On CHOW: The most delicious sandwiches
BNET Business Network:
BNET
TechRepublic
ZDNet

By David Becker
Posted on ZDNet News: Jul 27, 2004 8:05:00 PM

While the spread of the latest version of the MyDoom worm appeared to be quickly halted, the pest lived on Tuesday with a growing host of ancillary infections, including one programmed to launch a denial-of-service attack on Microsoft.

MyDoom.M, a new variant of the prolific worm, came to life Monday and quickly wreaked havoc on Google and other search sites, thanks to a novel method the worm's creator devised to propagate the pest.

But security experts said Tuesday that the worm was quickly dying out, with infections peaking a mere 12 hours after the worm was released.

MyDoom.M leaves behind significant potential for collateral damage from infected and unrepaired PCs, however. Besides propagating itself, the worm's main purpose apparently was to open a "back door" so that infected PCs could be used to host other malicious programs, according to researchers at security giant Symantec.

The first of those parasites, dubbed the Zindos.A worm, was released Tuesday with the intent of crippling Microsoft's main Web site.

According to a Symantec report, Zindos.A is programmed to probe random IP addresses in search of ports left open by Zincite.A, the destructive part of the payload left by MyDoom.M. Once Zindos finds a vulnerable PC, it installs itself and promptly launches a denial-of-service attack against the Microsoft.com domain.

Zindos.A did not appear to have gained a widespread distribution as of Tuesday morning, said Vincent Weafer, senior director for Symantec's security response center. He said Zindos appeared to be a trial bug intended to exploit MyDoom's spread. "I'd say it's an opportunistic worm from another group," rather than the MyDoom.M creator, he said.

Microsoft representatives said Tuesday the company was investigating Zindos and successfully fending off any attacks. "Microsoft has taken steps to ensure that Microsoft.com remains available to customers," according to a company statement. "The Microsoft.com network is stable and has been consistently accessible to customers."

But the situation presented a new and possibly dangerous trend of virus writers using one infection to prime the pump for others, Weafer said. MyDoom.M includes a mechanism to maintain a list of infected systems, permitting the worm's creator to upload new pests while preventing rival attackers from taking over infected PCs. A similar system was recently discovered in the last version of MyDoom, MyDoom.L, and may have been responsible for the fast spread of MyDoom.M, Weafer said.

"We're increasingly seeing infections like this where they're very aggressive during the initial propagation and you see a sharp drop off fairly quickly," he said.

Additionally, MyDoom represents a new trend among malicious code creators of focusing their attacks on known vulnerable PCs, allowing for more rapid and efficient propagation of new pests, Weafer said.

"There's a huge number of compromised machines sitting on the Internet at any one time," he said. "In many cases, these boxes are for hire--they're essentially owned by the virus writers and rented out to the highest bidder."

"It's a matter of how do we reach the people who own those PCs and let them know what's going on?" Weafer added. "It's not just MyDoom--they're wide open to anything attackers want to throw at them."

