MSMVPS.COM

The Ultimate Destination for Blogs by Current and Former Microsoft Most Valuable Professionals.
Welcome to MSMVPS.COM Sign in | Help
in Search

Harry Waldron - Corporate and Home Security

Latest Security Developments and Best Practices are shared to help keep users safe

MyDoom.M -- DDos Attack against Microsoft by Zindos worm

  I'm guessing that this is most likely an added attack feature the author of the MyDoom.M worm has implemented as a "second wave"

MyDoom.M -- DDos Attack against Microsoft by Zindos worm 
http://secunia.com/virus_information/10909/zindos/
http://www.sarc.com/avcenter/venc/data/w32.zindos.a.html
http://vil.nai.com/vil/content/v_127038.htm

W32.Zindos.A is a worm that performs a Denial of Service (DoS) attack against the domain, microsoft.com. The worm spreads through the backdoor that Backdoor.Zincite.A opens on TCP port 1034.

Due to bugs in the code, when a system that is infected with Backdoor.Zincite.A becomes infected with Backdoor.Zindos.A, an infinite infection loop is entered, with each infection of Backdoor.Zindos.A re-infecting the system. This may cause the system to become slow and unresponsive.

Note: Backdoor.Zincite.A is a backdoor Trojan horse that W32.Mydoom.M@mm drops.

Only published comments... Jul 27 2004, 05:34 PM by Harry Waldron

Leave a Comment

(required) 
(optional)
(required) 
Submit
Powered by Community Server (Commercial Edition), by Telligent Systems