PCs infected with the NetSky-Q worm are set to launch distributed denial of service attacks against P2P and warez sites tonight.

The worm will attempt to flood the main Web sites of Kazaa and eDonkey with spurious traffic between 00:01 8 April and 11 April (time taken from system clocks). Other sites including www.cracks.st, www.cracks.am and www.emule-project.net are also targeted for attack. File-sharing networks themselves won't be affected by the worm, only access to Web sites.

NetSky-Q, which first appeared on 29 March, includes a message from the virus authors embedded within its code. The previously unknown "SkyNet Antivirus Team" from Russia claim they are educating users, and want to prevent hacking and sharing of illegal content.

Between 14 April and 23 April a much rarer worm - NetSky-T - will launch a fresh wave of attacks against a similar set of sites: cracks.am, emule.de, kazaa.com, freemule.net and keygen.us. A few copies only have this low-risk virus have escaped onto the Net, so the consequence are likely to be limited.

Targeted sites have already begun to make preparations in advance of the anticipated onslaught.

The eMule project has posted a notice advising users that its main emule-project.net site will be unavailable "because of the upcoming DDoS Attack against our servers" between today and 16 April. It advises users to visit a mirrored site - www.emule-project.org - instead during the attack.

Carole Theriault, a security consultant at Sophos, said it is unclear how intense the NetSky-Q attack might be. She thinks that relatively small sites targeted would find it difficult to fend off attack, even though they've had a week to prepare for the assault. DDoS attacks are notoriously difficult to defend against.

In February, SCO pulled the plug on its main Web site, following a huge DDoS attack initiated from PCs infected with the MyDoom worm. It decamped to an alternative site, www.thescogroup.com, after the attack began. RIAA and Microsoft have also been prominent targets for DDoS attacks.

NetSky-Q exploits the Microsoft iFrame vulnerability to execute itself automatically on vulnerable machines. The flaw, now three years old, can be patched by following the links in Microsoft's bulletin here.

Advice from anti-virus vendors follows a familiar pattern: block executables files at the gateway, don't open unsolicited email attachments, update AV signature files, apply patches, use a personal firewall and wear a regulation tin-foil hat. ®

Related Stories

NetSky tops virus charts by a country mile
NetSky-Q worm targets Kazaa and eDonkey
SCO sidesteps MyDoom attacks
MyDoom assault forces SCO off the net
Windows Update still standing despite Blaster

The essential guide to IT transformation

More from The Register

next story
Goog says patch⁵⁰ your Chrome
64-bit browser loads cat vids FIFTEEN PERCENT faster!
e-Borders fiasco: Brits stung for £224m after US IT giant sues UK govt
Defeat to Raytheon branded 'catastrophic result'
Chinese hackers spied on investigators of Flight MH370 - report
Classified data on flight's disappearance pinched
NIST to sysadmins: clean up your SSH mess
Too many keys, too badly managed
Attack flogged through shiny-clicky social media buttons
66,000 users popped by malicious Flash fudging add-on
Think crypto hides you from spooks on Facebook? THINK AGAIN
Traffic fingerprints reveal all, say boffins
prev story

Whitepapers

A new approach to endpoint data protection
What is the best way to ensure comprehensive visibility, management, and control of information on both company-owned and employee-owned devices?
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Maximize storage efficiency across the enterprise
The HP StoreOnce backup solution offers highly flexible, centrally managed, and highly efficient data protection for any enterprise.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.