CNET News.com's Ina Fried contributed to this report.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 109 Talkback(s)
Flaws
I'll agree but then we need to hold every OS out there just as responsible. I agree that MS has many holes(actually it's the structure of it's build). But there is no OS out there that would not have ... (Read the rest)
Posted by: IT Scion Posted on: 08/02/04 You are currently: a Guest | | Terms of Use
Here's an option  Domb2 | 07/27/04
RE:Here's an option  dnirG_ot_xA_oN | 07/27/04
Not a bad idea. And all software, OS's included,...  bjbrock | 07/27/04
won't work now too many people already have peecees  Squawkbox | 07/27/04
And get a license to leave you house.  voska | 07/27/04
This is the STUPIDIST thing I've read here in months...  BitTwiddler | 07/28/04
Thank you.  Immanuel Tranz-Mischen | 07/28/04
Stupid is as Stupid does....  Wolfie2K3 | 07/28/04
This is the STUPIDIST thing I've read here in months...  blacksheepxlch1 | 07/29/04
MyDoom  wtasbury@... | 07/29/04
MyDoom  blacksheepxlch1 | 07/29/04
Here is a wiser option  michael-t | 07/27/04
I like your idea the best  Squawkbox | 07/27/04
I think  michael-t | 07/27/04
You've got my vote too.  Immanuel Tranz-Mischen | 07/27/04
You have to ask your self  agottschald | 07/30/04
the problem with infected email  balsover | 07/27/04
Microsoft's popularity and malware spread  Anton Philidor | 07/27/04
Apple also caters to the IQ challanged crowd  balsover | 07/27/04
Ha, Mac users on average are SMARTER...  ITGuy04 | 07/28/04
If your so so smart...  somethinginnovative | 07/29/04
Blocklists  Yagotta B. Kidding | 07/27/04
most infected email that I receive  balsover | 07/27/04
Briefing needed:  michael-t | 07/27/04
you are a little out of touch  balsover | 07/27/04
Speak of being out of touch...  MacCanuck | 07/28/04
Buy a Clue....  ITGuy04 | 07/28/04
1st worm was NOT for Windows  bwklatt@... | 07/29/04
Very out of touch  johnnyu | 07/28/04
Good point I would only add atleast one more thing.  computer_man | 07/27/04
OK I'm no rocket scientist...  Richard Flude | 07/27/04
Perhaps for the same reason...  balsover | 07/27/04
Enjoy your prison  Sunny Jalolly | 07/27/04
No, not the same at all  Richard Flude | 07/27/04
What's wrong with improving?  somethinginnovative | 07/29/04
Rocket scientist  uno@... | 07/29/04
Oops  uno@... | 07/29/04
Ya damned Skippy!  BitTwiddler | 07/28/04
Yeah, Let's Have More Regulation!!!  gsquared | 07/29/04
What if the ISP's  balsover | 07/27/04
OOOBIE DOOBIE would you want to be that ISP's tech support  Squawkbox | 07/27/04
If people were told  balsover | 07/27/04
Good one Bombay......I like that  Squawkbox | 07/27/04
One more thing that works good  computer_man | 07/27/04
Several do  Yagotta B. Kidding | 07/27/04
You could position it as a service.  enduser_z | 07/27/04
The capitalistic way ..will save you .....not  george@... | 07/29/04
ISP do pull the plug....  middle of nowhere | 07/27/04
Dang, I need to train my fingers to hit the proper keys!!!  middle of nowhere | 07/27/04
my take...  ryusen | 07/27/04
your take ...  PJfromOttawa | 07/28/04
at last a smart person .  george@... | 07/29/04
"I see the future...booooooo"  george@... | 07/29/04
More reasons to NOT USE WINDOWS  ITGuy04 | 07/27/04
The sky is falling, the sky is falling...  Confused by religion | 07/27/04
You'd never know if you were hacked  voska | 07/27/04
As it happens -  Confused by religion | 07/27/04
Computers to work for people!  leandro_z | 07/28/04
Heheheheh!!!  tgrady | 07/29/04
And you know that...how?  Chad_z | 07/27/04
Yes, it took me time...  Confused by religion | 07/28/04
3 years running, no single intrusion  garci | 07/29/04
Nobody has time for looking at the sky - they're all patching  whisperycat | 07/27/04
Patching  IT Scion | 07/29/04
Patch up  Amalia | 07/29/04
You need to comprehend what I posted.  IT Scion | 08/02/04
I guess  michael-t | 07/27/04
or....  computer_man | 07/27/04
See my response above.  Confused by religion | 07/27/04
Hmm I'm surprise at the ammount of people complaining about infections.  computer_man | 07/27/04
Jump to conclusions much?  Immanuel Tranz-Mischen | 07/27/04
Better Chicken Little than an Ostrich.  Immanuel Tranz-Mischen | 07/27/04
I cnose a Mac and  Confused by religion | 07/27/04
cnose?  Immanuel Tranz-Mischen | 07/28/04
HEHE - Good one!  Confused by religion | 07/28/04
Been in IT VERY Long  ITGuy04 | 07/28/04
But That's Not What Sweaty Ballmer Tells Us  claytonmuhler | 07/27/04
And why would he lie?  Immanuel Tranz-Mischen | 07/27/04
Sorry, not convinced!  Big Steve_z | 07/28/04
Uses of Windows  gsquared | 07/29/04
Sure, everybody switch to...  tgrady | 07/29/04
Not quite true  uno@... | 07/29/04
OS Virus Protection = AntiTrust legislation  somethinginnovative | 07/29/04
You don't get it  lengua99 | 07/30/04
No to Windows??  IT Scion | 07/29/04
Also  IT Scion | 07/29/04
Standard Stories of Misery  michael-t | 07/27/04
Best Windows Machine - Unplugged  Chad_z | 07/27/04
No one owns this FREEdom OS..!  Xunil_Sierutuf | 07/27/04
Infected machines need to be stopped  Xanth_z | 07/27/04
I am getting  Linux User 147560 | 07/27/04
OMG!  MDDM_z | 07/29/04
All vendors have bugs, but sheer number of MS bugs is GROSS NEGLIGENCE !!!  Plain Logic | 07/27/04
Hold yourself responsible.  IT Scion | 07/29/04
Six of one  Yagotta B. Kidding | 07/27/04
Again, they need to make sure everybody knows this is a Microsoft problem.  DonnieBoy | 07/27/04
only way to fix this is for ms to give users  V Sanders | 07/28/04
and it should be easy to remove  V Sanders | 07/28/04
MyDoom is your Doom  peterdee_z | 07/28/04
IT admins have the IP  jdubuke | 07/28/04
MyBaldurGate to take a whack at Apple  FilledOut | 07/28/04
Symptoms not Diseases  Techscan | 07/28/04
Flaws  IT Scion | 08/02/04
MY DOOM  kittyj57 | 07/29/04
Plain stupid  MDDM_z | 07/29/04
stupid  Amalia | 07/29/04
must be from USA  Cobrajet500 | 07/29/04
How dare I?  MDDM_z | 07/30/04
Windoze and IE  bhattaci | 07/30/04

What do you think?

SmartPlanet

Click Here