ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Jobs
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Security threats Toolkit

Security time bomb is triggered by 'rogue laptops'

Munir Kotadia ZDNet.co.uk

Published: 04 Jun 2004 18:00 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Unpatched notebook PCs are a weak link in enterprise security arrangements, experts warned on Friday.

Most enterprises have a significant number of desktop PCs that are vulnerable to an attack from the numerous worms and viruses that already exist on the open Internet; but these machines are protected, temporarily, by the corporate firewall.

The LSASS vulnerability, which Microsoft patched in April, is still causing a nuisance because there are so many unpatched computers connected to the Internet. Many of these machines are behind a corporate firewall and have so far escaped infection, but security experts say they represent a security time bomb that could be set off by an infected laptop connecting to the internal network.

Mikko Hyppönen, director of antivirus research at F-Secure, said the popularity of the Korgo worm, which takes advantage of the LSASS vulnerability in Microsoft -- the same vulnerability exploited by the Sasser worm -- shows that there must be a lot of computers that have not been updated.

"There are lots of unpatched machines in internal networks that could remain unpatched for years. They are not affected by the initial outbreak because corporate firewalls are protecting them. But eventually, someone brings in a laptop that has been infected and the worm gains access to the closed network," Hyppönen said.

Patrick Hinojosa, chief technical officer at antivirus firm Panda Software, agreed this was a big problem. He said "rogue laptops", which are used by people that are rarely in the office, are usually patched late and can easily bypass the perimeter security measures.

"One problem is that most IT departments do not have centralised control over security on rogue laptops -- they are used by someone that is on the road and are the last computers to get patched by the IT department," Hinojosa said.

Hinojosa said that when one of these rogue computers releases a worm onto the internal network, it spreads very quickly.

"If it is a network-aware worm -- like MSBlast or Sasser -- the speed at which it can go through the subnet is incredible. This is a big problem," Hinojosa said.

F-Secure's Hyppönen said that another factor causing problems is when brand new computers are introduced to the network.

"People buy a new computer that has Windows pre-installed but does not have the most recent patches, so they plug it in and it gets infected. We still see the MSBlast worm popping up, even though it was found last August," Hyppönen said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
107 out of 216 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Sentry Posts Blog

Nasa and the virus

Yesterday the BBC ran a story about a computer virus making it into orbit, which I read with incredulity. OK, it's a nice silly season story on the surface, but what really got me was... More

3 comments

Customer data found on eBay server hig...

The recent news about customer details being retrieved from a server sold on eBay is yet another story about the sorry state of information security in the electronic age (see: http://news.zdnet.co.uk/...m).... More

Post a comment

Does it matter if you are an aardvark...

In spam terms, apparently it does. According to Cambridge University security expert Richard Clayton, if your email address is aardvark at animal.net, you are more likely to receive... More

5 comments