New worm's got sass, but not much else

Published: 3 May 2004 y., Monday
The company, which found the flaws that were exploited by both the MSBlast worm and the Witty worm, on Saturday started analyzing the latest piece of attack code that takes advantage of a Microsoft Windows vulnerability discovered by its researchers. So far, eEye's analysts are surprised that the worm has spread so far. The Sasser worm started spreading late Friday, and so far has not racked up the crowd of compromised computers that its predecessors have been able to claim. Such a limited spread could indicate that computer users are becoming more diligent about heeding warnings and patching their systems, but security researchers believe that the worm's poor programming has given network administrators a break. "If this virus was better written, you would have seen more impact," said Alfred Huger, senior director of security firm Symantec's response center. The Sasser worm spreads from infected computer to vulnerable computer with no user interaction required. The worm exploits a recent vulnerability in a component of Microsoft Windows known as the Local Security Authority Subsystem Service, or LSASS. After scanning for vulnerable Windows XP and Windows 2000 systems, the worm creates a remote connection to the system, installs a file transfer protocol (FTP) server and then downloads itself to the new host.
Šaltinis: CNET News.com
Copying, publishing, announcing any information from the News.lt portal without written permission of News.lt editorial office is prohibited.

Facebook Comments

New comment


Captcha

Associated articles

Could Anthrax Scare Boost E-Mail Use?

All across America, anthrax-leery corporate mailrooms are taking extra care with envelopes and packages more »

India Slates $2Bil Plan For In-School Internet

India's government plans to invest $2 billion to improve Internet access in schools across the country. more »

Afghanistan, on 50 Websites a Day

Since the Sept. 11 attacks, the international spotlight has been trained on Afghanistan, the Central Asian country notorious for housing one of the most repressive regimes on the planet as well as suspected terrorist Osama bin Laden. more »

Swedish Mobile Users To Get Locatable E-911 Services

Hard on the heels of Sprint PCS announcing satellite location-enhanced emergency 911 (E-911) services in the U.S. last week, Europolitan Vodafone has announced plans for a similar set of services for its Swedish cellular users. more »

Digital Island Launches 2Way Web Services

San Francisco-based content delivery network Digital Island Inc. made its first significant move Thursday under the aegis of Cable & Wireless more »

Investment in Voice Technology Increases

Global investment in voice technologies in 2001 is already up by 33 percent, compared to the total investment made in 2000, according to a report by Datamonitor more »

FBI, industry team on computer security

The FBI is teaming with the computer industry to help American companies and regular Internet users prevent the 20 worst computer threats -- from the "Code Red" worm to the "Melissa" virus. more »

New Duron kicks off AMD chip parade

Advanced Micro Devices is getting October off to a start by releasing a series of processors for desktop PCs. more »

New virus "Vote"

Kaspersky Labs Strongly Urges Updating Your Anti-Virus Database more »

Microsoft Passport Still Faces Concerns

Microsoft is still a long way from resolving concerns about interoperability and control of enterprise information in its Passport authentication services more »