ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

Hacker exploits make PC worms more deadly

Wendy McAuliffe ZDNet.co.uk

Published: 18 Oct 2001 12:20 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Computer worms are set to become a more deadly combination of virus writing and hacker exploits, according to security experts at Symantec.

Code Red and Nimda marked the demise of socially engineered worms, by combining a blended threat of proven hacker exploits. Both worms attacked the same buffer-overflow vulnerability in Microsoft's IIS software, while Nimda additionally incorporated a mass-mailing component enabling the virus to propagate on a massive scale. Neither of the worms relied on the traditional need for an infected computer user to double-click on a malicious attachment.

"Nimda and Code Red have eliminated the need for human intervention, by virus writers using what hackers have already provided," said Eric Chien, chief researcher at Symantec. "One year ago email worms were the big threat, as they spread quickly and far -- but now a lot more virus writers will be looking at the hacker worm."

Chien predicts that by next year, the "blended" threat of computer worms could be enough to cause a serious Internet slowdown. Antivirus experts at Symantec have already developed an algorithm to prove that by removing human interaction from the virus equation, every PC connected to the Internet could be affected by a single worm within 20 minutes.

But the trend towards blended virus attacks is blurring the lines of responsibility for computer worms. On Wednesday, Microsoft launched a verbal attack on security firms and hackers who release what it calls virus "blueprints". A study done by Microsoft on recent attacks by worms such as Code Red and Nimda found that each had been prefaced by the release of so-called exploit code -- sample programs created by security firms and hackers to exploit software flaws.

"Responsibility lies with the people who release the worm, not necessarily the people who wrote it," said Chein. The Anna Kournikova virus, for example, was written with the help of an existing virus toolkit available on the Internet, but Chein argues that the script kiddie who unleashed the virus is the person ultimately responsible for any damage caused to the networks.

The changing trend in computer viruses is also likely to affect the structure of IT security companies. Hacker worms will make it necessary for antivirus units to merge with intrusion detection systems, according to Chein. "Companies who only concentrate on the antivirus side won't survive," he concluded.

See the Viruses and Hacking News Section for the latest headlines.

See the Net Crime News Section for the latest on hacking, fraud, viruses and related issues.

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum.

Let the editors know what you think in the Mailroom. And read other letters.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
32 out of 72 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

INFRASTRUCTURE ANALYST

Working within a team of experts, youll be involved with day-to-day operational duties in relation to Active As an IT all rounder, youll have good ...

Head of Sales and Customer Relations

Develop major areas of focus and key selling messages/training for each Operational Group (OG)/industry vertical, working closely with OG leads and ...

Enterprise Applications Finance Oracle - Manager - London

We provide consultancy services to some the strongest brand names globally, plus a variety of small and dynamic mid-market firms. Management and ...

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

2 comments

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains