ZeroHour
Schneier on Securitypublished ()ingested Bruce Schneier

A Security Vulnerability in the KmsdBot Botnet

mediumVulnerabilityimportance 30
Full article103 words · extracted from schneier.com · click to collapse

Security researchers found a software bug in the KmsdBot cryptomining botnet:

With no error-checking built in, sending KmsdBot a malformed command­—like its controllers did one day while Akamai was watching­—created a panic crash with an “index out of range” error. Because there’s no persistence, the bot stays down, and malicious agents would need to reinfect a machine and rebuild the bot’s functions. It is, as Akamai notes, “a nice story” and “a strong example of the fickle nature of technology.”

Tags: botnets, vulnerabilities

Posted on December 15, 2022 at 7:10 AM10 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.schneier.com/blog/archives/2022/12/a-security-vulnerability-in-the-kmsdbot-botnet.html