By Jay Lyman TechNewsWorld Part of the ECT News Network
08/12/03 7:48 AM PT
Although the Blaster worm was designed to propagate without wreaking havoc on systems or data, there is a chance that a variant or copycat might deliver a more damaging payload.
Increase Customer Sales with VerticalResponse Email Marketing! Quickly and easily send email newsletters, coupons & sales announcements to your customers – no technical expertise needed. Sign up for your Free Trial today and send 100 emails on us!
A widely anticipated threat materialized this week as a worm that exploits a Microsoft (Nasdaq: MSFT) Windows flaw began infecting some of the millions of vulnerable machines around the world.
Experts said the relatively simple "Blaster" worm -- also referred to as "LoveSan" -- was spreading at a steady pace Monday but was not infecting machines at the same rate as the earlier Nimda and Slammer worms, which quickly clogged corporate networks during those outbreaks.
While it might be slowing or stifling some corporate networks, the Blaster worm is not carrying a malicious payload to damage machines or data. However, antivirus experts are on the watch for variants of the threat that might be more destructive.
In addition, the worm includes a denial-of-service (DoS) component whereby infected machines will simultaneously flood the Microsoft Windows Update Web site on August 16th, Symantec (Nasdaq: SYMC) Security Response senior director of engineering Al Huger told TechNewsWorld.
"Even with proactive patching, there will be tens of thousands of hosts taking part in that attack," Huger said. "As long as the worm is circulating the Internet, it will be trying a denial-of-service on Windows Update."
Steady Spreader
The worm was expected following last month's announcement by Microsoft of a widespread weakness in Windows' Remote Procedure Call (RPC) protocol. Shortly after the announcement, exploit code was posted online to take advantage of the vulnerability.
Experts estimated hundreds of millions of machines were at risk because the vulnerability was present in all recent versions of Windows -– Windows NT 4.0, Windows 2000, Windows XP and Windows Server 2003.
However, the Blaster worm is not having nearly the same impact as earlier worms, likely because of the way it is written. "It's written a great deal more simply than the [other worms]," Huger said. "It's not the Corvette of worms."
Persistent Problem
While Blaster might not be spreading as quickly as Code Red did, Huger predicted it might actually be worse in terms of eradication.
"It will be with us for some time to come," he said. "There are just so many computers vulnerable, and this one is on a larger number of deployed hosts than Code Red was."
He noted that the worm is indeed causing disruptions around the Net. Some enterprise IT shops have reported that internal production systems are unavailable.
Advanced Billing
McAfee vice president Vincent Gullotto, who said there have been no reports of major network outages because of the worm, told TechNewsWorld that the spread might have been tempered by attention paid to the issue before the worm was released.
"The notice has certainly helped it not go as big as it might have," he said.
Symantec's Huger agreed that several potential victims were able to patch their systems -- by blocking port 135, for which the worm scans while looking for new hosts -- prior to being infected. However, he said, there are also many cases of corporations leaving their systems unprotected and thus winding up infected by the worm.
Offensive Offspring
Gullotto said that although the worm was designed to propagate without wreaking havoc on systems or data, there is a chance that a variant or copycat might deliver a more damaging payload. He added that a variant might not be obvious because it likely would have a different name or use a different technique to scan for vulnerable systems.
Huger said there is no question that there will be variants. Whether or not those variants will be designed to damage systems is the key factor.
"I think at this point, people should be concerned with how the children of this worm are going to look," he said.
DoS Delivery
Huger noted that as the worm spreads, it is gathering hosts for the DoS attack that is set for August 16th. Computers infected with the worm will be remotely directed to flood Microsoft's Windows Upadate with messages, rendering the site inaccessible.
Although the worm has the potential to cause Internet slowdowns, Microsoft would be most significantly affected by the DoS attack.
Still, Huger said, Microsoft probably will be able to mitigate that attack because of the advance warning.
If you cannot update on the windows update site, you are able to get the blaster worm HotFix, as ...
Next Article in Security
Benchmarking Encryption Technology August 12, 2003
Although the cost of encryption technology -- be it Triple DES, AES, Blowfish, RSA or one of many other alternatives on the market -- is negligible, implementing it can lead to higher storage and processing costs.
Denial-of-Service Attack Brings Down Microsoft August 04, 2003
There was speculation that the latest denial-of-service attack to hit Microsoft's site was a harbinger of more serious security issues to come.
MiMail E-Mail Worm Spreads Quickly August 04, 2003
While a patch was made available in late April for the Outlook Express vulnerability that is exploited by MiMail, the usual reluctance to apply patches left systems at risk.
Advisory: Windows Platform Widely Vulnerable to Attack August 01, 2003
Microsoft's latest security breach -- which affects all Windows servers and the Windows XP client -- is the result of relying on outdated protocols that were never meant to be deployed between machines or over networks.
Published Code Exposes Windows Flaw July 28, 2003
Security experts said the discovery and distribution of code to exploit the Windows flaw is consistent with the pattern of vulnerability followed by exploit followed by attack.
Related News Alerts
More by Jay Lyman
Open Source Developer Dumps Novell Over Microsoft Deal December 26, 2006
A key open source developer, Jeremy Allison, who cofounded the Samba project, has resigned from Novell in protest over the company's recent agreement to enter a collaborative arrangement with Microsoft. The deal has created an uproar in the open source community because it does not treat all recipients of the GPL equally and thus violates the spirit of the license, critics say.
Financial Firms Tap Microsoft for Linux December 22, 2006
Three major financial institutions are among the first companies to go to Microsoft for Linux services, provided through an agreement the software giant struck with Novell. Although a recent survey showed customer approval of the collaboration, many members of the open source community view Novell's move as sleeping with the devil.
Mozilla Beefs Up Security in Firefox 2.0 December 21, 2006
Mozilla's latest update to its open source Firefox browser includes security measures targeting phishers. Phishing scams that use social engineering techniques to dupe Web surfers into revealing personal financial information have become an effective way for cybercriminals to conduct their nefarious activities on the Internet.