ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

MSBlast still spreading strongly

Published: 18 Aug 2003 08:40 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Earlier reports that network traffic caused by the MSBlast worm dropped 30 percent to 40 percent may not mean that the worm is slowing, a major provider of network services said on Friday.

Instead, the worm seems to have been spreading at nearly the same rate over the past few days, according to Internet service provider Akamai Technologies.

"A lot of the network operators started filtering port 135," the data channel used by the worm, said Andy Ellis, chief security architect at Akamai. "That made it look like the number of infected machines was dropping."

In reality, the rate at which the MSBlast worm -- named for the worm's filename, "msblast.exe" -- is compromising computers seems to have dropped only slightly, Ellis said. The worm started spreading on Monday and has infected from 300,000 to a million computers, according to Akamai data.

A wide range of estimates for the spread of a worm are a common problem in gauging the effects of such an attack.

The latest data from security company Symantec, which uses a large intrusion-detection network to record the Internet addresses of infected Windows PCs and servers, estimates that 380,000 addresses have become home to infected computers since Monday morning.

The data does not necessarily correspond to the number of computers infected, as one Internet address can be the home to an entire network of computers, many of which are infected. On the other hand, the data also doesn't take into account any machines that have been cleansed of the infection since the worm began spreading. Moreover, most dial-up and some broadband Internet users receive a new Internet address every time they connect to their provider, making it appear that many more machines are infected than really are.

"For a Windows XP machine, it inherits a new IP (Internet Protocol address) every time it reboots," said Alfred Huger, senior director of engineering for Symantec's security response.

Symantec's data also shows a 30 percent to 40 percent decrease in traffic between Monday and Tuesday of last week. Huger agreed that the filtering being done by Internet service providers may well be the cause.

"The question is, 'how long will they keep that (filtering) up?'" he said. "It costs a great deal of money -- in CPU time and bandwidth."

The new data comes on the same day that Microsoft managed to dodge an impending denial-of-service attack. The attack, which would have levelled a flood of data at Microsoft's Windows Update site, was foiled when the software giant deleted the address the worm was targeting. The worm is expected to continue to spread despite the aborted attack.

Microsoft also announced on Friday that an email hoax is circulating. The subject line of the email is "updated," and the message appears to contain a critical update to patch systems against the MSBlast worm. In reality, clicking on the attached file will infect the recipient's computer with a Trojan horse program. Antivirus company Sophos dubbed the new program Graybird. Microsoft warned consumers that the company never uses email to distribute patches.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
96 out of 169 people found this useful


Full Talkback thread

1 comment

  1. This is so typical. The patch was released in Jul... Anonymous

Company/Topic Alerts

Create a new alert from the list below:



Related Jobs

Technical Support Engineer Windows XP 2003, Microsoft Outlook, LANs, WANs, DNS,

Technical Support Engineer Windows XP 2003, Microsoft Outlook, LANs, WANs, DNS, - Lambeth - 2198 RM helps to push the boundaries of technology to ...

Middleweight Java Developer Oxfordshire Software Solutions Provider

Java / J2EE, Java Web Developers Huxley Associates are working with a leading technology provider in the Oxfordshire area to recruit talented Java ...

Graduate Software Test Engineer

Products developed by the area include web and server based technologies as well as internet filtering so there are a range of areas to focus on. We ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment

Trades Unions against ID Cards

The Trades Union Congress (TUC) has backed up airport workers protesting against ID cards, the Financial Times reports. In a letter to Home Secretary Jacqui Smith, the TUC said it... More

Post a comment