Advertisement
Promo

Industry watch Toolkit

Server attacks stump Microsoft

Published: 05 Sep 2002 08:36 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft released further details of a rash of attacks on Windows 2000 servers that has so far stumped the software giant's research team.

In an advisory posted on 30 August, Microsoft warned customers that several companies had recently observed an "increased level of hacking activity". Microsoft Product Support Services (PSS) told system administrators to be on the lookout for Trojan horses -- programs that appear to be legitimate but aren't -- and for several specific kinds of odd network behavior.

On Wednesday, Mark Miller, security specialist for the Microsoft PSS, said that the attacks seemed to be ongoing, but at a much reduced level.

"We saw a pretty sharp spike," he said, adding that "we definitely consider this to be hacker activity and not worm activity."

Microsoft has only been able to characterise the attacks by certain files that each compromised machine has in common and that compromised machines have all been running Windows 2000.

One file, "gg.bat", attempts to connect to other computers using various administrator accounts. If successful, the file will then copy other files over to the compromised system. This behaviour is usually considered characteristic of a worm -- but Miller stressed that since the file doesn't copy itself to the victim's hard drive, it shouldn't be considered a worm.

Another file, "seced.bat", changes security settings on the compromised system. This attack could make it easier for a vandal to later log onto the computer and use the system. A third file, "gates.txt", contains a list of numerical Internet addresses. Microsoft, however, is unsure whether they are addresses of compromised systems, computers to be targeted, or some unrelated list.

While the company wouldn't say how many machines or customers had been victims of the attacks, Miller did say that "it has been a significant number".

With the rate of compromise apparently declining, however, Microsoft seems willing to wait before referring incidents to the Microsoft Security Response Center, the company's internal clearing house for information on flaws and bugs. Miller explained that the company has not been able to determine if the attack uses some new flaw in its operating system or just finds success because Windows 2000 system patches are out of date.

"We are still monitoring the situation and we are looking into it," said Miller.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
40 out of 65 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:







Discussions

CA CA

Well..

Thursday 17 December 2009, 12:51 AM

2 comments
CA CA

The sooner...

Thursday 17 December 2009, 12:42 AM

1 comment
CA CA

aye..

Thursday 17 December 2009, 12:30 AM

4 comments
CA CA

Mission accomplished..

Wednesday 16 December 2009, 10:09 PM

2 comments
Video icon

Video

Featured Talkback

In association with Network Liberation Movement
When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters