myITforum.com

Welcome to myITforum.com Sign in | Join | Help
in Search

Harry Waldron at myITforum.com

Sharing Security Developments, and Best Practices for corporate and home users

W32.Spybot.ACYR worm - Exploits the unpatched Symantec SYM06-010 issue

This new IRC based threat attempts to spread using a number of security exploits, including the SYM06-010 vulnerability recently highlighted by several security sources.  Staying up-to-date on all software updates as well AV protection, can prevent the 7 different methods this worm tries to infect vulnerable systems.  

SC Magazine Article
http://www.scmagazine.com/uk/news/article/606932/botnets-exploit-patched-symantec-stack-overflow-flaw/

Symantec Weblog
http://www.symantec.com/enterprise/security_response/weblog/2006/11/spybot_attempts_to_exploit_old.html

W32.Spybot.ACYR Description
http://www.symantec.com/enterprise/security_response/writeup.jsp?docid=2006-112810-5302-99

New Botnet impacts Symantec Client Port 2967 on unpatched PCs
http://msmvps.com/blogs/harrywaldron/archive/2006/11/27/new-botnet-impacts-symantec-client-port-2967-on-unpatched-pcs.aspx

 

Spread by exploiting the following vulnerabilities:

Comments

No Comments
Powered by Community Server (Commercial Edition), by Telligent Systems