August 15, 2003 4:00 AM PDT

Squashing the next worm

Related Stories

Cleanup dampens Blaster worm

August 14, 2003

Microsoft prepares to be Blasted

August 13, 2003

Decoding the lessons of Slammer

March 4, 2003

Bush unveils final cybersecurity plan

February 14, 2003

Patchwork security

January 24, 2001

special coverage
'MSBlast' echoes over Net
 Worm exploits widespread
 Windows flaw


Another virus, another epidemic.

Two years after the Code Red and Nimda worms spread across the Internet, home users and many companies still aren't doing enough to secure themselves against Internet threats, said security experts.

"Software is still flawed, people are still not patching, and companies are still not making security a focus," said Marc Maiffret, chief hacking officer for security software maker eEye Digital Security. "They didn't after Code Red, they didn't after Nimda, and they didn't after Sapphire/Slammer. Mostly likely, they won't after this worm either."

The criticism comes after the poorly programmed MSBlast worm spread worldwide. Despite numerous flaws in its code, the worm--also known as W32/Blaster and W32.Lovsan--infected more than 330,000 computers running Microsoft Windows. The computers were vulnerable as the result of a month-old flaw their owners had left unpatched.

The same script played out during the Code Red worm epidemics in July and August of 2001, the Nimda worm attack in September 2001 and the Slammer attack this past January. The lack of progress in lessening the effects of such attacks has security experts worried that companies and individuals are making too little headway, if any, in securing their computers.

"This worm shows that, even in a relatively sane scenario, what many are doing doesn't work," said Ted Julian, chief strategist for network-security company Arbor Networks. "We had weeks to prepare, and we aren't able to secure everything."

The statements come six months after the Bush administration released the first version of the United States' National Strategy to Secure Cyberspace, a document which aims to focus the efforts of government agencies and private industry toward defeating digital threats and protecting infrastructure.

Despite the release of the strategy, security on the Internet remains flawed at best. For example, a key piece of infrastructure for millions of Windows users will come under attack starting at 4 a.m. PT when worm-infected computers from the Asia-Pacific region start flooding Microsoft's Windows Update site. As successive time zones reach midnight on Friday, the attack will grow.

Microsoft hasn't detailed what steps it is taking to dodge the attack. However, the software giant is advertising alternative ways to get downloads and information from its site. The company has put more than 10 links on its main Web site to send people to more information and alternative channels for downloading updates.

In addition, the company had changed the Internet addresses to which the domain Windowsupdate.com refers, which likely means that a different network will handle the brunt of the attack. A source familiar with the changes said that the new addresses are on a network isolated from other Microsoft computers, so if the network is bogged down by the attack, the company will suffer no other ill effects.

The company will take steps in the future to better lock down PCs as well, said Jeff Jones, senior director for Microsoft's Trustworthy Computing initiative.

"For add-on security software, we are going to look at erring on the side of security rather than features and settings," Jones said.

The Internet Connection Firewall, a basic piece of software security that comes with Windows XP, will likely be turned on by default in the future, Jones said. He couldn't say when that will happen, however. The switch could occur in the next big update, called service packs, or be held off until a new version of the Windows operating system is released.

Moreover, software makers need to make their applications work better with the security of home computers, rather than bypassing the protections, said Fred Felman, vice president of marketing for computer-security software maker ZoneLabs.

"Application vendors do need to be more responsible about what services they do need to open up," Felman said.

Many times, consumers who have turned on firewalls will turn them off whenever an application doesn't seem to work properly. Often, they forget to turn the firewall back on.

Such basic training is also necessary to raise the level of awareness among home users, perhaps the category of PC user most responsible for vulnerable systems on the Internet. Education has been repeatedly touted as a solution to security woes. However, people still remain ignorant about many of the aspects of security and almost always pick convenience and whiz-bang features over security, Felman said.

"It is all this idea that people have valued productivity over security for a long period of time," Felman said. "We have been making more services and applications available to people (on their computers). As a result of this, we are all more vulnerable."

Microsoft's Jones pointed out that the news regarding MSBlast is not all bad. Considering that the flaw the worm exploits is thought to be the most widespread to date--potentially affecting hundreds of millions of PCs and servers--a Code Red-size epidemic is not that bad.

"The infections are lower (in relation to) the potential for spread of this thing," Jones said. "I think the industry has done a good job of getting the industry message out there. I can only make a personal observation: I'm glad it wasn't worse."

Powered by Jive Software
advertisement

Latest tech news headlines

Resource center from News.com sponsors
Same great protection. Reengineered for speed.
Norton Internet Security™2008

Click Here!
Norton still delivers award-winning protection and now uses 83% less memory and scans 48% faster than the competitor average. Get a FREE trial today!

Click Here!
Norton Beats the Competition

See how Norton Internet Security™2008 uses less memory, while scanning and booting faster than the competitor average.

Norton Protection Blog

Read the latest from our security experts as they help protect people from evolving online threats.

Protect Your Bluetooth Connection

Don't let fraudsters sink their teeth into your Bluetooth connection.

Vishing - What you need to know

Meet the latest ID theft scam: Voice Phishing.

Take Norton for a Test Drive Today!

Act now to get your FREE trial of Norton Internet Security 2008.

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right
  • News - Business Tech

    Samsung contemplating SanDisk acquisition

    South Korean consumer electronics giant is considering a buyout of the chipmaker to reduce its NAND flash memory costs, according to PaidContent.

  • Gallery

    Photos: Ron Paul's RNC alternative

    As the Republican convention took place just miles away, a crowd rallied for the former presidential candidate and his message of limited government, ensured civil liberties, lower taxes, and peace.

  • News - Apple

    iPhone to ingest EA's 'Spore Origins'

    The game that lets players design creatures and see them through a digital evolution is coming to Apple's iPhone and iPod Touch.

  • Beyond Binary

    Memo: Windows chief on new ads

    Windows business unit head Bill Veghte send a memo to troops late Thursday promising that the debut Seinfeld/Bill Gates ad was just an "icebreaker."

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Wireless

    Nokia market share to take a hit

    The No.1 mobile handset maker in the world says a weakening global economy and price cuts from competitors will affect its market share standing for the third quarter.

  • Video

    Political party playlists

    We know the Democrats and Republicans are split over policy issues, but does their musical taste fall down party lines too? And what kind of gadgets did they bring to the conventions to listen to their music? CNET reporter Kara Tsuboi finds out.

  • News - Politics and Law

    Video: Republican convention, day 4 recap

    John McCain offers his vision of what the country can expect if he and running mate Sarah Palin are sworn into office in January.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Photos: The brains behind Google Chrome

    Here's a look at some of the engineers and executives who took the stage at the company's headquarters as they unveiled the new browser.

  • Gadgettes, the blog

    Gadgettes 105: The Sing, Sing a Song Episode

    We have music on the brain in today's episode of Gadgettes. Don't worry, we won't destroy your ear drums with ear-piercing renditions of your least favorite '80s tunes. Instead, we'll soften the blow with a slew of musical gadgets and accessories.

  • Green Tech

    Green news harvest: Stolen solar panels, hydrogen at home

    Tata to bring small, all-electric car to Norway next year; a banner years for wind power; a home hydrogen-filling station; comparing the presidential candidates on plug-in cars; a microbial fuel cell for developing world; tips on greening your PC.