New worm's got sass, but not much else

Published: 3 May 2004 y., Monday
The company, which found the flaws that were exploited by both the MSBlast worm and the Witty worm, on Saturday started analyzing the latest piece of attack code that takes advantage of a Microsoft Windows vulnerability discovered by its researchers. So far, eEye's analysts are surprised that the worm has spread so far. The Sasser worm started spreading late Friday, and so far has not racked up the crowd of compromised computers that its predecessors have been able to claim. Such a limited spread could indicate that computer users are becoming more diligent about heeding warnings and patching their systems, but security researchers believe that the worm's poor programming has given network administrators a break. "If this virus was better written, you would have seen more impact," said Alfred Huger, senior director of security firm Symantec's response center. The Sasser worm spreads from infected computer to vulnerable computer with no user interaction required. The worm exploits a recent vulnerability in a component of Microsoft Windows known as the Local Security Authority Subsystem Service, or LSASS. After scanning for vulnerable Windows XP and Windows 2000 systems, the worm creates a remote connection to the system, installs a file transfer protocol (FTP) server and then downloads itself to the new host.
Šaltinis: CNET News.com
Copying, publishing, announcing any information from the News.lt portal without written permission of News.lt editorial office is prohibited.

Facebook Comments

New comment


Captcha

Associated articles

New Debit, Credit Cards in Bulgaria

All Bulgarians possessing debit or credit cards will have to replace them with new "plastic purses" in 2005 more »

search.lt news

search.lt presents newest links more »

search.lt news

search.lt presents newest links more »

Security incidents and cybercrime on the up

Security events recorded between July and September this year are up 150 per cent on those recorded by security company VeriSign in the same period last year more »

search.lt news

search.lt presents newest links more »

CASHING IN ON CREDIT

Banks partner with popular brands to promote credit cards more »

Virtualization company moves wares to Windows

SWsoft, a company that lets a Linux server be subdivided into independent partitions, is ready to begin testing a Windows version of its product more »

Estonia to Run Tests on 'E-Voting' System

Some Estonians will be able to vote online next year, as Tallinn plans trials with electronic voting software that is the first step toward a nationwide e-voting system more »

search.lt news

search.lt presents newest links more »

Closed Chechen Web site reopens out of Finland

A Web site used by a Chechen warlord to claim responsibility for last month's school siege in Russia has come back online based out of Finland more »