SecureScoutLogo.jpg
Backdoor program Remote Windows Shutdown (RWS)



Go to Vulnerabilities List


General Info


TC: 12014
Description: 'Remote Windows Shutdown' does exactly what its name implies!
It is usually installed via a trojan.
TC Impact: Attack
Service: Remote windows Shutdown



Specific Operations and Actions:


Vulnerability Publication: Unknown
Advisory Copyright: Unknown
Summary: A backdoor program has been found on the target system and must be removed.
Risk: High
CVSS 2.0 metrics: Access Vector: Network
Access Complexity: Low
Authentication: None
Confidentiality Impact: None
Integrity Impact: None
Availability Impact: Complete
CVSS 2.0 Base Score: 7.8
Vulnerability Impact: Gain Root
Host Impact: An attacker can reboot the system at will.
Nature of Remediation: Remove program.
Step required to fix the reported vulnerability:

***** Solution type: Reinstall System (root kit found) *****

Remove the server component.
Make sure that the system was not tampered with.



Glossary and References :


References:
Information : http://www.dark-e.com/archive/trojans/rws/

CVE Link: CVE-1999-0660
CVE Compatible

Glossary: Backdoor
Trojan Horse


© 2003-2010 NexantiS Corporation (www.securescout.com)
SecureScout is a trademark of NexantiS
All Rights Reserved
All products names referenced herein are trademarks of their respective companies

SecureScout products are certified:
CVE Compatible
SANS TOP 20 Compatible
CVSS Compatible (Common Vulnerability Scoring System)