Skip the navigation
)

Update: Feared RPC worm starts to spread

It could clog the Internet with traffic and allow a hacker to steal or corrupt data

By James Niccolai, IDG News Service
August 12, 2003 12:00 PM ET

IDG News Service - Security experts today warned of the first self-propagating virus to take advantage of a widespread vulnerability reported last month in Microsoft Corp.'s Windows operating systems.

Known by various names, including Blaster and Lovsan, the worm virus has begun to infect computers at homes and businesses and could clog the Internet with traffic and allow a malicious hacker to steal or corrupt data stored in an infected system, experts said.

The vulnerability, a buffer overrun in a Windows interface that handles the remote procedure call (RPC) protocol, was acknowledged by Microsoft in a security bulletin posted July 16 (see story). Along with government and private security organizations, Microsoft has been urging customers to install a security patch in order to protect against attack.

The flaw affects several versions of Windows, including Windows NT 4.0, Windows XP and Windows Server 2003, making potential targets of millions of desktop and server computers. Experts have warned of the potential for serious disruption of the Internet.

Symantec Corp. said today that based on the number of submissions received from customers and information from Symantec's DeepSight Threat Management System, Symantec Security Response had upgraded the threat to a Category 4 level.

Category 4 means that the virus is considered "dangerous [and] difficult to contain," Cupertino, Calif.-based Symantec said in a statement on its Web site. "The latest virus definitions should be downloaded immediately and deployed."

According to Symantec, the worm contains the following text, which is never displayed: "I just want to say LOVE YOU SAN!! billy gates why do you make this possible ? Stop making money and fix your software!!"

In a statement on its Web site, Helsinki, Finland-based F-Secure Corp. gave the virus its highest level alert, which is issued for a "worldwide epidemic of a serious new virus."

The spread of the worm appeared to increase rapidly today.

Yesterday, Tokyo-based security vendor Trend Micro Inc. said it had received reports of several infected machines. The worm was observed scanning for vulnerable systems and then sending itself to those machines using Port 135, the company said. The worm will also launch a denial-of-service attack against Microsoft's www.windowsupdate.com Web site on Aug. 16 and Aug. 31, and on every day from Sept. 1 through the end of the year, Trend Micro said.

Trend Micro gave the worm an overall risk rating of medium but rated the damage and distribution potential as high. Network Associates Inc.'s McAfee unit also rated the worm "medium on watch" for both home and business users.

Netsolve Inc., an IT services company in Austin that provides managed security services to about 1,000 businesses, said the worm was spreading rapidly and had been observed in several of its customers' networks yesterday afternoon. However, Chuck Adams, the company's chief security officer, said it was too early to say for sure how much damage, and what type of damage, the worm will cause.

"The impact is pretty small right now, but based on the analysis we've done on the (exploit) code we've captured, it's going to be a propagation pattern similar to SQL Slammer," he said, referring to a widespread worm that affected Microsoft's SQL Server 2000 database earlier this year.

Based on Netsolve's early observations, Blaster isn't likely to spread as widely as SQL Slammer, Adams predicted.

"I don't think it will be as large because there are some limitations" to Blaster, he said. For example, SQL Slammer tried to take advantage of multiple Windows vulnerabilities, while Blaster appears to exploit only one, he said.

The most troubling aspect of Blaster is that besides propagating itself, the worm installs a backdoor program on infected systems and reports back to an Internet relay chat server that the system has been compromised, Adams said. A malicious hacker could use that information to identify a compromised system and then attempt to delete or access data stored on it, he said.

Computerworld's Ken Mingis contributed to this report.




Reprinted with permission from IDG.net. Story copyright 2012 International Data Group. All rights reserved.
What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?
Additional Resources
Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Security White Papers
Driving Secure Enterprise File Sharing and Syncing in the Enterprise
GroupLogic's new activEcho is the industry's only secure Enterprise File Sharing and Synching solution that balances the need for simplicity for the end...
The Enterprise File Sharing Option
Enterprises and IT departments need to address several critical security issues when considering file sharing and syncing products. Many of today's solutions do...
Security Strategies to Virtualizing Internet-Facing Applications
The IT organization at Intel has set a goal to transition their enterprise to a private cloud for their Office and Enterprise applications....
Cloud Security Planning Guide
Cloud security considerations span protecting hardware and platform technologies in the data center to enabling regulatory compliance and defending cloud access through different...
Cloud Security Vendor Round Table
This vendor round table guide will help you to evaluate different cloud technology vendors and service providers based on a series of questions...
All Security White Papers
Security Webcasts
Live Webcast
Data Privacy and Protection in Production Environments: New Research from Ponemon Institute
Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT

In a recent study conducted by Ponemon Institute, fifty-five percent of respondents...
Data Privacy and Protection in Production Environments: New Research from Ponemon Institute
Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT

In a recent study conducted by Ponemon Institute, fifty-five percent of respondents...
Security Certifications 101 - BlackBerry and all those acronyms what do they mean and why they matter?
FIPS, Common Criteria, CAPS, AISEP, NFC, NIST, Fraunhofer SIT, CESG, DSD - these are just some of the government and industry certifications which...
BlackBerry PlayBook OS 2.0 Security Overview
The presentation provides an overview of BlackBerry PlayBook OS 2.0 security capabilities and features, including: BlackBerry® Balance™ technology, BlackBerry® Bridge, data-at-rest protection, and...
BlackBerry NFC Security Overview
The presentation on NFC security will provide an overview of the security protections built into the BlackBerry platform to protect users, application developers...
Playing Defense: Staying on Top of Your Disaster Recovery Game
When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
All Security Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs