ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Experts predict new virus rampage

Published: 24 Oct 2003 08:45 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A program that exploits a software vulnerability Microsoft recently described could spell trouble for companies that haven't quickly patched their system, security experts said this week.

Released on a security mailing list earlier this week, the program takes advantage of a flaw in Microsoft's Messenger Service to cause Windows-based computers to crash. The vulnerability affects almost every current Microsoft Windows system, leaving security experts concerned that independent hackers will quickly find a way to take control of a large number of computers by exploiting the flaw.

"I think we are going to see a repeat of the (MSBlast worm)," said Vincent Weafer, senior director of Symantec's antivirus research centre, referring to the program that spread across the Internet in August. The program used a similarly widespread Windows flaw to break through computers' security. "It took three weeks (for hackers) to figure out a working worm in that case."

Programs that illustrate how to take advantage of such holes are known as "exploit code" and are seemingly being developed faster, coming out soon after the first notification of a flaw, a recent study by Symantec found.

This isn't the first time the Windows Messenger feature has been the source of users' pain. Not to be confused with Microsoft's instant messaging services, the Messenger feature allows Windows applications to communicate and send data among themselves. The feature has already been exploited by some spammers to send messages directly to users' desktops.

The flaw that led to the MSBlast worm affected another Windows service, known as the distributed component object model (DCOM), which allows components of the operating system to communicate. The software is a fundamental piece of the operating system, so the flaw affected all versions of Windows.

Microsoft announced the latest flaw a week ago as one of several security problems it highlighted in its first monthly security update. At the time, the software giant said all the flaws could be exploited to create a worm. "All of the five critical (vulnerabilities) are, of course, critical, so that means they are wormable," Jeff Jones, senior director of Microsoft's security business unit, said last week.

On Monday, a researcher released source code to a security mailing list, showing how to crash a computer using the flaw. Because the issue affects so many computers, companies should patch the issue quickly, said Craig Schmugar, virus research engineer for Network Associates.

"The greater the number of vulnerable systems out there, the greater the concern," he said. "We definitely take the demo code seriously."

Information on how to protect your PC can be found here.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
106 out of 188 people found this useful



Company/Topic Alerts

Create a new alert from the list below:



Related Jobs

Data Manager - London - 55,000 Plus

Ability to communicate complex technical issues to technical & non-technical audiences. You will join a team of experts involved in data ...

Software Architect, Dorset

Compact Framework and have the ability to communicate with various groups of people. You will also be responsible for assisting the Director of ...

Head of Programs BRISTOL

Comfortable in a leadership position with the ability to successfully plan, co-ordinate, communicate and manage change. Rapid understanding of ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment