Welcome | Sign In
LinuxInsider.com
Security

New Worm Starts Crawling the Net

Print Version
E-Mail Article
Reprints
New Worm Starts Crawling the Net

"We don't know yet if this will be the next so-called 'Big One,'" Emory Lundberg, research analyst in the Managed Software Services division of VeriSign, told TechNewsWorld. "It might just be a proof of concept test or a harbinger of a bigger worm to follow on its heels."


Increase Customer Sales with VerticalResponse Email Marketing! Quickly and easily send email newsletters, coupons & sales announcements to your customers – no technical expertise needed. Sign up for your Free Trial today and send 100 emails on us!

A new worm materialized yesterday in the U.S. Pacific region and was continuing a slow circulation across the U.S. mainland last night in search of compromised computer systems.

VeriSign (Nasdaq: VRSN) engineers have been tracking increased Internet traffic on customers' computer systems around the country since April 16th. The increase in suspicious activity through the week had Internet security experts bracing for what some analysts warned could be the next big worm attack worldwide.

Charles Kaplan, MSS information security officer for VeriSign, told TechNewsWorld earlier this week that a new worm with marching orders for some major Internet activity should be evident within the next few days. His prediction proved accurate, as confirmed evidence of a worm surfaced midday Tuesday.

"We don't know yet if this will be the next so-called 'Big One,'" Emory Lundberg, research analyst in the Managed Software Services division of VeriSign, told TechNewsWorld. "It might just be a proof-of-concept test or a harbinger of a bigger worm to follow on its heels."

Pattern Differs from Earlier Attacks

Lundberg said this new worm, which has yet to be named, was formulated by automated worm-creating software. As such, it is not incredibly optimized.

However, worms that attacked older vulnerabilities in Microsoft (Nasdaq: MSFT) software and Internet protocols could be more easily stopped than this latest worm. Adjusting router settings and applying patches issued by Microsoft protected computers from being accessed by attackers.

But Lundberg said this newest worm leaves computer users only two options. One is to disconnect from the Internet to prevent intrusion. The other is to apply specifically designed patches to protect against SSL PCT server vulnerabilities.

"We don't know just yet if up-to-date antivirus software will be able to identify and block this new worm," Lundberg told TechNewsWorld.

Code Captured Early On

Worm-related activity involved numerous probes checking for computers that already had a back door opened from a previous vulnerability. Engineers succeeded in uncovering portions of the denial-of-service code.

By last Thursday, engineers had found the DoS code posted publicly on many well-known hacker Web sites. Having access to that code allowed Internet security teams to prepare for anticipated attacks.

Lundberg said Microsoft and another as-yet-unnamed company had acquired a copy of the full worm code by yesterday afternoon. The fact that analysts already were working on the worm code might further slow the worm's progress, he said.

As of last night, VeriSign did not have the worm code, company officials said, but preliminary analysis showed the worm did not seem to have complete directions for a DoS attack. Instead, said Lundberg, it contained a lot of administrator command prompts.

Testing has shown that rebooting a machine that is hit by this new worm might prevent execution of command instructions. But the worm does leave some code on the hard drives of infected computers, according to Lundberg.

Still a Guessing Game

Preliminary activity reports suggest this new worm will not spread with the kind of rapid-fire growth seen in the cases of the Slammer and Blaster worms. "This one seems to be crawling along," Lundberg told TechNewsWorld.

Two reasons account for the slower spread of this worm, he said. One is that people learned their lessons after the last round of worm attacks and are more prepared now. The other is that they didn't wait until the last minute to patch their systems.

Engineers said it is still too early to know for sure what the worm writers have in mind.

"We have more analysis to do yet," said Lundberg.


Print Version E-Mail Article Reprints More by Jack M. Germain


More by Jack M. Germain

Microsoft FOSSifies .Net Micro Framework
November 18, 2009
Microsoft has declared its .Net Micro framework open source under the Apace 2.0 license. Not all bits of .Net Micro are covered, however. Its TCP/IP stack has been stripped, as has its cryptography libraries. Rights to the TCP/IP stack aren't Redmond's to give, and the cryptography libraries are used outside of the scope of the .Net Micro framework, according to the company.
New Ubuntu OS Features Create Good Karma
November 13, 2009
Amidst the OS upgrades from Apple and Microsoft over the last few months, the Linux OS Ubuntu got a version bump of its own. Ubuntu 9.10, or Karmic Koala, is well worth the effort to upgrade, and its developers have made the process easier -- if you're using the full-sized desktop/notebook version. The Remix version, intended for netbooks, caused quite a few headaches.
Samsung Chimes In With Bada Mobile OS
November 11, 2009
With Android, iPhone, BlackBerry, WinMo, Symbian, WebOS and plenty other mobile platforms fighting for space, is there room for one more? Samsung believes there is, and it's announced a new open mobile platform called "Bada." The company, which already makes handsets for several existing platforms, says Bada will make app-making easy for developers. The first Bada handset should be out in the first half of 2010.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network