Worm Lays Waste To IT's Defenses
Politics, project delays and an ineffective response allow for a Sasser disaster.
Computerworld - I was planning to spend my week evaluating disk encryption products before the Sasser worm breached our defenses. What's more frustrating than the worm, however, is the fact that proposed projects that could have prevented it have been bogged down for a number of reasons.
My team and I are almost done selecting a patch management product and have all but decided on PatchLink Update from PatchLink Corp. in Scottsdale, Ariz. We run a wide range of servers and operating systems, and PatchLink seemed to work with the majority of them during our evaluation.
Meanwhile, we continue to deal with frustrating patching problems. The W32/Sasser attack is the latest example.
Sasser takes advantage of a previously known vulnerability within Microsoft's Local Security Authority Subsystem Service, which helps manage security and authentication for Windows networking. Had we applied the appropriate patches when they were released, my company might have avoided the worm.
As it was, we first realized that something had gone wrong when the IT help desk received a spate of calls about arbitrary system shutdowns and references to a dialog box indicating an "LSA Shell" problem. At about the same time, network bandwidth usage spiked.
We turned to our in-house Snort intrusion-detection system expert, who quickly associated the traffic with Sasser. This worm attacks by looking for vulnerable machines through TCP Port 445, which is used for Windows networking. Once Sasser finds a vulnerable host, it spreads itself by installing a file transfer protocol server on Port 5554 and leaves Port 9996 open for commands to execute. It then modifies several registry entries and services, causing the system shutdowns. Finally, it spreads by scanning other systems for vulnerable hosts and directing those to the FTP server port to download the malicious code.
The impact of Sasser on my company was substantial. Help desk calls started coming in from all of our hub sites as well as from overseas and remote users with corporate Digital Subscriber Line connections. Although we knew we had to find every infected system, we lacked the time and resources to locate them all. So, to buy time, we asked the network engineering group to reconfigure the access control lists on our network devices to block Ports 5554 and 9996. We use Mountain View, Calif.-based Solsoft Inc. to centrally manage many of our ACLs. Unfortunately, we also have many network devices that it doesn't manage, and we spent several hours visiting every one of them.
After the ACLs were updated, network degradation decreased, as did the



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
- Identity Governance: The Business Imperatives
- This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make... All Security White Papers
- Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game - When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
- Introduction to VMware vCenter Site Recovery Manager 5
- Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
- The Top Ten Secrets to Avoiding SAN Performance Problems
- Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
- Deduplication Without Compromise
- Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
- Director of Disk Products Discusses DXi6700
- Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts