ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Viruses can be tamed - by upgrading users' brains

Munir Kotadia ZDNet.co.uk

Published: 04 May 2004 17:55 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

PCs are actually safer today than they were four years ago, when the first batch of mass mailing viruses -- such as LoveBug and Melissa were introduced.

The Sasser worm is spreading quickly, automatically infecting Windows systems that are not protected by Microsoft's latest patches. Similar to the Blaster worm that hit last August, Sasser uses a known defect in Windows that allows it to scan for other vulnerable machines without any intervention from the user.

Antivirus firm Panda said that companies are running for cover as all four of Sasser's variants charge up the company's "top ten" most detected viruses chart. According to Panda, Sasser has infected a third of the Taiwan postal service's computers, and the UK Coastguard has reported that its network is under attack from the worm.

Antivirus firm Sophos' senior technical consultant Graham Cluley said new laws have also helped, which means it's harder for the bad guys to get away:

"More countries have introduced computer crime laws," said Cluley, who pointed out that the author of the LoveBug virus, a student from the Philippines, was never prosecuted: "He got away scot free because the crime laws in the Philippines were not strong enough."

Ben Nagy, senior security engineer at eEye, the company responsible for discovering the Windows vulnerability exploited by the Sasser worm, agrees that virus and worm writers are much cleverer than they were four years ago: "Four years ago, your average hacker may have been able to exploit a simple stack-based buffer overflow, but now we are seeing exploits that require a deep understanding of the Windows architecture," he said.

And although virus writers have improved their skills over the past four years, so has the security industry. This means users are actually much safer -- as long as they keep their security software updated. Nagy said the main problems are caused by a lack of patching, not because attackers getting smarter.

"People need to understand that although these exploits are hitting known vulnerabilities, they are not being patched in time because users are not yet accustomed to thinking in that way -- they always want to put it off till tomorrow," said Nagy.

Sophos' Cluley said that although Sasser does not require user intervention to spread, the vast majority of viruses spread because users continue to click on attachments.

"Four years ago, LoveBug didn't rely on any Microsoft vulnerabilities, it relied on the bug in people's brains -- and I don't think we have upgraded enough people's brains yet. If an attachment's name is attractive enough, a large percentage of people will still click on it and get infected," he said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
58 out of 147 people found this useful



Company/Topic Alerts

Create a new alert from the list below:











Related Jobs

Operational Analyst- Edinburgh- 30,000

You will be reviewing and cross checking the daily back-up sequence outlining any failures, timeframes changes etc; Collating and reviewing the ...

Messaging Support Analyst (AD,TREND protection,Exchange) BANKING

You will be supporting Microsoft Exchange, Windows Server, AD, TREND (virus protection) Blackberry Enterprise Server, MindAlign & Mailmarshal. The ...

IT Service Desk Analyst

IT Service Desk Analyst 23,509 - 29,574 (inc.of London weighting) + benefits London This is your chance to help make the capitals streets safer with ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Biometric devices. Do you need one?

When saying “biometrics” I am not thinking about law enforcement, AFIS systems, national ID and visa projects. I first think about personal solutions that will make my life easier.... More

1 comment

Barracuda launches counter-suit agains...

Court cases are never pleasant or simple. The ongoing battle between security companies Trend Micro and Barracuda Networks took a new twist on Wednesday, when Barracuda launched a counter-suit... More

Post a comment

Mobile Speed Demon: Wireless Surpasses...

Mobile Speed Demon: Wireless Surpasses Landline Author: Eric Everson, Founder MyMobiSafe.com As I look around my house and throughout my network of friends, I instantly realize... More

Post a comment