'Huge increase' in worm attacks plague unpatched Windows PCs

2 comments | 8I like it!
January 12, 2009, 08:43 PM —  Computerworld — 

A computer worm that exploits a Windows bug Microsoft Corp. patched more than two months ago continues to wreak havoc, a security company said Monday, as it boosted its overall threat ranking and warned users to patch their PCs.

"We've seen a huge increase in the number of [malware] samples, as well as infections," said Ryan Sherstobitoff, chief corporate evangelist at Panda Security, referring to the "Conficker.c" worm.

In response, Panda upped its Global ThreatWatch to "orange" status, a move that means the company believes users face "an important danger."

The worm, which was first reported by Panda and other security companies on Dec. 31, 2008, exploits a vulnerability in the Windows Server service that's part of all currently supported versions of Microsoft's operating system, including Windows 2000, XP, Vista, Server 2003 and Server 2008.

Microsoft issued an emergency patch Oct. 23 to fix the flaw with one of its rare "out of cycle" updates.

Conficker.c, said Sherstobitoff, pings machines with malformed RPC (remote procedure call) packets in the hope of finding PCs not yet patched with the October update. The worm can also spread via brute-force attacks against systems' usernames and passwords, and from an infected PC to a USB-based device, such as a flash drive or digital camera, on which it then hitchhikes to another computer.

Once on a system, the worm downloads new versions of itself from a rapidly changing list of malicious Web sites, tries to block most security software updates, and installs more malware on the machine.

"The biggest issue is replication over the network," said Sherstobitoff, who added that the USB attack vector, while serious, has so far played just a small part in the overall picture.

Rival security company Symantec Corp., which calls the same worm "Downadup.b," has not mimicked Panda's threat-status ranking move. On Monday, Symantec's ThreatCon remained at "1," the lowest level.

Last Friday, however, Symantec also warned that it was tracking an increase in infections. In a blog post last week, Symantec said its researchers were seeing a "considerable" number of both the original Downadup, which first appeared in late November, and the newer Downadup.b.

"Downadup.b is just starting to get the same traction [as the original]," said Ben Greenbaum, a senior research manager with Symantec's security response team, in an interview today. In fact, today marked the first time that the number of detections for Downadup.b equaled the number for Downadup, he added.

Symantec estimated that approximately 3 million PCs have been infected by the worm.

"I'm not surprised that there are unpatched systems out there," Greenbaum said. "But I have been somewhat surprised by the number of unprotected systems. Anytime that Microsoft issues an out-of-cycle patch, users should pay attention."

Apparently, users didn't listen. In early December, Qualys Inc. concluded that the patching pace for the October emergency fix was similar to the rate at which people fixed flaws that Microsoft issued several weeks later on its regularly scheduled Patch Tuesday.

Users' lackadaisical approach to the emergency patch prompted one Microsoft executive to claim that some customers were "playing Russian Roulette" with their networks by not deploying the fix. In a post to his blog Sunday, Roger Halbheer, the chief security adviser for Microsoft's Europe, Middle East and Africa group, scolded users. "If you decide not to roll out a security update which is so critical that we decide to go out of band, you play Russian roulette with your network, as you can guess that there will be attacks exploiting this vulnerability pretty soon," said Halbheer.

More information about the vulnerability, and links to the patch, can be found in the MS08-067 security bulletin on Microsoft's Web site.

» posted by ITworld staff

Computerworld

I like it!
Comments

Just a Little

Just a little late with this article. The infestation of downadup.b has been growing for the past week at a alarming rate. I have been removing this worm from machines for the past week. All I have to say is any effected machine should be removed from the network due to the broadcasting of this virus.
| reply

バッテリー

大阪でバッテリー販売。 セルモーターリビルト。 オルタネーターリビルト。リビルト在庫多数。大阪で電装品販売。リンク品在庫多数。大阪でウイング車モーター修理・販売・在庫多数。大阪でパワーゲート車モーター修理・販売・在庫多数。
| reply
Free books

Essential JavaFX
Get started building rich Web apps quickly with an introduction to the power of JavaFX key features -- scene node graphs, nodes as components, the coordinate system, layout options, colors and gradients, custom classes with inheritance, animation, binding, and event handlers.Enter now!

The Nomadic Developer
Consulting can be hugely rewarding, but it's easy to fail if you are unprepared. To succeed, you need a mentor who knows the lay of the land. Aaron Erickson is your mentor, and this is your guidebook. Enter now!

Featured Sponsor

AISO founders envisioned a Web hosting company that was environmentally friendly. While the company employed energy-efficient innovations like solar panels, its infrastructure produced unacceptable power and cooling requirements. Find out how AISO leveraged AMD technology to overcome their challenge in this case study white paper.

In this whitepaper, Scalar explores the opportunity to change the landscape with respect to mission critical databases built around Oracle. Leveraging technologies such as Linux, high-end commodity processing power and Oracle RAC technology to architect, design, build and maintain database infrastructure that delivers maximum availability, reliability and performance at a fraction of traditional cost.

On a typical day, weather.com, the Web site for The Weather Channel in Atlanta, serves up between 15 million and 20 million page views. But in September 2004, when back-to-back hurricanes ransacked Florida, the peak traffic on one day more than tripled: over 70 million page views by more than 7 million unique visitors. Read the full success story now.

Marketplace