Free Newsletters
Technology & Business Daily

InfoWorld
Log-in | Register

Opportunism, spam behind new worms

Windows vulnerability presents a target

By Paul Roberts, IDG News Service
August 21, 2003
 

A widespread and dangerous Microsoft Corp. Windows vulnerability, spam e-mail messages and human frailty combined in recent weeks to produce a flood of new Internet worm attacks, according to experts at leading antivirus and e-mail security companies.

Free IT resource

Virtualization Insights from Top Experts - Learn how virtualization gets real!

Sponsored by Dell

Free IT resource

TechNet: More ways to know it, share it, and keep it running.

Sponsored by Microsoft

August saw four major worm infections alone, according to antivirus company Symantec Corp., making it one of the busiest months for antivirus vendors in recent memory.

"Taken all together, this has been a more intense week, in terms of virus activity, than any we've seen," said Chris Belthoff, senior security analyst at antivirus company Sophos PLC.

That activity included the appearance of W32.Blaster on August 11, a virulent new Internet worm that exploited a flaw in the Windows implementation of the RPC (Remote Procedure Call) protocol, which enables client and server applications to communicate across networks.

The worm spread worldwide in a matter of hours, infecting hundreds of thousands of Windows machines before the outbreak began to wane, according to Internet Security Systems Inc. (ISS) .

A survey of 1100 organizations by TruSecure Corp. found that almost 21 percent were infected by the worm, with 15 percent of corporations worldwide recording a "moderate" or "major" impact on operations by Blaster.

The impact among home users, who are generally less well-protected than organizations, is believed to be even greater, according to Marc Maiffret, chief hacking officer at eEye Digital Security Inc.

As Blaster waned, new worms emerged that exploited the same vulnerability including W32.Welchia, also known as Nachi, which attempted to patch Windows systems with the RPC vulnerability. 

At the same time, a new version of the Sobig worm, Sobig.F, began bombarding e-mail accounts around the world, prompting new infections, warnings from antivirus companies and hurried updates of antivirus software. 

E-mail filtering company MessageLabs Ltd. of New York City intercepted ten times the normal number of e-mail viruses in the 24 hours after Sobig.F appeared and has intercepted over three million copies of the virus so far, according to CTO Mark Sunner.

But the recent spate of large outbreaks don't herald the arrival of a new and more dangerous generation of viruses, as did the appearance of the Code Red and NIMDA worms in 2001, or the SQL Slammer worm in January, according to Belthoff.

"I think it's an intersection of a couple things," Belthoff said. "Blaster and (Welchia/Nachi) -- those are all opportunistic worms. They're all based on this Windows (RPC) vulnerability. Blaster didn't take any in-depth skill to write."

In the case of the new Sobig worm, improvements in that worm's ability to send out copies of itself in e-mail messages meant that even a small number of infected machines could generate massive amounts of infected e-mail traffic, according to Sunner.

MessageLabs researchers believe that there is a link between the Sobig author and the spamming community and that machines that are compromised by Sobig are being used as distribution stations for spam e-mail, Sunner said.

Sixty six percent of the e-mail messages MessageLabs intercepts come from such machines, commonly referred to as "open proxies." And the increase in spam traffic corresponds closely to the appearance of worms like Sobig, Sunner said.

The intense media attention given to the worm outbreaks may have also stimulated virus and worm writers, according to Neel Mehta, a research engineer at ISS X-Force.

"Virus writers get recognized and that encourages them and others to repeat their actions," he said.

While experts tend to agree on the myriad of causes for the new worms, there is less agreement about what to do to stop them in the future.

Most agree that software companies such as Microsoft need to do a better job of weeding out glaring security holes like the RPC vulnerability while companies should be better about promptly applying software patches as they become available.

"You need balance with the (software) vendors. They need to build more stable code, but IT departments need to take patching more seriously and make it part of their overall security plan," Belthoff said.

Corporate IT security personnel should also do a better job educating employees about proper etiquette for opening or forwarding suspicious e-mail messages.

"If your end-user population is educated in the work environment, (e-mail worms) shouldn't be a problem at all," Belthoff said.

But others disagree, saying that part of the blame lies with antivirus technology companies, which still require their customers to apply software patches and updates to be protected against new threats.

"Traditional antivirus protection is very reactive in nature. Antivirus vendors don't know about a new virus until their switchboards start to light up with calls from their customers, then it's a race against time," Sunner said.

