ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security management Toolkit

Networks must counter triple threat

John McCormick

Published: 21 Aug 2003 12:40 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

After several months of relative calm on the virus front, with only low-level threats, last week the MSBlast worm assaulted many networks and wreaked havoc on a lot of PCs. This week, the Welchia worm -- which is actually supposed to remove Blaster -- arrived and began causing additional problems. Not only that, but a hot new version of the old Sobig mass-mailing worm has turned lethal and begun infecting many systems with its own brand of mischief.

MSBlast
Despite repeated warnings from Microsoft, columnists, and even the US federal government, a lot of systems are experiencing serious denial of service (DoS) attacks from the worm (also know as Msblast.exe, Blaster, Lovesan, and Posa) worm. Blaster takes advantage of a DCOM RPC vulnerability in newer Microsoft Windows operating systems. If an unpatched system with an open port 135 is attacked, the worm will attempt to install and run msblast.exe.

Fortunately, the initial worm was poorly designed. However, by Wednesday 13 August, Kapersky Labs reported that its security team had already seen a slightly "improved" version that could coexist in the same computer with the original version -- meaning that you can have two Blaster infections simultaneously. Files in the new version are teekids.exe (5.3K) and penis32.exe (7.2K).

As CNET News.com reported, "MSBlast does not spread via email. Instead, it scans the Internet on port 135 looking for vulnerable computers. When it finds one, it attempts to exploit the DCOM RPC buffer overflow, create a remote root shell on TCP port 4444, then use FTP to download a file called msblast.exe onto the infected computer. MSBlast contains a denial-of-service (DoS) attack aimed at Microsoft's windowsupdate.com. The attack will start on 15 August and continues throughout the end of the year."

Fix
This worm is easy to block by closing port 135 or by applying the Microsoft patch provided in Microsoft Security Bulletin MS03-026. But what if you have an infected system? Many users with the infection report their computers are rebooting so often and generating so many error reports that they are unable to download the patch.

Simply activating Windows XP's minimal Internet Connection Firewall (ICF) appears to make it possible for XP-based systems to stay online and download removal tools or the patch. Symantec reports that other firewalls may be able to provide the necessary protection to help repair the system even after infection.

Next

Previous

1 2 3


  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
183 out of 356 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:



Related Jobs

Embedded C / C++ Developer - Gloucester - 40,000

Embedded C - Micro Controller - Developer - Gloucester - 40,000 My client, international market leaders based in the Forest of Dean, are urgently ...

Tier 1 investment bank they are seeking an Oracle\\sybase Project DBA.

The project is to port the Openlink application from a Sybase platform to an Oracle platform. My client is a tier 1 investment bank they are seeking ...

SAN Systems Administrator

Storage Management Team Responsibilities:- SAN Configuration Zoning / Masking / Switch & port configuration Storage Allocation Port allocation ...

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

Featured Talkback

It seems to me this is a burden being placed on the wrong shoulders. There is not an It system in the world that can stop an individual taking information in their heads and spewing out at the nearest undesirable third party.

By: RonaldWilkins

Read full story:
Deloitte: People are still weakest security link

DOWNLOAD

Security Essentials

Security Downloads

There are masses of security suites out there for small businesses. Here's a selection to get you started

Editor’s Rating
1 Norton 360™
2 AVG Anti-Virus Free Edition Rating: 10
3 PC Tools AntiVirus Free Edition
4 Kaspersky Internet Security

See All Software

In association with Symantec