Advertisement
Promo

Online business Toolkit

ISPs cut off virus-infected customers

Wendy McAuliffe ZDNet.co.uk

Published: 10 Oct 2001 15:51 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

British Internet users who fail to protect their machines against virulent computer viruses such as Nimda could have their Internet connections suspended by their Internet service provider.

UK ISP Telewest has been the first to take direct action against customers who have refused to patch their computers against the Nimda worm, or have left infected PCs running. The company insists that these are "sensible" measures to protect its blueyonder customers from malicious worms that are able to self-propagate across networks without user intervention.

"Telewest, in line with other service providers, has put into practice a virus protection strategy to prevent infection of our network," said a spokeswoman at the company. "Protective measures include the temporary removal of service from customers who are virus-infected and who may have not taken appropriate preventive measures."

The destructive Nimda virus was unleashed into the wild last month, and comprised a mass-mailing component enabling it to propagate on a massive scale. The worm spreads in several ways: it can arrive as an attachment entitled Readme.exe, and is programmed to automatically archive the attachment so that the executable file can run without the end user having to double-click on it. Nimda can also be spread from infected servers running Microsoft IIS software, which it uses to attack other servers across the Internet.

The ISP crackdown is to prevent customers' computers from acting as a proxy to scout for other vulnerable PCs. "Some people may be a Typhoid Mary, spreading the disease onto anyone that they are in contact with, and so need to be isolated," said Graham Cluley, senior technology consultant at security firm Sophos. "But I hope that any ISP would get in contact with the customer first."

Freeserve used Nimda as an opportunity to remind users of their responsibility to patch their machines against known and publicised exploits. An email was circulated to all customers that read: "It is important that Internet users take safeguards against viruses of this nature. Your PC may otherwise become infected without your knowledge. If this happens, you may easily infect other peoples' PCs with which you have contact."

"It all comes down to the terms of service, and deciding where you draw the line," said Graham Cluley. "If a site is vulnerable (i.e. hasn't been patched) but hasn't been infected, do you suspend that account?"

See the Viruses and Hacking News Section for the latest headlines.

See the Net Crime News Section for the latest on hacking, fraud, viruses and related issues.

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum.

Let the editors know what you think in the Mailroom. And read other letters.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
25 out of 45 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:











Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010

Video icon

Video

Google Chrome

Roundup: Full coverage of Google Chrome

The search giant has launched a beta of its own open-source browser, sending a clear challenge to Microsoft in the way it lets users work with applications More

Blog: Google Chrome has Microsoft's code inside, says MS manager

And furthermore, he says, that's a good thing... More

Blog: Google Chrome — nine things we've found since launch

Google must be very happy with the coverage Chrome has gathered. But it's not all good news... More


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters