On GameSpot: Next-gen DS, Xbox tech contracts set?
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Jun 23, 2005 8:36:00 PM

A surge in scanning on a port associated with a Windows flaw patched last week suggests that a mass worm attack may be imminent, experts said.

A rise in activity on TCP Port 445 could be a sign that hackers are trying to exploit a flaw in Server Message Block, Gartner analyst John Pescatore said Thursday.

"Increased scanning does not always mean an attack will happen, but it greatly increases the odds that one will," Pescatore said. "I don't think this has a high probability of a worm, but if people get lax about patching the odds of worms goes way, way up."

Like would-be burglars knocking on doors looking for a likely target, Internet intruders sometimes scan random computers to see if a particular network port is available, as a precursor to attack.

TCP Port 445 is used by SMB, which Windows uses to share files, printers, serial ports and also to communicate between computers. Microsoft recently released a fix for the "critical" vulnerability in the protocol as part of its monthly patch cycle.

Increased port scanning has preceded major worm outbreaks in the past, Pescatore said. Alfred Huger, a senior director at Symantec Security Response, also said that a worm could be on its way.

Users should patch their systems as soon as possible, they both said.

However, Pescatore and Huger also note that port scanning by suspected hackers is common after Microsoft discloses vulnerabilities. Furthermore, this particular Windows flaw is not easy to exploit, so the scanning may not be an ominous sign at all.

Symantec saw a spike in scanning on TCP Port 445 last week, but the probing of the port has since gone back to normal levels, Huger said. "I don't think we should be screaming the barn is burning by any means," he said.

