According to this article here, the latest variant of Netsky doesn't even need anyone to open an attachment as it uses XML (which can be rendered through an email client in a preview pane). Downright scary!
If you're using Outlook/IE/OE, better start looking for an alternate email client, however, it makes me wonder how much longer it is before we see a strain written to detect what client you're using (I use Opera's for example) and alter code accordingly...at run-time.This new V variant has malicious XML code hidden in the message body of the email. When a user opens the email to read it, the code automatically seeks out a known object validation vulnerability in Microsoft Corp.'s Outlook and Internet Explorer software. The vulnerability allows the malicious code to be trusted, installed and executed on the local system.
Once the computer is infected, the malicious code will install a backdoor that listens to TCP ports 5556 and 5557. Netsky-V is designed to launch denial-of-service attacks on several Web sites between April 22 and April 28. The sites to be attacked include kazaa.com; emule.de; cracks.am; freemule.net, and keygen.us.
EDIT: possible "workarounds" would be to immediately deny all traffic leaving out of ports 5550-5560 (if you have a software firewall or a router) to prevent your ISP shutting you down because you were part of a possible DDOS.




Reply With Quote