ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Security threats Toolkit

Increase in Windows attacks reported

Joris Evers CNET News.com

Published: 01 Sep 2006 09:05 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Several security experts are warning of increased cyberattacks targeting Windows PCs, but Microsoft says all is calm on the attack front.

The SANS Internet Storm Center, Symantec, McAfee and several other security companies are warning of a new worm that wriggles into Windows PCs by way of a security flaw for which Microsoft issued a patch with security bulletin MS06-040 on 8 August.

On Thursday, Symantec raised its ThreatCon to Level 2, which means an outbreak is expected. In an alert to customers, the company said it is seeing "ongoing and frequent attacks" that utilise the MS06-040 flaw. There are now six variants of malicious code that exploit the vulnerability, Symantec said.

"The potential impact of these threats is exaggerated due to reports of successful compromise of Windows NT systems, for which there is no patch available," Symantec said in its alert. Windows 2000 and Windows XP are also at risk, according to Symantec.

Symantec was joined in its alert by the other security watchers. The SANS Internet Storm Center, which monitors network threats, noted on its Web site that several people had reported increased malicious activity. Analysis of the threat, however, found that attacks should be "relatively easy to catch". Most antivirus software detects the bad code.

Microsoft, however, has not seen an increase in malicious activity associated with MS06-040, a security hole in a Windows component related to file and printer sharing.

"Microsoft has been watching diligently since the release of MS06-040 for any increase in malicious activity... At this time we are not seeing an increase over the already existing limited attacks attempting to exploit that vulnerability," a Microsoft representative said in a statement on Thursday.

Security tools from Microsoft and third parties offer protection against all current exploits of the flaw, according to Microsoft. Still, those users who have not yet applied the 8 August update are encouraged to do so immediately, Microsoft said.

Malicious code that exploits the Windows hole has already led to significant growth in the number of hijacked PCs, CipherTrust said last week. The messaging-security company has seen a 23 percent growth in the total number of so-called zombie PCs it has detected and attributed that to the spread of Mocbot worm variants that exploit MS06-040.

If a PC is hijacked, SANS Internet Storm Center recommends completely erasing the hard drive and reinstalling the computer's operating system. "That sounds drastic... but it gets rid of the worm, gets rid of the botnet, plus you have a brand new box," according to the ISC.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
429 out of 535 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:








Sentry Posts Blog

Nasa and the virus

Yesterday the BBC ran a story about a computer virus making it into orbit, which I read with incredulity. OK, it's a nice silly season story on the surface, but what really got me was... More

3 comments

Customer data found on eBay server hig...

The recent news about customer details being retrieved from a server sold on eBay is yet another story about the sorry state of information security in the electronic age (see: http://news.zdnet.co.uk/...m).... More

Post a comment

Does it matter if you are an aardvark...

In spam terms, apparently it does. According to Cambridge University security expert Richard Clayton, if your email address is aardvark at animal.net, you are more likely to receive... More

1 comment