Advertisement
Promo

Security threats Toolkit

MSBlast still spreading strongly

Published: 18 Aug 2003 08:40 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Earlier reports that network traffic caused by the MSBlast worm dropped 30 percent to 40 percent may not mean that the worm is slowing, a major provider of network services said on Friday.

Instead, the worm seems to have been spreading at nearly the same rate over the past few days, according to Internet service provider Akamai Technologies.

"A lot of the network operators started filtering port 135," the data channel used by the worm, said Andy Ellis, chief security architect at Akamai. "That made it look like the number of infected machines was dropping."

In reality, the rate at which the MSBlast worm -- named for the worm's filename, "msblast.exe" -- is compromising computers seems to have dropped only slightly, Ellis said. The worm started spreading on Monday and has infected from 300,000 to a million computers, according to Akamai data.

A wide range of estimates for the spread of a worm are a common problem in gauging the effects of such an attack.

The latest data from security company Symantec, which uses a large intrusion-detection network to record the Internet addresses of infected Windows PCs and servers, estimates that 380,000 addresses have become home to infected computers since Monday morning.

The data does not necessarily correspond to the number of computers infected, as one Internet address can be the home to an entire network of computers, many of which are infected. On the other hand, the data also doesn't take into account any machines that have been cleansed of the infection since the worm began spreading. Moreover, most dial-up and some broadband Internet users receive a new Internet address every time they connect to their provider, making it appear that many more machines are infected than really are.

"For a Windows XP machine, it inherits a new IP (Internet Protocol address) every time it reboots," said Alfred Huger, senior director of engineering for Symantec's security response.

Symantec's data also shows a 30 percent to 40 percent decrease in traffic between Monday and Tuesday of last week. Huger agreed that the filtering being done by Internet service providers may well be the cause.

"The question is, 'how long will they keep that (filtering) up?'" he said. "It costs a great deal of money -- in CPU time and bandwidth."

The new data comes on the same day that Microsoft managed to dodge an impending denial-of-service attack. The attack, which would have levelled a flood of data at Microsoft's Windows Update site, was foiled when the software giant deleted the address the worm was targeting. The worm is expected to continue to spread despite the aborted attack.

Microsoft also announced on Friday that an email hoax is circulating. The subject line of the email is "updated," and the message appears to contain a critical update to patch systems against the MSBlast worm. In reality, clicking on the attached file will infect the recipient's computer with a Trojan horse program. Antivirus company Sophos dubbed the new program Graybird. Microsoft warned consumers that the company never uses email to distribute patches.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
96 out of 169 people found this useful


Full Talkback thread

1 comment

  1. This is so typical. The patch was released in Jul... Anonymous

Company/Topic Alerts

Create a new alert from the list below:



Video icon

Video

Sentry Posts Blog

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment

Authentication risks all too human

Risks to successful online banking identification and authentication using smartcards involve a mixture of human and technological factors, according to the European Network and Information... More

1 comment

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

2 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters