Advertisement
Promo

Online business Toolkit

Worms target lazy passwords

Published: 11 Mar 2003 09:42 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A spike in Internet traffic caused by a worm over the weekend can be largely blamed on bad passwords and poor security practices, security experts said on Monday.

The Deloder worm, which spreads by communicating with Windows computers that have file-sharing enabled, may have spread to perhaps as many as 10,000 systems using a list of 86 passwords to break into computers running Microsoft Windows NT, 2000 and XP. While not an epidemic, the attack did highlight that people frequently choose easily guessable passwords to guard their computers' security.

"Whether it is a worm or human being that is trying to break into any machine, English words are easy passwords to crack," said Steve Trilling, senior director of research for security software maker Symantec.

Bad passwords are a major chink in the Internet armour surrounding company networks and home computers -- one that worms and viruses will frequently exploit.

The recent LovGate worm -- which appeared on the Internet two weeks ago -- uses a list of 16 passwords as a secondary way to infect computers. The current Deloder worm, also called W32.HLLW.Deloder by Symantec and W32/Deloder.worm by Network Associates, uses its longer list as the primary attack on Internet-connected computers.

It's not surprising that worm writers have started using the technique. By some estimates, a third of computer passwords can be found by systematically trying every word in a smallish dictionary. Limited attacks, such as those using a small dictionary of words that could be bundled up in worm code, have fewer successes but are much faster.

The Deloder worm shows the speed of such attacks. The worm caused a spike in traffic on Saturday and Sunday, but after the weekend had begun to level off, said Johannes Ullrich, chief technology officer for the Internet Storm Center, a service that tracks attacks.

On Saturday, the Internet Storm Center detected Server Message Block (SMB) requests from almost 15,000 sources. The SMB protocol is used by Microsoft for file sharing and is normally used within corporate networks, not on the Internet. For the most part, the service averages about 4,000 such requests. The ISC had increased its threat assessment to a "yellow," or medium rating, over the weekend because of the worm's spread, but decreased the grade to "green" by the end of day on Monday.

Ullrich stressed that bad passwords aren't the only culprit; PC users shouldn't have file sharing turned on, either.

"A strong password would slow the worm down," he said. "But in reality, the best thing to do is to block file sharing. There is no good reason to use this protocol over the Internet."

The Deloder worm uses Windows file sharing to spread, sending attack data to potential victims using port 445. Ports are software addresses that applications use to communicate with other programs running on other computers. The Windows operating system uses port 445 to send data to other computers with whom files are being shared.

On computers that it compromises, the worm will install two programs that allow an attacker to issue commands to the victim computer over the Internet.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
48 out of 67 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Sentry Posts Blog

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment

Authentication risks all too human

Risks to successful online banking identification and authentication using smartcards involve a mixture of human and technological factors, according to the European Network and Information... More

1 comment

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

2 comments

Video icon

Video

Google Chrome

Roundup: Full coverage of Google Chrome

The search giant has launched a beta of its own open-source browser, sending a clear challenge to Microsoft in the way it lets users work with applications More

Blog: Google Chrome has Microsoft's code inside, says MS manager

And furthermore, he says, that's a good thing... More

Blog: Google Chrome — nine things we've found since launch

Google must be very happy with the coverage Chrome has gathered. But it's not all good news... More


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters