search technology reviews, news, features, group tests
Popular Searches:   free , windows , asus
 |  Register
 |  Newsletters  | 
Sitemap  |  RSS
RSS
Monday November 30, 2009 5:46 AM AEST
Skip Navigation LinksPC Authority > News > Top 10 technologies in a death spiral
NEWS

Message to Gates: 'Fix your software!'

by George V. Hulme , John Kreiser  on Aug 13, 2003
Tags: Message | to | Gates | 'Fix | your | software!

Some call it MSBlast; others know it as LovSan. Regardless of the name, the latest infection to attack Microsoft's Windows operating systems has disabled tens of thousands of computers worldwide, though there's been a fix available for nearly a month.

The worm snarled business networks Tuesday, inundating them with data packets and frustrating home computer users. It forced Maryland's motor vehicle agency to close for the day and kicked Swedish Internet users offline as it spread.

Security experts said the world was lucky this time around because LovSan is comparatively mild and doesn't destroy files, but they fear a subsequent attack exploiting the same flaw could be much more damaging.

Internet performance-monitoring company Keynote Systems said its Internet Health Monitor observed 'massive packet-loss problems' Monday after the worm struck. According to Keynote, when measuring Internet traffic from services provider Level 3 Communications in San Diego to Sprint Corp's services in Boston or New York, latency was consistently about 3 seconds and reached 9 seconds about 30 percent of the time. According to Keynote, normal Internet latency from these two points would be 95 milliseconds. 'Under these network conditions, Web-page downloads will typically time out', Keynote said in its statement.

Keynote said it couldn't confirm that the Internet slowdown can be directly contributed to the MSBlast worm, but the timing of the latency closely coincides with reports of the worm's surfacing.

Security experts have been predicting that a worm would appear since 16 July, the day Microsoft revealed a vulnerability in its Distributed Component Object Service in its Remote Procedure Call interface. The vulnerability affects Windows NT 4.0, 2000, XP, and Windows Server 2003.

'That's just too large of a target pool for them [virus writers] to ignore,' said Russ Cooper, surgeon general of the security services firm TruSecure and editor of the security mailing list NTBuqtraq, in an interview late last month.

The US Department of Homeland Security issued an alert on 30 July warning of a potentially significant impact on Internet operations as a result of the flaw in Microsoft operating systems. Two weeks earlier, on 16 July, Microsoft posted on its Web site a patch that prevents MSBlast and similar infections. The underlying flaw affects nearly all versions of the vendor's flagship Windows operating system.

However, many businesses did not install the patches and scrambled Tuesday to shore up their computers. Security experts said patches often stay on to-do lists until outbreaks occur.

Security vendor Symantec reported that its DeepSight Threat Management System has spotted more than 57,000 systems that have been infected with the worm and are launching probes to infect other vulnerable systems against port 135. Symantec estimates that this worm is spreading at a rate of about 20 percent that of the Slammer worm, which struck in January and infected all of its targeted and vulnerable systems in less than 15 minutes.

According to Lurhq Corp, which said it has obtained a copy of the worm, MSBlast is designed to launch a denial-of-service attack, specifically a Syn Flood, against Microsoft's Windowsupdate.com Web site on 16 August.

Joe Stewart, senior security researcher at Lurhq, said the research on MSBlast is still preliminary, but the security firm believes the worm doesn't have any payload other than the Microsoft denial-of-service attack.

Security vendor Internet Security Systems said successful worm outbreaks have been known to significantly diminish corporate networks and cause widespread denial-of-service interruptions as the worm tries to replicate itself.

Reports from several security vendors indicate failed attempts of MSBlast to replicate itself also are causing systems to crash.

'Until [Monday] afternoon, most of the activity we saw was exploits being used for Internet relay chat distributed denial-of-service bots,' Stewart says. 'This is the first worm that attacks this RPC vulnerability.'

Lurhq says it has seen scanning for vulnerable systems increase more than 300 percent since Sunday. 'And scanning activity was already high,' Stewart added. He says the worm, MSBlast.exe, is about 6KB in size and takes about 20 seconds to infect a vulnerable system and begin scanning for new systems to infect.

Because this worm is attacking a vulnerability found in Windows NT 4.0, 2000, XP, and Windows Server 2003, security experts believe there will be no shortage of unpatched and at-risk systems. 'It could easily be over a million,' Stewart said.

Within the code of the worm is the following statement: 'billy gates why do you make this possible? Stop making money and fix your software!!'

All users--consumers, small businesses, and large companies--are being urged to patch vulnerable systems if they haven't already done so.

Information on the Microsoft vulnerability the worm attacks is available here.

More information on the Microsoft vulnerability and how to secure systems is also available from the CERT Coordination Center.

Copyright (c) 2003 CMP Media LLC

Copyright © 2009 Dennis Publishing
Email a Friend Email this
Print Page Print this
Tweet This Tweet this
Feedback Send us your tips


Ads by Google

Comments

Be the first to comment on this article.
Thoughts on this article? Add a comment below.
Login or register to submit a comment.
 

Top Stories

 All I want for Christmas...Apple slapping on the discount stickers this Friday
If you're looking to buy an Apple product then this Friday is your lucky day, with Apple planning a "Black Friday" discount frenzy.
 
Telstra release slew of new plans, Earth fails to shake
New broadband plans from Telstra with bigger download quotas are welcome, though you'll still find better value with the competition
 
TiVo 2.0:  Revamped content line-up could fuel box bust-up for pay TV competition, as IPTV era begins
TiVo have doubled their drive capacity, introduced IPTV capabilities, vast amounts of new content and better home networking options. But can the marketplace handle another content provider?
 


 
Intel
 
 
Amazing Dell Coupons now available
 
Discover Apple