You are here: silicon.com > Software > Security Strategy

Security Strategy

New Bobax worm copies Sasser exploit

It's spreading slowly but get patched anyway…

By Dawn Kawamoto

Published: 20 May 2004 08:45 GMT

A new worm that turns infected computers into launch pads for spam and other attacks is making the rounds, according to antivirus experts.

Bobax, which was discovered on Sunday, uses the same Microsoft security vulnerability as the fast-spreading Sasser worm, but it looks to be slower.

Craig Schmugar, virus research manager for McAfee Alert Antivirus Centre, said: "The seriousness of Bobax is about a three or four [on a scale of 10]. It's attacking systems that are already vulnerable to Sasser. If you have Sasser, then you could see an additional slow down with your computer, but not necessarily. Bobax can also make your computer reboot, but not as frequently as with Sasser."

Bobax exploits a vulnerability in a Windows security component known as the Local Security Authority Subsystem Service (LSASS). The LSASS flaw is present in all recent versions of Windows, but Bobax is programmed to target only the XP operating system. Once established on a system, Bobax contacts a website and gets instructions on what to do next, such as sending spam or running other programs.

"This worm has more of an ulterior motive than Sasser," Schmugar said.

But Bobax's infection rate is far less severe than Sasser's, antivirus experts said.

Antivirus firm Sophos expects Bobax's impact to be more limited because a number of computer systems have already received the Microsoft patch for the LSASS flaw and have shored up their firewalls and antivirus protection. The worm's spread is also inhibited because it is targeting only XP, said Schmugar.

"We're not seeing as many machines affected as with Sasser," Schmugar said, noting that Bobax has infected about one-tenth the 500,000 to one million machines racked up by Sasser.

Dawn Kawamoto writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business

Jon Collins Is losing a mobile device really such a big deal? How to minimise the damage to your business


  • Jobs
Vulnerability / Penetration tester (CEH) -

An immediate opening has arisen for a penetration / Vulnerability tester who also has a broad general Info sec background. My client is a FTSE 100 ...

Information Security Analyst (Attack Monitoring/Data Leakage/CISSP/CEH

You must have previous experience in a dedicated vulnerability management function where you have been responsible for all potential attacks on a ...

IT Technical Support Engineer - Manchester

Also knowledge of routers, firewalls, switches, DNS, DHCP, Internet lines printers, backups, antivirus, spam, spyware prevention an advantage. IT ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: