ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Flaws set to spawn another Blaster

Ina Fried CNET News.com

Published: 17 Sep 2003 08:54 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Tools have been developed to exploit a recently announced Windows flaw, further increasing the likelihood that new viruses will emerge soon, a security firm has warned.

Ken Dunham, an analyst at iDefense, said on Tuesday that it is "highly likely" that new worms or Trojan horses will emerge in the next few days. These bugs are expected to prey on computers that have not been updated with the latest security patch for Microsoft's operating system.

"A new Blaster-like worm family could be created in a matter of hours or days, now that exploit source code has been posted in the underground," Dunham wrote in an email. "The new attack tool makes it trivial for any malicious actor to gain unauthorised root access to an unpatched computer."

Experts advised people last week that a new virus was reasonably likely, given the fact that the recently discovered Windows vulnerabilities are similar to those that paved the way for the MSBlast worm.

Microsoft is using the warning as a way to remind individuals and companies to install the patch that it made available when it sent out an alert about the latest flaw last Wednesday. Dunham echoed the software maker's advice.

"Computers that have been patched for the... vulnerability thwart this attack," he said. "Unfortunately, a large number of computers remain unpatched."

Microsoft has seen the sample code identified by iDefense and is in the process of reviewing it, according to Amy Carroll, director of product management in a Microsoft security unit.

"It's another reminder of the need to patch," she said. "That message is getting out."

Carroll noted that in the first five days since Microsoft announced the latest vulnerabilities, 63 percent more people downloaded the patch for them than did in the same period for the vulnerability that led to MSBlast.

Carroll also encouraged individual Windows customers to make sure they are using a firewall and antivirus software.

Even as Microsoft explores longer-term ways of improving security, the company is trying to make more modest, but immediate improvements to its software, Carroll said. For example, the company has added to its Web site a tool that, with a user's permission, checks to see if Windows is set to automatically download and install new patches and whether firewall software is turned on.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
83 out of 182 people found this useful


Company/Topic Alerts

Create a new alert from the list below:



Related Jobs

Network Security Lead

The successful candidate will be responsible for the Network and Firewall areas across all projects and the local environment within the site. Job ...

Technical Consultant, Wholesale Banking Payment, Swift, AIX, Watford

This is an application focussed role & your responsibilities will be to install, configure & set-up these Wholesales Banking Payment systems for my ...

TWS Scheduling Specialist - UNIX AIX/TRU64, Windows O/S, MS Office, Shell - St Davids Park, Ewloe, Deeside

Provide 2nd level infrastructure support as required - Undertake the diagnosis and completion of Root Cause Analyses to enable Problem Management as ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

2 comments