On TV.com: Heroes: Don't Bring Back Ali Larter
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Aug 14, 2006 8:08:00 PM

Two worms based on a recently disclosed Windows flaw have been unleashed, but the attacks so far don't appear to be widespread, security experts said.

The pair of worms surfaced over the weekend, several security companies said in alerts. The malicious software tries to hijack the computer for use in a network of commandeered PCs that can be remotely controlled, popularly called a botnet. The worms also can communicate via AOL's Instant Messenger and may be able to spread via the service.

"This is run-of-the-mill malicious software," said Don DeBolt, director of the Security Advisor group at CA, formerly known as Computer Associates. "The malware purveyors are simply packaging their old wares with the new exploit."

The worms are derivatives of the original Cuebot family that first surfaced last year, DeBolt said. These variants have been programmed to exploit a serious flaw in a Windows component related to file and printer sharing. Microsoft issued a patch for the security hole last week in security bulletin MS06-040. Security experts had already predicted that the flaw would spawn a worm attack.

Neither of the variants is very widespread, according to Microsoft, which calls them "Graweg."

"This appears to be an extremely targeted attack, very much unlike what we have seen in the past with recent Internet-wide worms," Stephen Toulouse, a program manager in Microsoft's Security Technology Unit, wrote on a corporate blog Saturday.

The MS06-040 worms appear to be limited to computers running Windows 2000. That's because the computer code used to exploit the vulnerability is most effective on computers with that older operating system, DeBolt said.

"Windows XP is appearing to be more difficult to exploit than its sister platform Windows 2000," he said.

Some security experts have said the age of the high-impact, Internet-wide worm is over. Instead, increasingly organized cybercriminals are looking to exploit flaws directed at specific companies for financial gain and want to fly under the radar. Criminals use botnets to relay spam, distribute spyware and launch other online attacks. A widespread worm could affect the performance of the Internet--a disruption that could also disrupt their means of business.

For the new worms to propagate, the attacker must instruct a compromised machine to scan for new targets, DeBolt said. A vulnerable computer can be compromised remotely and without any user interaction, he said.

"We are not seeing a widespread epidemic at this time, but we do see increased activity on TCP port 445," DeBolt said, referring to the network port used by the vulnerable Windows service.

Security experts expect that the computer code that exploits the MS06-040 flaw will be perfected and popular among miscreants looking to take over Windows systems. "We will see a number of different viral and spyware packages that utilize this exploit as it reaches a large audience," DeBolt said.

To protect their computers, Windows users are urged to install Microsoft's patch. All Windows versions are vulnerable, the software maker said. The fix is available via the Windows Update and Automatic Updates tools, as well as for download on Microsoft's Web site. The company has workarounds for people who cannot apply the patches yet, because they need to test it first, for example.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 21 Talkback(s)
sounds like M$ intentionally left win2k vulnerable to force users to
upgrade and contribute to the coffers so billy-boy and wifey can give millions to groups that advocate killing babies in the mother's womb and advocating peace at any cost, even surrender!

just... (Read the rest)
Posted by: wessonjoe Posted on: 08/16/06 You are currently: a Guest | | Terms of Use
As expected, more attacks....  OhMyGosh | 08/14/06
would a *nix hack for an older OS make news  defconvegas | 08/14/06
There have been a few of them  Sabz5150 | 08/14/06
recently....  JoeMama_z | 08/14/06
Any Unix hack would make the news as they are so RARE ...  michael_t | 08/15/06
fud?  merc2dogs` | 08/15/06
Did the DH(I)S forget where they put the backdoors already?  Mr. Roboto | 08/14/06
They borrowed some "mackholes" from the pool  michael_t | 08/15/06
They borrowed some "backholes" from the pool  michael_t | 08/15/06
Does not affect us...  Mike Cox | 08/14/06
Um  flatliner | 08/14/06
9  LoCal | 08/15/06
Worm duo tries to hijack Windows PCs  Loverock Davidson | 08/14/06
Yep! Have you got your Windows machine patched?  Grayson Peddie | 08/14/06
Still testing  nucrash | 08/15/06
Still working...  Spikey_Mike | 08/15/06
Yes!  Loverock Davidson | 08/15/06
So many good reasons to be looking forward to buying Vista  michael_t | 08/14/06
genius! >>  Suicida| | 08/15/06
Dang, can't get the worms to use Wine in Linux properly  Boot_Agnostic | 08/15/06
sounds like M$ intentionally left win2k vulnerable to force users to  wessonjoe | 08/16/06

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

advertisement
Click Here