ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Jobs
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Security management Toolkit

Networks must counter triple threat

John McCormick

Published: 21 Aug 2003 12:40 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

After several months of relative calm on the virus front, with only low-level threats, last week the MSBlast worm assaulted many networks and wreaked havoc on a lot of PCs. This week, the Welchia worm -- which is actually supposed to remove Blaster -- arrived and began causing additional problems. Not only that, but a hot new version of the old Sobig mass-mailing worm has turned lethal and begun infecting many systems with its own brand of mischief.

MSBlast
Despite repeated warnings from Microsoft, columnists, and even the US federal government, a lot of systems are experiencing serious denial of service (DoS) attacks from the worm (also know as Msblast.exe, Blaster, Lovesan, and Posa) worm. Blaster takes advantage of a DCOM RPC vulnerability in newer Microsoft Windows operating systems. If an unpatched system with an open port 135 is attacked, the worm will attempt to install and run msblast.exe.

Fortunately, the initial worm was poorly designed. However, by Wednesday 13 August, Kapersky Labs reported that its security team had already seen a slightly "improved" version that could coexist in the same computer with the original version -- meaning that you can have two Blaster infections simultaneously. Files in the new version are teekids.exe (5.3K) and penis32.exe (7.2K).

As CNET News.com reported, "MSBlast does not spread via email. Instead, it scans the Internet on port 135 looking for vulnerable computers. When it finds one, it attempts to exploit the DCOM RPC buffer overflow, create a remote root shell on TCP port 4444, then use FTP to download a file called msblast.exe onto the infected computer. MSBlast contains a denial-of-service (DoS) attack aimed at Microsoft's windowsupdate.com. The attack will start on 15 August and continues throughout the end of the year."

Fix
This worm is easy to block by closing port 135 or by applying the Microsoft patch provided in Microsoft Security Bulletin MS03-026. But what if you have an infected system? Many users with the infection report their computers are rebooting so often and generating so many error reports that they are unable to download the patch.

Simply activating Windows XP's minimal Internet Connection Firewall (ICF) appears to make it possible for XP-based systems to stay online and download removal tools or the patch. Symantec reports that other firewalls may be able to provide the necessary protection to help repair the system even after infection.

Next

Previous

1 2 3


  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
183 out of 356 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:



Sentry Posts Blog

Nasa and the virus

Yesterday the BBC ran a story about a computer virus making it into orbit, which I read with incredulity. OK, it's a nice silly season story on the surface, but what really got me was... More

3 comments

Customer data found on eBay server hig...

The recent news about customer details being retrieved from a server sold on eBay is yet another story about the sorry state of information security in the electronic age (see: http://news.zdnet.co.uk/...m).... More

Post a comment

Does it matter if you are an aardvark...

In spam terms, apparently it does. According to Cambridge University security expert Richard Clayton, if your email address is aardvark at animal.net, you are more likely to receive... More

5 comments

Featured Talkback

It seems to me this is a burden being placed on the wrong shoulders. There is not an It system in the world that can stop an individual taking information in their heads and spewing out at the nearest undesirable third party.

By: RonaldWilkins

Read full story:
Deloitte: People are still weakest security link

DOWNLOAD

Security Essentials

Security Downloads

There are masses of security suites out there for small businesses. Here's a selection to get you started

Editor’s Rating
1 Norton 360™
2 AVG Anti-Virus Free Edition Rating: 10
3 PC Tools AntiVirus Free Edition
4 Kaspersky Internet Security

See All Software

In association with Symantec