Microsoft is not aware of any active attempts to exploit any Microsoft vulnerabilities via TCP Port 445, a company representative said Thursday. Also, the software maker has not received any indication of malicious activity associated with the security vulnerability that affects SMB, the representative noted.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 96 Talkback(s)
Automatic Windows updates
Personally, I use automatic Update at home. However, that is since I built a new machine from scratch after an automatic Windows update to correct an error in USB handling completely ruined my earlie... (Read the rest)
Posted by: gardoglee Posted on: 06/30/05 You are currently: a Guest | | Terms of Use
I smell a worm  toadlife | 06/23/05
I know the exact amount  ibabadur1 | 06/23/05
What the heck are you talking about?  toadlife | 06/23/05
Yeah, really. What an idiot.  Immanuel Tranz-Mischen | 06/23/05
An idiotic question deserves an idiotic answer.  ibabadur1 | 06/24/05
The only thing YO' momma is teaching...  Colonel_Panic | 06/24/05
Re: An idiotic question deserves an idiotic answer.  nightshade0143 | 06/24/05
Re: What the heck are you talking about?  nightshade0143 | 06/24/05
That all depends...  tree_dweller_z | 06/26/05
Belongs in Opinion section  ibabadur1 | 06/23/05
No, not really  toadlife | 06/23/05
Thank you for concurring  ibabadur1 | 06/23/05
*sigh*  toadlife | 06/23/05
Comprende dis  ibabadur1 | 06/23/05
Weather reports must drive you nuts.  Immanuel Tranz-Mischen | 06/23/05
Movie reviews, Sunday morning news magazines, etc., etc., etc.  gardoglee | 06/24/05
I think my decoder ring is working, just a sec...  Colonel_Panic | 06/24/05
wink  bchesmer | 06/25/05
Re: Comprende dis  nightshade0143 | 06/24/05
OMG! Toad', you are wasting waaaaaaay too...  Colonel_Panic | 06/24/05
And when the Sun rises it is  michael_t | 06/23/05
Huh?!?!  dms350 | 06/24/05
That's right ....  michael_t | 06/24/05
hmmm  Protector | 06/24/05
Revenge of the Worms! Episode MCXXXIV  Reverend MacFellow | 06/24/05
Buy a Mac? Not worth it  node357 | 06/24/05
Not much more  ITGuy04 | 06/24/05
Re: Buy a Mac? Not worth it  nightshade0143 | 06/24/05
You do realize....  middle of nowhere | 06/24/05
Then why buy OS X...  aforencich | 06/25/05
Uhhh... because  Linux User 147560 | 06/25/05
Once again, you have shown yourself  mustangj36@... | 06/24/05
My Unix Rep And I Had A Good Laugh Over This  itanalyst | 06/24/05
1.0  UncleBubba | 06/24/05
Re: 1.0  nightshade0143 | 06/24/05
10.0...Well done...us *nix fanboys need a voice...  Colonel_Panic | 06/24/05
(chuckle) You are getting good...  sceeble | 06/24/05
Good rythym. Easy to dance to.  mustangj36@... | 06/24/05
When Bob Horn Had the Show  THEJET_z | 06/24/05
Because Unix doesn't Support IP Port 445, Thanks Heaven  PMC-CON | 06/24/05
HAHHAHAHA  Macs Rule | 06/24/05
Bet that is a hoot  Macs Rule | 06/24/05
That's a 10.0  bchesmer | 06/25/05
alleged danger, again...........well maybe not alleged  pesky_z | 06/24/05
"due us all a favor"?  kbeartxzd | 06/24/05
you're so eloquent  pesky_z | 06/24/05
Anyway...  gardoglee | 06/24/05
Baaaaad pesky, baaaaaad! Now get to the...  Colonel_Panic | 06/24/05
Geeze, I average won or too mistakes purr post...  Colonel_Panic | 06/24/05
You misspelt....  s_gamgee | 06/24/05
;-] (nt)  Colonel_Panic | 06/24/05
Just more fear-mongering from ZD, et. al.  kbeartxzd | 06/24/05
It's Obvious  Edward@... | 06/24/05
Scanning is like breathing!  node357 | 06/24/05
It's SkyNet  gstrick | 06/24/05
No doubt we're being spied on  node357 | 06/24/05
Perhaps an intersting note...  gardoglee | 06/24/05
Funny you should mention the Chinese...  Colonel_Panic | 06/24/05
it IS skynet  Protector | 06/24/05
THE SKY IS FALLING, THEY SKY IS FALLING  Protector | 06/24/05
Worse.....  nottheusual1 | 06/24/05
Re: Buy a Mac  Julie8x | 06/24/05
Re: Buy a Mac  node357 | 06/24/05
Wormdows strikes again! *Yawn* Wake me up...  Colonel_Panic | 06/24/05
How is it NEWS  michael_t | 06/24/05
wording is fantastic  ssloan1700 | 06/24/05
no support for this assertion  james@... | 06/24/05
Isn't it funny  IT Scion | 06/24/05
Now don't I feel stupid. Is ZDNet pulling this...  Colonel_Panic | 06/24/05
Its only to be expected  mafer_z | 06/24/05
Try DOS 6.0  ekimeloc | 06/24/05
I just checked...  Rodo1 | 06/24/05
This sounds like the Homeland Security  Tundra Gregg | 06/24/05
Ports 1026 & 1027 are...  eula-gree | 06/24/05
Wrong information  skykingoh | 06/24/05
How about Port 1337 ??  hellooothere | 06/27/05
Anybody dumb enough...  Poser | 06/24/05
RE: Anybody dumb enough...  Linux User 147560 | 06/24/05
Test  Linux User 147560 | 06/24/05
devil  Linux User 147560 | 06/25/05
Not as limited as I thought...  Linux User 147560 | 06/25/05
TYVM  bchesmer | 06/25/05
TYVM  bchesmer | 06/25/05
???  bchesmer | 06/25/05
Ahem, you are asking for big trouble...  Colonel_Panic | 06/24/05
Re: Explain  Julie8x | 06/24/05
Re: Explain  Julie8x | 06/24/05
Automatic windows update.  alle2003@... | 06/24/05
Automatic Windows updates  gardoglee | 06/30/05
But I thought it was said that new Windows holes were harder to find?  HypnoToad | 06/25/05
Exploit has been released  toadlife | 06/27/05
correction  toadlife | 06/27/05
Would this affect my new iMac G5?  Paco20 | 06/27/05
They don't make viruses or software for that!  Protector | 06/27/05
NO!  An_Axe_to_Grind | 06/27/05
Prepared = Apple OSX !  An_Axe_to_Grind | 06/27/05

What do you think?

advertisement
Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
advertisement

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline