DV Hardware bringing you the hottest news about processors, graphics cards, Intel, AMD, NVIDIA, ATi, hardware and technology!

   Home | News submit | News Archives | Reviews | Articles | Howto's | Downloads | Mirror Area | Advertise
 
DarkVision Hardware - Daily tech news
  Login/sign up  


Main Menu

Home
User account
Info
News archives
Links
Articles
Howto
Reviews
Member list
 

Who's Online
There are currently 439 people and 1 DV-member(s) online.

 

Latest Reviews
  • Kingston DataTraveler 150 32GB USB drive
  • Super Talent Pico 8GB USB Drive
  • Razer Destructor mousepad
  • Ghost Squad for Nintendo Wii
  • OCZ DDR2 PC2-9200 Reaper HPC Edition
  • Vizo Ninja II notebook cooler
  • PC Power & Cooling Silencer 610 PSU
  • Mario & Sonic at the Olympic Games for Nintendo Wii
  •  

    RSS
    RSS
    RSS by email. Enter your email address:

     

    Recommended: Click here to Update all your outdated drivers

    Exploit in ISS's BlackICE firewall feeds fast-spreading worm Witty

    Posted on Tuesday, March 23 2004 @ 00:14:34 CET by Thomas De Maesschalck


    Since Saturday Witty, a fast-spreading worm, has infected between 10,000 and 50,000 computer systems by exploiting a vulnerability in ISS's BlackICE firewall. The worm Witty exploits a stack overflow vulnerability within BlackICE that was disclosed only two days before the worm first appeared.
    Unlike most other worms, Witty doesn't need human interaction to spread. Rather than rely on users to open a file attachment--the typical way worms propagate--Witty simply scans for vulnerable systems, then uses UDP port 4000 to infect the machine. This auto-spread strategy was last used to wreak havoc by 2003's MSBlast worm.

    Witty is particularly dangerous, said experts, because after it executes, it opens a random drive on the PC and writes 65KB of data to a random location on the disk. It repeats that process until the system is rebooted or the computer crashes.

    "This worm is highly malicious, slowly destroying the systems it infects," said security firm Lurhq, in an alert posted on its Web site. "Rather than simply executing a 'format C:' or similar destructive command, the worm slowly corrupts the file system while it continues to spread. Any infected machine will likely have its operating system and partition data destroyed along with most files on the physical drives, depending on how long the worm runs on the machine."

    Internet Security Systems said its analysis indicated that only about two percent of its customers could be open to Witty's attack, but other analysts have tagged the number of infected machines at significant levels.

    "It's unlikely that many computers will be patched against this vulnerability at this time," said Ken Dunham, the director of malicious code research at iDefense, in an e-mailed statement. "Early data suggests about 10,000 infected computers worldwide." Others have put forward the number of 50,000 infected machines.

    Experts such as Dunham urged ISS customers to disable the firewall until it has been patched, and, where feasible, block traffic on UDP port 4000. ISS recommended that infected systems be disconnected from the network to stop the worm's spread.
    So if you are using BlackICE please update your firewall as soon as possible at ISS's website

    Source: InformationWeek


    Add to Del.icio.us | Digg It

     
    Threshold
      
    The comments are owned by the poster. We aren't responsible for their content.
     

    DarkVision Hardware - Privacy statement
    All logos and trademarks are property of their respective owner.
    The comments are property of their posters, all the rest © 2002-2008 DarkVision Hardware