Ares.exe - Spreading

Spreading

The following propagation methods are sub-modules to the port scanning engine:

  • MS03-026 RPC DCOM Remote Buffer Overflow
  • MS03-026 LSASS Remote Buffer Overflow
  • MS05-039 Plug and Play Remote Buffer Overflow
  • Attempts to hijack common Trojan horses that accept incoming connections via an open port.
  • The ability to spread to systems by brute forcing a login. A good example is Telnet or Microsoft's Server Message Block

Generally, it has been observed that every custom modified variant of Agobot features a selection of the above methods as well as some "homebrew" modules, which essentially are released exploits ported to its code.

Names and such can be added via the xml files the produce variable shuffle imports.

Read more about this topic:  Ares.exe

Famous quotes containing the word spreading:

    As the tenor roars his passion, I think sadly of my spreading middle, and his.
    Mason Cooley (b. 1927)

    Glory is like a circle in the water,
    Which never ceaseth to enlarge itself,
    Till by broad spreading it disperse to nought.
    William Shakespeare (1564–1616)

    ... less and less of luck, and more and more
    Of failure spreading back up the arm
    Earlier and earlier ...
    Philip Larkin (1922–1986)