Welcome | Sign In
ECommerceTimes.com
Security

Windows Vulnerability Scans Increase - Worm Likely To Follow

Print Version
E-Mail Article
Reprints
Windows Vulnerability Scans Increase - Worm Likely To Follow

Forrester research director Michael Rasmussen said the high activity surrounding the Windows vulnerability indicates a worm is soon to come.


How Much is 'Free' Costing You?
Learn how DaveRamsey.com saw a 567% uplift in ROI with Omniture. This complimentary guide and webinar cover the most important factors in selecting an analytics solution. Download Now.

New coded exploits that take advantage of a widespread Microsoft (Nasdaq: MSFT) Windows vulnerability have been posted online. By most reports, malicious scans to expose vulnerable systems are running rampant a week after government warnings regarding the flaw.

Security experts said the scans for the vulnerability -- which involves a flaw in the Remote Procedure Call (RPC) protocol that could allow malicious users to execute code remotely -- are continuing amid actual attacks.

Not only does the pattern of vulnerability, exploit, attack seem to be quickening, but the typical evolution of the exploits is resulting in increasingly harmful payloads, which could lead to destruction, modification or theft of data, experts said.

"We're going to have competing exploits published with more interesting payloads," Gartner (NYSE: IT) vice president of research Richard Stiennon told TechNewsWorld, referring to backdoor trojan add-ons, which quietly allow remote control of a machine. "The one we won't get a chance to examine is going to be the one that's the worm. It's got such a potential for damage."

Windows Shopping

Ever since Microsoft disclosed the RPC vulnerability on July 16th, security experts and government officials have warned of a looming attack or worm that could take advantage of it. The critical software hole affects all of Microsoft's recent operating systems, including Windows NT 4.0, Windows 2000, Windows XP and Windows Server 2003.

Stiennon said the number of scans for systems that have not yet patched the RPC vulnerability's port 135 is rising dramatically as would-be attackers check for machines that are open to attack. He reported 3,500 source addresses scanning for the vulnerability -- more than double the number of scans in early July, which averaged 900 source addresses for the month.

Toolkits for Trouble

Dan Ingevaldson, engineering manager for Internet Security Systems' X-Force, said automated scanning tools -- sometimes called "root kits" -- are contributing to the scanning increase and adding backdoor trojans designed to control computers in the background.

Ingevaldson told TechNewsWorld that there have been reports of scans and attacks affecting academic and university networks, which are particularly vulnerable because of their openness and large numbers of computers and users.

Internet carriers and service providers also are being targeted because, in serving their customers, they are not blocking or filtering traffic, according to Ingevaldson. A malicious user who penetrates an ISP network server conceivably could have access to many hundreds of potentially vulnerable PCs.

Worm on the Way

Forrester research director Michael Rasmussen said the high activity surrounding the Windows vulnerability indicates a worm is soon to come.

"I definitely think that we're very close to seeing a worm," he told TechNewsWorld. "I hate to raise a red flag and then have nothing happen, but the truth is, there's a legitimate likelihood we'll see an attempt through that exploit."

Rasmussen said a worm based on the RPC vulnerability could be released simply to spread itself or might be used in a targeted attack to destroy or steal information using a malicious payload.

Patching Problematic

Stiennon said that with millions of machines at risk, installation of the patch provided by Microsoft often is too time-consuming -- especially in large corporations -- to roll out quickly enough to stop the attacks.

"There just is not time to patch all of the machines in the universe. That's a very, very frustrating piece of advice to give somebody," Stiennon said, referring to the difficulty of patching hundreds or thousands of servers.

However, security experts did suggest alternative ways of covering the vulnerability, such as using firewalls and filtering or blocking port 135.

Vital Part Vulnerable

Experts said the RPC vulnerability is particularly difficult to deal Increase Customer Sales with Email Marketing -- Free Trial from VerticalResponse with because the remote-control feature is such an important part of the Windows operating system.

"It would be great if we could say we don't need RPC, but we do," Stiennon said. "Microsoft uses it for a lot, including for active directory authentication."

Ingevaldson said the RPC protocol is important, for example, for Outlook e-mail to communicate with Exchange servers.

"It's woven very closely throughout the Windows operating system," he said.


Print Version E-Mail Article Reprints More by Jay Lyman


More by Jay Lyman

Open Source Developer Dumps Novell Over Microsoft Deal
December 26, 2006
A key open source developer, Jeremy Allison, who cofounded the Samba project, has resigned from Novell in protest over the company's recent agreement to enter a collaborative arrangement with Microsoft. The deal has created an uproar in the open source community because it does not treat all recipients of the GPL equally and thus violates the spirit of the license, critics say.
Financial Firms Tap Microsoft for Linux
December 22, 2006
Three major financial institutions are among the first companies to go to Microsoft for Linux services, provided through an agreement the software giant struck with Novell. Although a recent survey showed customer approval of the collaboration, many members of the open source community view Novell's move as sleeping with the devil.
Mozilla Beefs Up Security in Firefox 2.0
December 21, 2006
Mozilla's latest update to its open source Firefox browser includes security measures targeting phishers. Phishing scams that use social engineering techniques to dupe Web surfers into revealing personal financial information have become an effective way for cybercriminals to conduct their nefarious activities on the Internet.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network