You are here: silicon.com > Software > Security Strategy

Security Strategy

'Witty worm' burns briefly but brightly

Fastest turnaround ever from 'flaw to infection'?

By Robert Lemos

Published: 23 March 2004 08:30 GMT

A worm exploiting holes in one company's internet security software quickly compromised tens of thousands of servers this past weekend, before crashing the infected computers.

The worm, dubbed Witty, exploits a flaw found last Wednesday in software and devices created by network protection firm Internet Security Systems. Using a manner of infection similar to the fast-spreading Slammer worm, the Witty program compromised more than 20,000 machines in less than an hour. The worm also overwrote data on the infected computer, quickly crashing systems, said Johannes Ullrich, chief technology officer for the Internet Storm Center.

"Because it crashes the machines eventually, it died off really fast," Ullrich said. He estimated almost 30,000 computers had been infected by the worm, and most of them had crashed because of file corruption within 30 minutes of being infected.

The worm breached systems through a security hole in ISS's firewall products, such as its BlackICE and RealSecure software. While the flaw affects the company's Proventia network devices, the manner in which the worm is constructed prevents it from infecting the devices.

ISS estimated that the worm could only affect about two per cent of its customer base. Subscribers to the company's maintenance service had already received the update a week prior to the release of the worm, ISS stated on its website.

Dan Ingevaldson, director of ISS's vulnerability research and development group, said: "We have been doing our own research and we came up with 12,000 internet addresses [that seem to be infected] at last check. It is impossible to know how widespread it is. Whenever you count IP addresses you may be double counting or triple counting machines."

An unknown author created the worm about two days after news of the flaw became public, in what may be the fastest turnaround of malicious code writing to date. Like Slammer, the Witty worm spread through single packets of data sent on the Internet using a protocol known as the user datagram protocol, or UDP.

Robert Lemos writes for News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Bob Tarzey The rise and rise of Infor Quocirca's Straight Talking: Where next for the apps giant?

Inbox: Vista, Bletchley Park and Cuil "Windows 98 was a far better and more capable OS..."


  • Jobs
Senior QA (Quality Assurance) Officer, Biopharmaceutical Company

Senior QA (Quality Assurance) Officer, Biopharmaceutical Company, Staffordshire/Oxfordshire Senior QA (Quality Assurance) Officer: My client is a ...

Policy Officer- Herfordshire- Attractive Rates

My client has an excellent opportunity for a Policy Officer. The Policy Officer will Provide a system to capture and co-ordinate organisational ...

Procurement Officer 3-6 month contract in London 250 - 280 P/D

Overall purpose of the job/Key results areas The Procurement Officer is responsible for developing and implementing best practice in procurement ...

CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.





Quick Sitemap Links: