About InfoWorld : Advertise : Subscribe : Contact Us : Awards : Events : Store
InfoWorld HomeNewsTest CenterOpinionsProduct GuideTechIndex
 COLUMN ARCHIVE  FORUMS
 

COLUMN

 
Window Manager
Brian Livingston

Descan your network

A SMALL COMPANY is about to go live with a big idea that you can greatly benefit from.

   ADVERTISEMENT
  

Free IT resource

Virtualization Insights from Top Experts - Learn how virtualization gets real!

Sponsored by Dell

Free IT resource

TechNet: More ways to know it, share it, and keep it running.

Sponsored by Microsoft

RELATED LINKS
»  IE 7 bug reopens debate over patch responsibilities
»  Woman ordered to pay for file-sharing will appeal
»  McAfee to buy SafeBoot for $350M
»  Security RSS feed 

IDG ENTERPRISE NETWORK
Research Reports  (CIO)
Ask the Expert  (CIO)

TOP NEWS 


IT SOLUTION SEARCH
The company is Descan.net, and the idea is to identify and halt the "script kiddies" who are infiltrating and subsequently attacking our computer networks.

An example of the kind of attack I'm talking about is the recent infestation known as SQLSnake or Spida, which attempts to take control of systems running Microsoft SQL Server.

Shortly after security groups sent out their first announcements about SQLSnake on May 20, its probes briefly became the most prevalent attack on the Internet, according to Dshield.org, which monitors such intrusions.

Methodically testing IP addresses around the world, SQLSnake looks for SQL Server machines with a system-administrator account of "sa" and a blank password, which was at one time installed by default. Whether you blame novices who don't know they need to set the password or Microsoft for distributing a product with such a weak default, there are a lot of such systems. The vulnerable components may also be installed by Visio Enterprise Network Tools or Microsoft's Access 2000, Project Central, or Visual Studio 6.

SQLSnake isn't just a harmless nuisance. Once it finds an opening, it sends the vulnerable system's password database to an e-mail address in Singapore. (This address is now shut down, but we may never know how many passwords it received.)

Even worse, infected machines begin their own scans. This creates mucho traffic. MyNetWatchman, another monitoring group, at one point detected 300 new servers being infected per hour. (For additional information, see http://www.mynetwatchman.com/kb/security/ports/6/1433.htm and http://online.securityfocus.com/news/444.)

Descan.net is a well-thought-out effort to stop this nonsense. You download a small, free listening agent and install it on a firewall or a machine outside your firewall that's running Linux 2.4 or later. (A version for Windows servers is coming.)

The agent reads only one small part of Internet traffic, called the SYN packet, and ignores all other content. This alone is enough to catch scanners.

Descan.net engineering manager David Graves says there are hundreds, not thousands, of bad actors in the world, and they can be stopped. The company's logs show that its agent issued an alarm about SQLSnake probes on April 27, more than three weeks before the first public warnings.

Richard Leeds, chairman of Descan.net, says ISPs and the FBI could use these alarms to shut down and prosecute offenders. The for-profit company plans to sell add-on services to ISPs and corporations, which means Descan.net will have enough revenue to continue supporting its agent.

I'll have more next week, but meanwhile go to http://www.descan.net/joinin.html and get the code.


Send tips to brian@brianlivingston.com. He regrets that he cannot answer individual questions. Go to http://www.iwsubscribe.com/newsletters to get his Window Manager column and EBusiness Secrets e-zine free via e-mail.




RELATED SUBJECTS

Security

MORE >


SPONSORED WHITE PAPERS
EMC - Lower costs and improve reliability-Get the EMC CLARiiON white paper!
Ciphertrust - Are you ready for Sobig.G? Learn how to protect your email systems.
CDW - Personal attention. CDW. The Right Technology. Right Away.
EMC - Explore key performance features and capabilities of EMC ControlCenter 5.1.1.
Intel - Free Intel white paper shows you how to deploy a secure wireless LAN
Cisco - FREE WHITE PAPER: BLUEPRINT to design and implement secure VPNs
Verity, Inc. - "Mass Consolidation Hits the Web-Search Market"
McDATA - Download a FREE storage consolidation white paper from McDATA(R).
Lucent Technologies - Overcoming Common Firewall Limitations
Lucent Technologies - Leverage Your Mobile High Speed Data Access. Download Free White Paper!
Nokia - Get the scoop! Mobilizing business white papers & case studies.
BMC Software - Maximize the Potential of Enterprise Data: Free white paper!
Network Associates - Free white paper - Strategies for Optimizing Network Costs and Benefits
Entrust - Manage identities across applications. Improve productivity.
Stalker Software - CommuniGate Pro - Transform your Email and Calendaring
Remedy - A NEW Gartner Research Note:Producing Quality IT Services

Search the IDG White Paper Library:


SPONSORED LINKS

INFOWORLD MARKETPLACE


» IT Compliance Conference: Nov. 5-7 in San Diego
Best Practices, Peer Experiences, & Expert Advice for Building a Defensible IT Compliance Program
» FREE Sophos Threat Detection Test
Is your AV catching everything it should? Free virus, spyware and adware scan.
» IT Audit Checklists
Prepare for your next internal IT audit. Checklists cover security, risk management, PCI, and more.
» FREE White Paper: Mitigating Rock Phish Attacks
Standard anti-phishing methods cannot defeat complex Rock Phish attacks. Learn how to fight back...
» Apply BPM and ITIL at your IT Help Desk
ServiceWise brings BPM to complete IT service while eliminating integration cost. Learn more here.




 HOME  NEWS  TEST CENTER  OPINIONS  PRODUCT GUIDE  TECHINDEX   About : Advertise : Subscribe : Contact Us : Awards : Events 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy

All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses, phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

Computerworld :: Network World :: CIO :: PC World :: Darwin :: CMO :: CSO
IT Careers :: JavaWorld :: Macworld :: Mac Central :: Playlist :: GamePro :: GameStar :: Gamerhelp
ITWorld Canada :: Computerwoche :: Techworld UK :: tecChannel :: IDG.se :: IDG.no