Flawed code throttled spread of Zotob variants

By Munir Kotadia, ZDNet Australia
Monday, August 22, 2005 11:16 AM

Havoc caused by variants of the Zotob worm could have been far worse had they not contained flaws, security companies say.

Chris Andrew, vice president of product management at PatchLink, said that coding errors caused a few variants of the worm to send computers into a reboot loop, which meant they spent very little time spreading the infection.

"If you read the vulnerability description in that exploit, it actually tells you that if you do it wrong it crashes the computer. If you do it right, then nobody can tell you have hacked the computer," Andrew said.

He said companies that were hit by one of the flawed variants were "lucky" because it gave them more time to stop the infection taking hold.

"The people at CNN and ABC were very upset that their computers crashed, but they were the lucky ones," Andrew said.

James Turner, security analyst at Frost & Sullivan Australia, agreed that the worm could easily have been worse--because the flawed variants gave administrators some warning that they were under attack.

"Your ultimate crime does not leave any traces. The minute a worm forces computers to do things that are abhorrent--like rebooting--it draws attention to itself," Turner said.

Allan Bell, marketing director for McAfee Asia-Pacific, said the versions that caused systems to crash--which McAfee has called IRCbot--are "often copy-and-paste jobs" created using source code distributed online.

PatchLink's Andrew agreed: "There are documented open-source materials available that show you how to do the hacks. It is hardly surprising that there are a whole bunch of (Zotob) variants."

American Express, Boeing and Holden are just some of companies with Australian locations that suffered from Zotob infections this week.

As part of its monthly patching cycle, Microsoft last week released a number of security updates, including the now infamous MS05-039, which fixed a critical vulnerability in Windows 2000.

Within days, exploit code was being distributed, and on Sunday the first Zotob worm was discovered in the wild.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Code concepts: Visual Studio's T4 templates

Web Development

The T4 templating system is used to programmatically generate artifacts. Here's an overview about why the templates are useful and how to work with them.


Read more »


 
Virtualize your way to cost savings
Build an infrastructure that is flexible, scalable, and economical, as you strive to become a truly agile business.

Red Hat Outlines Its Virtualization Strategy and Roadmap for 2009
» Watch the video




Where have all the bosses gone?

Blog thumbnail

I've had dreams of opening my own cafe or bistro...cum music store...cum music school. But, I soon gave up that dream when I realized it would require significant investment and..... by Eileen Yu

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web