On MovieTome: The 10 worst movies of 2009 so far!
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Aug 16, 2005 10:44:00 PM

Network worms that shut down computers running Microsoft's Windows 2000 operating system on Tuesday may be linked to competition between rival hackers, security experts said.

Computers across the United States have been hit, including those at cable news station CNN, television network ABC and The New York Times. Tokyo-based antivirus company Trend Micro blames the havoc on various worms, including the Zotob worm that hit the Internet over the weekend and new variants of the Rbot worm.

Some security researchers claim the outbreak is tied to a "war" between rival virus writers. "We seem to have a botwar on our hands," Mikko Hypponen, chief research officer at Finnish software security firm F-Secure said in a statement issued on Wednesday.

"There appear to be three different virus-writing gangs turning out new worms at an alarming rate, as if they were competing to build the biggest network of infected machines," he said.

All of the worms exploit a security hole in the plug-and-play feature in the Windows 2000 operating system. Microsoft offered a fix for the bug as part of its monthly patching cycle last week. The software maker deemed the issue "critical," its most serious rating.

CNET security center
Zotob prevention and cure
New worms attack vulnerable Windows 2000 and Windows XP SP1 machines.

"It seems like every couple of minutes a new variant comes in. We cannot pinpoint the infections to one variant," Joe Hartmann, director of the antivirus research group at Trend Micro, said on Tuesday. "We are still gathering infection reports. It is coming globally."

Symptoms of infection include the repeated shutdown and rebooting of a computer, Trend Micro said.

Microsoft is investigating the reports of the worm outbreak, the company said in a statement. It lists "Worm_Rbot.CEQ," an Rbot variant, as the possible cause of the trouble.

The company also sought to downplay the threat and said Windows 2000-based PCs running the latest patch are protected. "Zotob has thus far had a low rate of infection. Zotob only targets Windows 2000. Customers running other versions such as Windows XP, or customers who have applied the MS05-039 update to Windows 2000 are not impacted by this attack," the company said in a statement issued Tuesday.

Inside job
The multiple worms are hitting individual organizations rather than computer users at large, said Johannes Ullrich, chief research officer at the SANS Institute, an Internet security training and research outfit.

"These worms are not having an impact on the Internet," Ullrich said on Tuesday. "They do have a substantial effect on organizations running Windows 2000 without last week's Microsoft patch installed."

The pain is being felt "on the inside," agreed David Cole, the director of product management at Symantec Security Response. The worms might slither onto the networks of companies with Windows 2000 systems from an infected laptop that has been used outside the corporate firewall, for example, he said.

"It gets inside an organization and then it bounces around and wreaks havoc," Cole said.

The New York Times has been hit by the virus, but the assault has not impacted the delivery of the news, said a spokeswoman for the publication.

"The Web site was not affected and newspaper production will not be affected," the representative said. The internal systems of the paper are "operational," the representative added, but she did not state what degree of impact the worm had had on its internal operations.

Walt Disney's ABC News and Time Warner's CNN confirmed in postings to their Web sites that their computers had been hit.

Which worm done it?
Experts have different opinions on the cause of the latest infections. The SANS Internet Storm Center, which tracks network threats, attributes Tuesday's trouble to Zotob, which keeps mutating and finding new victims. "As seen with prior TCP worms, it is reaching its peak around three days after the outbreak," SANS said on its Web site.

The security issue exploited by the worm also affects the newer Windows XP and Windows Server 2003, but only PCs running Windows 2000 are susceptible to a remote attack, Microsoft has said.

There are desktop and server versions of Windows 2000, which was released in 2000 for business users rather than consumers. More recent editions of Windows are available, but Windows 2000 remains popular. The operating system ran on 48 percent of business PCs during the first quarter of 2005, according to a recent study by AssetMetrix.

The onslaught of worms based on the plug-and-play flaw appeared less than a week after Microsoft's patch release, leaving users very little time to protect their systems.

Many Windows 2000 users likely will not have patched yet since they need time to test the fixes before installing them, Ullrich said.

Although there are several worms that exploit the Windows plug-and-play flaw, the spread remains limited, Cole said. "We are not seeing any one of these really soaring or escalating to something like a Blaster or Slammer," he said. Symantec has elevated its ThreatCon rating from one to two, with five being the highest.

