
Mind the malicious code...
By Joris Evers
Published: 1 September 2006 08:35 BST
Several security experts are warning of increased cyber attacks targeting Windows PCs but Microsoft says all is calm on the attack front.
McAfee, the Sans Internet Storm Center, Symantec and several other security companies are warning of a new worm that wriggles into Windows PCs by way of a security flaw for which Microsoft issued a patch with security bulletin MS06-040 on 8 August.
On Thursday, Symantec raised its ThreatCon to Level 2, which means an outbreak is expected. In an alert to customers, the company said it is seeing "ongoing and frequent attacks" that utilise the MS06-040 flaw. There are now six variants of malicious code that exploit the vulnerability, Symantec said.
It said in its alert: "The potential impact of these threats is exaggerated due to reports of successful compromise of Windows NT systems, for which there is no patch available." Windows 2000 and Windows XP are also at risk, according to Symantec.
Symantec was joined in its alert by the other security watchers. The Sans Internet Storm Center, which monitors network threats, noted on its website that several people had reported increased malicious activity. Analysis of the threat, however, found attacks should be "relatively easy to catch". Most antivirus software detects the bad code.
Microsoft, however, has not seen an increase in malicious activity associated with MS06-040, a security hole in a Windows component related to file and printer sharing.
A Microsoft representative said in a statement on Thursday: "Microsoft has been watching diligently since the release of MS06-040 for any increase in malicious activity... At this time we are not seeing an increase over the already existing limited attacks attempting to exploit that vulnerability."
Security tools from Microsoft and third parties offer protection against all current exploits of the flaw, according to Microsoft. Still, those users who have not yet applied the 8 August update are encouraged to do so immediately, Microsoft said.
Malicious code that exploits the Windows hole has already led to significant growth in the number of hijacked PCs, CipherTrust said last week. The messaging-security company has seen a 23 per cent growth in the total number of so-called zombie PCs it has detected and attributed that to the spread of Mocbot worm variants that exploit MS06-040.
If a PC is hijacked, Sans Internet Storm Center recommends completely erasing the hard drive and reinstalling the computer's operating system. It said: "That sounds drastic... but it gets rid of the worm, gets rid of the botnet, and plus you have a brand new box."
Joris Evers writes for CNET News.com
My client is seeking a C# / Delphi developer to join their existing team. The successful applicant will be working on a complex, three tier Real Time ...
Alongside this you will be responsible for Maintenance of current versions of all Software on all Servers and ensure adequate licences for all ...
You will be responsible for support of my clients Infrastructure including (but not limited to) Desktop PCs, Laptops, Handheld email devices, ...
CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.
Stories from the web...
Copyright ©1995-2008 CNET Networks, Inc. All rights reserved. Top of page
Peter Cochrane Peter Cochrane's Blog: Is convergence a fiction? Or could it finally be happening…
Clive Longbottom Quocirca's Straight Talking: A game of two halves Microsoft Virtualisation scores while its SOA bores...