Virus writers like the author of Sobig are increasingly savvy and look to exploit that, he said.

"They're trying to get a virus out there for a short period of time and exploit that window of time using a mass propagation tool like e-mail," Sunner said.

More security vulnerabilities like the RPC vulnerability are inevitable, as are new worms to exploit them, according to experts.

Even more troubling, the window of time between when vulnerabilities are disclosed and when worms and viruses that exploit them appear is likely to close even more.

It took six months for the SQL Server vulnerability to be turned into the SQL Slammer worm. The Windows RPC vulnerability was exploited in just three weeks.

"There is more awareness of vulnerabilities and more motivation to go ahead and write malicious code, because of the attention previous worms have gotten," Mehta said.





 

TOP NEWS:


»  Sun's expanded storage lineup takes on data boom
Sun Storage J4000 arrays can cost just $1 per gigabyte for bulk storage, with significant savings resulting from free software

»  Hands on with Giga-byte's M912X mini-laptop
Giga-byte netbook's 8.9-inch touchscreen that can swivel around 180 degrees makes it stand out from the rest of the pack

»  Google tool creates 3D social spaces on Web sites
Google's Lively platform integrates with the regular Internet, enabling users to create a 'room' and embed it with their Web site or blog

»  Microsoft innovation winner finds gold in green
Imagine Cup winner develops a way for people to report environmental problems with their mobile phones

»  Symantec warns of new Word attack
Symantec says cybercriminals are exploiting an undisclosed vulnerability affecting Microsoft Word

»  Microsoft vs. VMware: Rumble in the virtual world
As Hyper-V marks Microsoft's entry into virtualization, market leader VMware must consider new strategies for survival against the software behemoth




Solutions to the Toughest IT Challenges in Remote Offices
Though small in size, remote offices face many of the same IT challenges as larger central offices. This Webcast zeroes in on the top line challenges to deliver information that can provide immediate benefits to your business. Sponsor: AMD and Dell

»  Click here to view this Webcast
  Zombie PCs Are Attacking Your LAN
A recent study showed that malware-infected zombie PCs are now a bigger threat to ISPs and Web infrastructure than DoS attacks. As this brand new IT Strategy Guide explains, an increased use of peer-to-peer techniques by the attackers has made it harder to fight back. Download now, compliments of Verio:

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 

FIND PRODUCTS AND COMPANIES
» COMPLETE PRODUCT GUIDE



TECHNOLOGY INDEX
• Applications
• Application Development
• Security
• Networking
• Wireless
• Platforms
• Hardware
• Data Management
• Storage
• Web Services
• Business
• Telecom
• Professional Services
• Standards

TECH WATCH 


What's the 411 on GOOG-411?
Just as Google has become synonymous with "performing a Web search," 411 is understood to mean "information" -- as in "what's the 411?" I was thus surprised to discover, from a billboard, no less, that the king of search is taking on the ...

Apple HTML source reveals 'iPhone Extreme'
"This one's a stretch..." reports AppleInsider. Um, yeah. Reporting on HTML code sightings of product names could be called a stretch, but iPhone Extreme has a ring to it. Now, that sounds like the product Apple should have released first, rather ...

COLUMNISTS

Unified under law
Ephraim Schwartz's Column and Blog (InfoWorld) - In the litigious world we live in, deploying a unified communications platform in your enterprise could...
» MORE COLUMNISTS

MORE INFOWORLD BLOGS


Open Sources 
Product Management
When I joined MySQL four years ago, there was quite a lot of debate about product management. We didn't actually have ...

Zero Day 
Botnet herders tending smaller flocks
New research backs up the theory that botnet operators are keeping their networks smaller in a continued effort to keep ...



• Advice Line
• Database Underground
• The Deep End
• Enterprise Mac
• Geeks in Paradise
• Grid Meter
• The Gripe Line
• InfoWorld Daily
• Inside IT
• IT Troubleshooter
• ITXtreme
• Open Sources
• ProdBlog
• Real World SOA
• Reality Check
• Security Adviser
• SMB IT
• The Storage Network
• Tech Watch
• Virtualization Report
• Zero Day

ADVERTISEMENT


RESOURCE CENTERadvertisement 

GOVERNMENT IT & POLICY
'If you don't go after the network, you're never going to stop these guys. Never.'
From the State Department, All the News for Inquiring Minds
TechPresident, the Internet Citizenry's New Consensus Taker



Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS  CAREERS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist