Internet worms
Internet worms
R E L A T E D   C O N T E N T
ADVERTISEMENT

Patch now or suffer Sasser

'Dark forecast' as Windows users warned of new family of viruses

vnunet.com staff, vnunet.com 04 May 2004
ADVERTISEMENT

Microsoft customers are being urged to update their patches to protect against a family of internet worms that are spreading fast by exploiting a vulnerability in Windows.

The Sasser worms exploit the Windows Local Security Authority Subsystem Service flaw, about which Microsoft has already advised users. Four variants of the worm have been reported since 1 May.

Security software firm McAfee warned that systems are especially at risk, as the virus does not spread via email and no user action is required to propagate it. The worm simply instructs vulnerable systems to download and execute its code.

"Computers which are not properly protected with antivirus updates, firewalls and Microsoft's security patches are asking for trouble," warned Graham Cluley, senior technology consultant at antivirus firm Sophos.

Luis Corrons, a director at Panda Software, said that Sasser looked like a dangerously virulent worm.

"All these signs make for a dark forecast for the beginning of the week when it is expected that the number of incidents will soar at the start of the working day," he said in a statement.

The worm scans random IP addresses for vulnerable systems, then sends a specially crafted packet to produce a buffer overrun on LSASS.EXE. This causes the program and infected system to crash, requiring Windows to reboot.

"More infections can lead to increased network traffic and result in severe network slowdowns, like an internal denial-of-service attack," said Joe Hartmann, senior virus researcher and analyst at Trend Micro.

The worm affects Windows 95, 98, ME, NT, 2000 and XP. Customers are advised to apply the necessary patches immediately. The Microsoft patches can be found here.

See also:

Update issued for 'important' flaw in Windows XP and Server 2003 Help Centre  12 May 2004
Iain ThomsonMany IT managers are being caught out by the speed at which hackers are reverse-engineering patches  12 May 2004
Sasser.ELatest variant suggests availability of virus source code, say experts  11 May 2004
Sasser.EGerman law enforcement picks up alleged virus writer, but new variant emerges  10 May 2004
Adapting security policies to cover all threats  05 May 2004
SSL flawsHackers preparing to exploit Secure Socket Layer vulnerabilities in Windows  26 Apr 2004
MicrosoftPatches for more than 20 vulnerabilities in Windows systems  14 Apr 2004
Take cover - here comes another MyDoom/Netsky/Bagle variant ...  17 Mar 2004
Research coincides with new virus outbreak  03 Mar 2004

All Enterprise Security Technology

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Greythorn IT
Leading Mobile Network vendore is currently seeking a Process consultant for a positions based either in the Middle east or Africa. We are looking for around 10 years experience with at least 5 years business ... more >
| Greythorn IT
Tier 1 Network solutions provider is currently seeking an experienced Telecommunications sales manager to work in their Abu Dhabi office. There is a brilliant benefits package as well as an attractive salary available for the ... more >
| Greythorn IT
Leading network solutions provider in Egypt is currently seeking and experienced Egyptian Network Operation /Supervision Engineer. There are competitive packages and attractive benefits package on offer for the right candidate. You will be responsible to ... more >
| Greythorn IT
A leading network Solutions vendor is currently seeking an Egyptian national to act as a Service Assurance manager out of their Egyptian office. Ideally we are looking for someone with Vendor based experience however other ... more >
More job opportunities