Trend Micro has rated the worm attack "yellow," which is in the middle of its alert range. The security company has seen thousands of infections from Zotob alone, Hartmann said.

Infected machines can be cleaned up using tools available from antivirus software makers, including Symantec. Windows 2000 users who have not patched, should do so, Microsoft urges.

CNET News.com's Michael Kanellos contributed to this report.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 249 Talkback(s)
Artistic interpretation
That's a rather artistic interpretation ya got there. Of course, it's from the guy who thought a 64 bit version of windows shipped back in the day too.

Now, I'll do my artistic interpretation ... (Read the rest)
Posted by: Sxooter_z Posted on: 08/25/05 You are currently: a Guest | | Terms of Use
Windows worm knocking out computers  Loverock Davidson | 08/16/05
Howdy doody there: the worms were  michael_t | 08/16/05
Having trouble reading for comprehension?  ShadeTree | 08/17/05
Windows worm knocking out computers  abcpc123 | 08/16/05
Sorry but it is  Loverock Davidson | 08/16/05
GIANT ant hill...  gfeier | 08/17/05
Nope  Loverock Davidson | 08/17/05
I'd hate to see...  gfeier | 08/17/05
no problems here  linuxoverwindows | 08/17/05
Artistic interpretation  Sxooter_z | 08/25/05
So if your girl friend is going in she must know that ...  ShadeTree | 08/17/05
Just what I was thinking...  Scrat | 08/17/05
another thing to do...  linuxoverwindows | 08/17/05
You don't use windows much do you?  Scrat | 08/17/05
ever tried that with a constant rebooting recipient? n/t  NemesisNL | 08/17/05
yeah, ive heard of it, but...  linuxoverwindows | 08/17/05
Haaa your so right  jc5wong | 08/17/05
Message has been deleted.  computer_man | 08/17/05
i agree...  linuxoverwindows | 08/17/05
Actually, come to think about it...  Scrat | 08/17/05
why let laptops connect to the core network?  linuxoverwindows | 08/17/05
Surely that would depend..  Scrat | 08/17/05
One Week though  nucrash | 08/17/05
No need to  Loverock Davidson | 08/17/05
That's just too funny...  jacarter3 | 08/17/05
i know you're smarter than that  Monkey_MCSE | 08/17/05
he is just proving that he is a troll...  linuxoverwindows | 08/17/05
Thats laughable  Loverock Davidson | 08/17/05
No doubt about it...  jacarter3 | 08/17/05
Thats laughable  Loverock Davidson | 08/17/05
You did cuz you know it's true  jacarter3 | 08/17/05
You did cuz you know it's true  Loverock Davidson | 08/17/05
i only come here to see how the windows...  linuxoverwindows | 08/17/05
found the fix  Monkey_MCSE | 08/17/05
Nonsense!  cdgoldin | 08/17/05
Provided the tests passed! (NT)  The King's Servant | 08/17/05
Not nonsense  Loverock Davidson | 08/17/05
Rare is a subjective thing  maldain | 08/17/05
Okay, now you're worst than Mike Cox!  The King's Servant | 08/17/05
Shall we list the examples  nucrash | 08/17/05
i had a patch that crashed my test server once...  linuxoverwindows | 08/17/05
But...  rapson | 08/17/05
Linux worm knocking out computers  figgle | 08/17/05
The day will come (again)  cdgoldin | 08/17/05
Hate to rain on your parade.  Cardinal_Bill | 08/17/05
or, it could be...  linuxoverwindows | 08/17/05
Those Darn Coporations Running W2K ...  PMC-CON | 08/17/05
Yeah, time to upgrade...  jacarter3 | 08/17/05
So Which of the Umpteen incompatible Linux Distros Do You Use? (nt)  PMC-CON | 08/17/05
The most incompatible...  jacarter3 | 08/17/05
I dunno?  Cardinal_Bill | 08/17/05
