ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Heard the one about the Stages worm?

Robert Lemos, ZDNet News ZDNet.co.uk

Published: 20 Jun 2000 08:35 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Six weeks after the ILOVEYOU worm hit companies and computer users worldwide, a new worm using the same old tactics invaded several large corporations on Monday.

Both Visa International and Microsoft had shut down email to deal with several infections involving the VBS_STAGES.A worm, sources said Monday.

"The problem is that we are relying on end users," said Dan Schrader, chief security analyst with anti-virus software maker Trend Micro. "There are 30 different files that can be executables. Users cannot keep track of them all. It's time that companies started focusing on a more complete content filtering approach."

Many companies seem to have let security become lax. Despite the Melissa virus attack 15 months ago -- and another rude reminder just six weeks ago by the ILOVEYOU worm -- corporate computers and their users are falling victim to what is quickly becoming an unoriginal ploy.

'Stages' copies the ILOVEYOU worm's tactics almost verbatim.

Posing as a joke file -- rather than an amorous Internet missive -- an infected email attachment, once opened, infects a user's registry and system files with copies of itself. Next, the worm generates an email with one of several randomly chosen subject lines to every address in the user's Microsoft Outlook address book.

Users of other email clients, or users who have patched their Outlook client with Microsoft's new security patch, do not need to worry about spreading the digital disease, although their own PCs can still be infected.

The worm utilises a relatively unknown file format called Windows scrap files. The extension for such a file is normally .SHS, but users will most likely never see the suffix because of a trick virus writers are increasingly using to fool their victims.

According to a CERT advisory released Monday, the security weakness in Windows occurs because the operating system assumes users do not know the extensions for certain file types. Thus, an executible script file (in this case, LIFE_STAGES.TXT.SHS) will appear to be a innocuous text file (such as LIFE_STAGES.TXT).

"A file that appears to be innocent based on its viewable file name may contain malicious executable code," stated the CERT advisory.

Whereas ILOVEYOU deleted files, Stages does not and, in fact, is relatively benign. Future versions created by copycats could easily change that, however.

The worm has mainly infected US computers, according to Trend Micro, whose Virus Tracker showed 430 verified infections among users who checked their PCs with the company's free HouseCall virus checker.

Email service provider MailZone.net caught almost 5,400 copies of the virus from email passing through its system in the past 24 hours. The next most frequent attachment was the G-variant of the ILOVEYOU worm with 4,900 copies.

Microsoft, Visa, and Internet analyst firm Zona Research joined the list of companies hit by the Outlook-client worm on Monday.

A Visa spokesperson who asked not to be identified confirmed that its mail system had been inundated with email containing the virus. The company declined any immediate on-the-record comment. ZDNet News received several emails from Zona Research, indicating that at least two employees at the Internet market research firm had opened the attachment and were infected. Zona also declined comment on the incidents.

Microsoft confirmed its employees had seen the worm but would not confirm reports that its users had been infected.

Trend's Schrader said that, despite the media coverage of such digital infections, users cannot be blamed for the outbreaks.

"Can I blame you if you infect me with a cold? Until we get to the point where we can give users guidelines for simple effective behavior, we cannot blame them," he said.

Take me to the Virus Workshop

What do you think? Tell the Mailroom. And read what others have said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
67 out of 105 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

SQL Server developer wanted, Successful Trading House, Solid education

A fantastic opportunity has opened up within a leading financial company specialising in commodities a very solid market to get into! Get exposure ...

Head of Information

Head of Information Dudley The Dudley Group of Hospitals is a newly opened PFI acute general hospital, based in the heart of the Black Country. The ...

2nd Line Support, Bournemouth

You need to have experience with Windows XP/2000, Exchange, Microsoft Outlook, Active Directory and WAN/LAN. Computer Futures are seeking a 2nd Line ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

2 comments