On CNET: 7 essential free apps for PC
BNET Business Network:
BNET
TechRepublic
ZDNet

By Tom Espiner ZDNet.co.uk
Posted on ZDNet News: Jan 08, 2009 5:57:55 AM

A Microsoft worm that is currently attacking business systems is also a USB worm, security vendor F-Secure has warned.

The worm, which F-Secure calls Downadup, attacks the vulnerability outlined in MS08-067, a Windows Server service flaw that was patched in October.

The worm launches a dictionary attack to attempt to crack user passwords, and uses server-side polymorphism and modification to the Access Control Lists (ACL) "to make network disinfection particularly difficult", F-Secure said in a blog post on Tuesday.

However, F-Secure said it has discovered the worm also propagates on the client side, via USB. If a person plugs a USB stick into an infected computer, the malware creates an autorun.inf file on the root of the USB drive.

The .inf file then uses either autorun or autoplay to infect any unpatched systems either when the stick is plugged into the system, or when the user double-clicks on the USB icon in My Computer in Windows Explorer.

The USB worm uses a steganographic technique to hide the autorun file in "binary garbage" to make detection more difficult, said F-Secure's chief research officer Mikko Hyppönen in a blog post on Wednesday.

The US Computer Emergency Response Team has urged IT professionals to apply the patch linked to in MS08-067.

ZDNet UK reader gareth25, who describes himself as an IT consultant from Manchester, said he has had to deal with systems infected by this worm. "I have first hand experience with this worm," wrote gareth25 in a response to a ZDNet UK story. "The connections it made outbound crashed the firewall and brought the internet down constantly. It's not exactly a one click removal either. Please patch your systems now."

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 12 Talkback(s)
Worm infects MP3 players as well
The Downadup worm also known as Conficker infects any Windows mapped drive. This not only includes network drives but also any removable media that Windows creates a drive letter for such as some MP3 ... (Read the rest)
Posted by: Dunsobarky Posted on: 01/09/09 You are currently: a Guest | | Terms of Use
And all my users keep wondering why  Michael Kelly | 01/08/09
I too  mdemuth | 01/08/09
Using this attack vector can this really be considered a worm? (nt)  ye | 01/08/09
Not the only vector, so yes. (NT)  SpikeyMike | 01/08/09
Thanks ZDNet!!!  Kromaethius | 01/08/09
RE: Microsoft server worm can spread via USB  Loverock Davidson | 01/08/09
Uh huh.  rpmyers1 | 01/08/09
For quite a while  Loverock Davidson | 01/08/09
MY IDS Logs have quite a bit of traffic  SpikeyMike | 01/08/09
Well good for you (NT)  Loverock Davidson | 01/08/09
If it's not a problem, how come there are still infections  rpmyers1 | 01/08/09
Worm infects MP3 players as well  Dunsobarky | 01/09/09

What do you think?

Click Here
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here