Forced to stay with 2K sometimes...  jefmud | 08/17/05
CNN, NY Times, ABC News...... ALL HIT!!! (NT)  zootbobbalu | 08/16/05
Yup, its all over the news ...  George Mitchell | 08/16/05
It works well with the memoryless masochists. For the rest I doubt .... nt  michael_t | 08/16/05
i guess  eLurker | 08/16/05
And what are you if you get hit due to a defect that is  michael_t | 08/16/05
Stick to the story!  Trevor_G | 08/17/05
And what about testing?  The King's Servant | 08/17/05
i keep a clone of my server...  linuxoverwindows | 08/17/05
Good plan!  The King's Servant | 08/17/05
re: good plan - you left one out...  linuxoverwindows | 08/17/05
HE MENTIONS ME!! AND IT GIVES ME CREDIT TOO  Loverock Davidson | 08/17/05
re: testing  eLurker | 08/17/05
keep reading...  The King's Servant | 08/17/05
re: keep reading...  eLurker | 08/17/05
as i said  eLurker | 08/17/05
risks?  haxmeister | 08/18/05
obviously  eLurker | 08/18/05
SBC  user1212 | 08/16/05
The Capital Also!! (NT)  zootbobbalu | 08/16/05
Add to that list the WSJ, and several Wall Street firms  Otto_Delete | 08/17/05
Serves 'em right...  cdgoldin | 08/17/05
Random s/w haphazzardly stitched together to form a 'system' .... happy  michael_t | 08/16/05
Before we know it, we'll be blaming an iPod!!!!  mlindl | 08/16/05
OMG!!! One of my users got a new iPod yesterday...  The King's Servant | 08/17/05
actually...  linuxoverwindows | 08/17/05
Meanwhile back at the Penguin cave...  Linux User 147560 | 08/16/05
Yet another reason not to depend on Windows  ITGuy04 | 08/16/05
RE: Yet another reason not to depend on Windows  Linux User 147560 | 08/16/05
thats what im talking about  linuxoverwindows | 08/17/05
Well....  11bravo | 08/16/05
Guess what? People live in denial!!!  mlindl | 08/16/05
re: Yet another reason not to depend on Windows  bobhume | 08/17/05
nah, windows is an easy target.  linuxoverwindows | 08/17/05
re: nah, windows is an easy target.  bobhume | 08/17/05
So with *nix dominating the server room....  The King's Servant | 08/17/05
microsoft.. again  u2in99 | 08/17/05
Patch and forget  SteveG123 | 08/16/05
RE: Patch and Forget  crash89 | 08/16/05
Not exactly zero!  ShadeTree | 08/17/05
Uh, yeah...exactly zero.  pdq | 08/17/05
What a dufus  D-Ram | 08/17/05
Yes, you are.  The King's Servant | 08/17/05
i do this from work...  linuxoverwindows | 08/17/05
zero virus vs zero flaws...  linuxoverwindows | 08/17/05
Patch, PREVENT and NOT forget.  michael_t | 08/16/05
2 differnt statements from same company  John Zern | 08/16/05
Patch Management  Too Old For IT | 08/17/05
Did Mike's outfit get hit?  duclod | 08/16/05
No, 'cause he is running Linux and Unix throughout wink nt  michael_t | 08/16/05
Mike's outfit . . .  abcpc123 | 08/17/05
LMAO! I can't wait to hear from Mike.  The King's Servant | 08/17/05
cant wait...  linuxoverwindows | 08/17/05
Same tactics, same goal  Otto_Delete | 08/17/05
m$ would label me a prude.  linuxoverwindows | 08/17/05
All quiet here  toadlife | 08/16/05
Good: test your confidence by publishing your IP addresses...  michael_t | 08/16/05
Real smart mikey.  toadlife | 08/16/05
REReal smart mikey.  Linux User 147560 | 08/16/05
RE: Real smart mikey.  Linux User 147560 | 08/16/05
Yeah. That's me.  toadlife | 08/16/05
RE: Yeah. That's me.  Linux User 147560 | 08/17/05
....  toadlife | 08/17/05
I hope that while you were trying unsuccessfully to  michael_t | 08/16/05
Trying to outsmart you?  toadlife | 08/16/05
You need to understand what 'sarcasm' means  michael_t | 08/17/05
