Microsoft refutes claims that Nimda infected its FrontPage

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS
Microsoft refuted claims Wednesday that the main Web site for its FrontPage software had been infected by the Nimda virus, despite the antivirus software alarms set off by viewing the site. On Wednesday, several security experts believed that the software giant -- which has often put the responsibility on customers to patch software holes -- had apparently failed to patch at least one major server. However, Christopher Budd, security program manager for Microsoft's security response center, said that wasn't the case. "No one is being infected," he said. "There is no code to infect people." According to Budd, a third-party content provider that apparently created the elements for the FrontPage site had been infected by Nimda. The worm caused all the HTML files created by the third-party provider to include the script that attempts to upload the worm -- masquerading as a file called "readme.eml" -- to the browser's PC. However, even PCs with no antivirus protection wouldn't have been harmed, because there was no file to upload. "It's an impotent reference," Budd said. "For a PC to be infected by a server, we have to have the script and the payload, but there was no payload on the page." When the third-party provider copied the HTML file to Microsoft's servers, the actual virus was left behind, protecting the software giant. While Budd insisted the server had not been infected, he would not make the same claim for all of Microsoft's systems. As of Wednesday at 3:30 p.m. Pacific Daylight Time, Microsoft's Web site seemed to have been fixed. The close call with the Nimda worm had security experts criticising the software giant for not protecting customers against the virus. "They have talked about being the repository of users' information," said Greg Shipley, director of consulting for network-protection company Neohapsis, "but they have trouble keeping their own stuff secure." Microsoft hosts all the security updates and patches for its products on its site, making it a key destination for Windows users when a worm such as Nimda hits the Internet. Nimda -- which is "admin," the shortened form of "system administrator," spelled backwards -- started spreading early Tuesday morning and quickly infected PCs and servers across the Internet. Also known as Readme.exe and W32.Nimda, the worm is the first to use four different methods to infect not only PCs running Windows 95, 98, Me and 2000, but also servers running Windows 2000. The worm spreads by sending e-mail messages with an infected attachment, scanning for and infecting vulnerable Web servers running Microsoft's Internet Information Server software, copying itself to shared disk drives on networks, and appending JavaScript to Web pages that will download the worm to a surfer's PC when they view the page. It's the latest mode of distribution that many thought had affected Microsoft. Visitors to the software giant's FrontPage site apparently became the target of the Nimda worm when the site attempted to upload the code to their computers. Luckily for them, the code was not there. That should be a small comfort to customers, said Neohapsis' Shipley. "Not only do they have an application-development history of having massive security flaws," he said, "they have an operations history of having flaws." In August, Microsoft admitted that its Hotmail e-mail service had been infected by Code Red. Microsoft isn't alone, however. This time around, several Web servers really were infected with the worm. In one case, the marketing site for fast-food chain Carl's Jr. was infected by the worm. Several CNET News.com readers noticed the compromised server when the site attempted to upload the Nimda worm to their PCs. "That server is hosted elsewhere," said Daniel Baker, director of IT security for parent company CK Restaurants. "They are aware of the problem and will have it resolved soon." Baker added that the worm had not infected the company's own network. Another site, Wininternals.com, is also infected. Readers should not attempt to view the site without adequate antivirus protection and without first setting their browser security to "high." David Dittrich, senior security engineer for the University of Washington and a computer forensics expert, believes software makers such as Microsoft will need to be proactive about future security holes and treat them like product defects. "Somehow, as the number of patches coming out is going up exponentially, the word has to get out to a larger number of people to apply the patches," Dittrich said. Rather than post an advisory on a hard-to-find Web site, software companies should contact customers to tell them to update their software immediately, he said. See the Viruses and Hacking News Section for the latest headlines. Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum. Let the editors know what you think in the Mailroom. And read other letters.

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

35 minutes ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

38 minutes ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

2 hours ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

3 hours ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

4 hours ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

4 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

4 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

5 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
ramwellian

Your comments would seem pretty naive and immature. Your 'solution' appears to be, "gee, let's all just give in to the hackers and give them...

5 hours ago by ramwellian on Cloud computing security: no more oxymoron?
BugStalker

"Interesting thought ... If you installed Win7 as a dual boot on a machine that previously only had Linux, and it wrecked your Linux installation,...

5 hours ago by BugStalker on Windows 7 Declares War on GRUB
whs001

This is an excellent summary of Ubuntu and Mint and the interface differences between them. Most such articles take a very partisan position for...

5 hours ago by whs001 on A tale of two distros: Ubuntu and Linux Mint
Moley

@ewallace. Not so clear. Anyone can obtain the text, for example from here http://www.ustr.gov/webfm_send/2379. I support ACTA so long as it and...

6 hours ago by Moley on ACTA: Facts, misconceptions and questions
45283

I think WinRT is fantastic. I just wish it was an option for people that didn't want to go through Microsoft's App Store with its attendant...

9 hours ago by 45283 on Why Windows 8 needs architectural hygiene for WOA
Burn-IT

Nine people? £30m? Who's back pocket is that lot going in? And IF they say it is for new buildings, what about all the ones the government has...

10 hours ago by Burn-IT on Police set to launch three £30m e-crime hubs
ewallace

Just to be clear, nobody knows what is in the text of ACTA, here is a photograph of the text of ACTA http://twitpic.com/8h9iju as submitted to the...

10 hours ago by ewallace on ACTA: Facts, misconceptions and questions
fgvrg56

Unfortunately main issue is that ASUS is refusing to accept that they make some mistake on this version of asus Transformer prime. 1 - GPS sensor...

11 hours ago by fgvrg56 on Asus Eee Pad Transformer Prime Wi-Fi & GPS problems?
Ben Woods

@Marcus A fair question. Just talked with Archos which said it was working on an announcement for next week....

12 hours ago by Ben Woods on Archos confirms G9 Ice Cream Sandwich update schedule
Marcus Karlsson

Any update on this, considering the claimed "first week of February"?

13 hours ago by Marcus Karlsson via Facebook on Archos confirms G9 Ice Cream Sandwich update schedule
apexwm

Bill Goodrich : Just as al_langevin pointed out, with Windows Server 2008 there is no Services for Macintosh anymore. It's gone, not available....

22 hours ago by apexwm on Windows Server 2008 drops the ball for Mac compatibility
txtrainguy

Replying to an old topic that I'm currently facing with my CEO (who is on a Mac). Our servers are primarily Windows Servers, office is about...

1 day ago by txtrainguy on Windows Server 2008 drops the ball for Mac compatibility