ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Zotob worm targets Windows 2000

Munir Kotadia ZDNet Australia

Published: 15 Aug 2005 08:55 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Antivirus firms have urged affected users to patch their systems immediately after a worm was discovered over the weekend that exploits a critical vulnerability in some Windows platforms.

The Zotob worm exploits a flaw which primarily affects the Windows 2000 platform but has an impact on Windows XP Service Pack I.

Microsoft released a patch on August 9. The Microsoft Technical Bulletin MS05-039 stated that a successful exploitation would allow the attacker to "take complete control of the affected system ... install programs; view, change, or delete data; or create new accounts with full user rights."

The worm does not affect Windows XP SP2 or Windows Server 2003 systems.

Mark Sinclair, technical services director at Trend Micro Australia, told ZDNet Australia that it was about to issue a yellow alert -- which means the worm is being reported in at least two [global] regions and there is a high potential for damage -- for Zotob after receiving infection alerts from customers.

"We are seeing some evidence of [infections] today -- I can't talk about which companies in particular but they are big enterprises. We are getting reports from those customers that they are getting infected by this particular worm," said Sinclair.

However, companies should not panic ... yet.

"It is not panic stations at this stage. But given that the vulnerability was only announced last week, it is a very quick turnaround for virus writers and it could get nasty," said Sinclair.

Allan Bell, marketing director for McAfee Asia-Pacific, said most large organisations could avoid the worm by making sure they block ports 445 and 139 on their firewall.

"These particular ports are used for file sharing and most corporates should have them blocked off. It is unusual for a corporate to have those open because you don't normally want somebody remotely accessing your systems," said Bell.

Antivirus firms are particularly worried because of the number of Windows 2000 systems that are still in use. According to a recent study published by asset management specialist Assetmetrix, Windows 2000 is still installed in more than 50 percent of computers used by large corporations worldwide.

Graham Cluley, senior technology consultant at Sophos said in a statement yesterday: "There will be many Windows computers that will not have been patched yet and may be vulnerable to infection and compromise. Everyone should act swiftly to ensure their PCs are properly protected with antivirus software, firewall software and up-to-date security patches."

Click here to download the patch.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
93 out of 166 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Business Development Director / Rail Industry

A well established Engineering organisation have a new challenging opportunity for a Business Head / Business Development Director to join and head ...

URGENT - ASSOCIATE MEDICAL/MEDICAL DIRECTOR - DIABETES - SE - ~ 100K

Medical Director/Associate Medical Director - Diabetes: My Client, a Global Pharmaceutical Company, is urgently seeking to recruit a Medical Director ...

Sales Manager / Sales Director - University /HEI - Bristol 80k OTE

Huxley Assocaites are looking for a Senior Sales Manager to become Sales Director for our exclusive communications client based in the Bristol area. ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Biometric devices. Do you need one?

When saying “biometrics” I am not thinking about law enforcement, AFIS systems, national ID and visa projects. I first think about personal solutions that will make my life easier.... More

1 comment

Barracuda launches counter-suit agains...

Court cases are never pleasant or simple. The ongoing battle between security companies Trend Micro and Barracuda Networks took a new twist on Wednesday, when Barracuda launched a counter-suit... More

Post a comment

Mobile Speed Demon: Wireless Surpasses...

Mobile Speed Demon: Wireless Surpasses Landline Author: Eric Everson, Founder MyMobiSafe.com As I look around my house and throughout my network of friends, I instantly realize... More

Post a comment