Man you are not very smart.  computer_man | 08/17/05
I don't filter ports  toadlife | 08/17/05
re: Man you are not very smart  toadlife | 08/17/05
Unsuccessfully?  Scrat | 08/17/05
Howdy Scat: the first  michael_t | 08/17/05
So what?  michael_t | 08/16/05
i get "tested" everyday...  linuxoverwindows | 08/17/05
If ports 80 and SSH are open to public Internet  michael_t | 08/17/05
yep, got r locked down to 1 user.  linuxoverwindows | 08/17/05
Same here  NonZealot | 08/16/05
How many of those are outside their packaging? 0 ?  michael_t | 08/16/05
(nt)Publish a public IP address at your workplace first  toadlife | 08/16/05
Here it is:  michael_t | 08/17/05
127.0.0.1  NonZealot | 08/17/05
Thanks that was funny .... I only hope you  michael_t | 08/17/05
as i posted above...  linuxoverwindows | 08/17/05
All is quiet here too.  osreinstall | 08/16/05
Only a newbie would go on the net without a firewall?  whisperycat | 08/17/05
RE: Only a newbie would go on the net without a firewall?  Linux User 147560 | 08/17/05
Yep, I shoulda clarified that point  whisperycat | 08/17/05
Mandriva  PMC-CON | 08/17/05
try these instead, i switched from mandrake...  linuxoverwindows | 08/17/05
If your Mum can figure out Mandrake...  cdgoldin | 08/17/05
mandrake is a joke.  linuxoverwindows | 08/17/05
Cost of windows + $0 = TCO  NonZealot | 08/17/05
So there is no associated costs to Windows virus?  whisperycat | 08/17/05
Who said anything about integrated AV?  NonZealot | 08/17/05
zonealarm?  linuxoverwindows | 08/17/05
However,  Patrick Jones | 08/17/05
You pay for it though  voska | 08/17/05
really funny ....  michael_t | 08/17/05
Yes they do.  osreinstall | 08/18/05
linux firewalls...  linuxoverwindows | 08/17/05
Not an elitist attitude at all  osreinstall | 08/17/05
I am truely glad that  michael_t | 08/17/05
Another silly rant from the psycho ward!  osreinstall | 08/17/05
Windows XP Sp2 and Win 2003 not phased  ITsucks | 08/16/05
And funny ... coincidence now that MS wants to switch W2k users to xp/vista  michael_t | 08/16/05
Re: Coincidence  X Marks The Spot | 08/16/05
Conspiracy?  An_Axe_to_Grind | 08/16/05
even so, i would stick with 2k  Monkey_MCSE | 08/16/05
that would be a waste of money  voska | 08/17/05
win2k is a decent windows  linuxoverwindows | 08/17/05
Sweet, made a funny and I didn't even know it!  voska | 08/17/05
Sweet, made a funny and I didn't even know it!  glstorck@... | 08/17/05
couldnt resist happy (nt)  linuxoverwindows | 08/17/05
RE:Windows XP Sp2 and Win 2003 not phased  sir_cheats_a_lot | 08/17/05
Yet another high-profile worm outbreak embarassing all those  michael_t | 08/16/05
I'm certainly not a MS apologist  ebrke | 08/17/05
The problem was addressed before the virus  balsover | 08/17/05
I don't recall UNIX  michael_t | 08/17/05
Patching/security doesn't work for Windows  mlindl | 08/16/05
I disagree  Otto_Delete | 08/17/05
I've never had virus on W2K  voska | 08/17/05
i think my computer has vd  linuxoverwindows | 08/17/05
LoL  computer_man | 08/17/05
Oh, boo hoo... boo who..  oo7curtis | 08/17/05
Just another case of the malware writers reverse ...  ShadeTree | 08/17/05
and break your servers.  The King's Servant | 08/17/05
heres a patch all for your servers...  linuxoverwindows | 08/17/05
I love those patches!  The King's Servant | 08/17/05
It has been a super long time since a patch has...  ShadeTree | 08/17/05
Re: 'Apply the patches dummies!' OR throw the  michael_t | 08/17/05
Microsoft never finds their own  bjbrock | 08/17/05
It's all in the mind set.  papatator | 08/17/05
i hear ya...  linuxoverwindows | 08/17/05
There is your problem right there ...  George Jay | 08/18/05
Message has been deleted.  computer_man | 08/17/05
You read it hear first...  The King's Servant | 08/17/05
Would this affect my new iMac G5?  Paco20 | 08/17/05
Assuming this is a serious question...  pdq | 08/17/05
Message has been deleted.  computer_man | 08/17/05
Give us YOUR phone number so we can teach you some manners  cdgoldin | 08/17/05
I don't care !!I love viruses !!!! ARGGG !! Hack the planet !!  GeoMartinez | 08/17/05
HACK THE PLANET!!!  linuxoverwindows | 08/17/05
Helllooooo!  c320162 | 08/17/05
htp://hack.the.planet...  linuxoverwindows | 08/17/05
and for the record...  linuxoverwindows | 08/17/05
Suprise?  Edward@... | 08/17/05
Tell ya what...  ArtMac | 08/18/05
CLARKCONNECT RULES!!!  Airwolph | 08/17/05
Windows security  ciph3r | 08/17/05
virus  cardinal33 | 08/17/05
MicroSoft  DrSwiney | 08/17/05
Already done  cdgoldin | 08/17/05
Variants Rely on Having Admin Rights  PMC-CON | 08/17/05
Have you any idea how many Win apps will not run  The King's Servant | 08/17/05
Have you any idea how many Win apps will not run  mrlinux | 08/17/05
Good for you. But that doesn't answer my question.  The King's Servant | 08/17/05
Depends on a few factors ...  PMC-CON | 08/17/05
Almost None ...  PMC-CON | 08/17/05
yes  Jack-Booted EULA | 08/17/05
Obviously An Amateur ...  PMC-CON | 08/17/05
yes again  Jack-Booted EULA | 08/17/05
Most != all.  The King's Servant | 08/17/05
Vendor Problem  PMC-CON | 08/17/05
Direct Answer  PMC-CON | 08/17/05
Who is lazy, here? The ISV, MS or me?  The King's Servant | 08/17/05
ISV is Lazy, BUt If App Is Critical ...  PMC-CON | 08/17/05
Sorry but this is the reason why people like Linux  computer_man | 08/17/05
So Linux "Hobbyist" ...  PMC-CON | 08/17/05
"So dis' me ..."  linuxoverwindows | 08/17/05
at least in linux...  linuxoverwindows | 08/17/05
Correction: Remote Execution and Elevated Privileges  PMC-CON | 08/17/05
Sorry -- Anonymous Attacks ARE possible with W2K  PMC-CON | 08/17/05
Gibson Research Article on Port 445  PMC-CON | 08/17/05
Variants Rely on Having Admin Rights  c320162 | 08/17/05
I Apologize ... Port Open on W2K  PMC-CON | 08/17/05
Amen on admin responsibility  Spdlmt150 | 08/17/05
If the shoe were on the other foot  papatator | 08/17/05
M$ API's are the real problem  NovellisBettter | 08/23/05
If you can write a Cookie, you can write a worm  cygnet@... | 08/17/05
your "Index.dat files"  cygnet@... | 08/17/05
Gotta love disinformation...  Allstar_z | 08/17/05
"Fresh" HOTP from M$oft  oldskillz | 08/17/05
How good is your IT department?  mwagner@... | 08/17/05
How easy can it get?  mwagner@... | 08/17/05
FYI  Monkey_MCSE | 08/17/05
No Personal Firewall in W2K (NT)  PMC-CON | 08/17/05
It isn't that simple  George Jay | 08/18/05
Worm, virus, and the alike  mcseport | 08/17/05
A buck in a bug  cdgoldin | 08/17/05
AWWWW  nightshade0143 | 08/17/05
Your TOO late on the story  gamerzworld | 08/17/05
hospitals  Billmac_z | 08/17/05
Heavens...  ArtMac | 08/18/05
I have visions...  ArtMac | 08/18/05
Buy a Mac!  An_Axe_to_Grind | 08/18/05
They are only young playing.  jolumoar | 08/18/05
XP infected  snafu-cf | 08/19/05
Informed users  yarbelo001@... | 08/19/05
OS Wars and the Average Joe  The Computer Pimp | 08/19/05

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here