DoS worm invades Microsoft servers

NEWS A program created to automatically flood Microsoft's Web and email servers has been discovered on several corporate networks and may have spread further on the Internet, antivirus researchers said Friday. Discovered this week, the worm -- dubbed DoS.Storm -- infects Microsoft Web servers and then scans for new machines to infect, floods Microsoft's main Web site with data, and sends a deluge of obscene email to an apparently invalid address for Microsoft Chairman Bill Gates. "This is one of the trends that we are going to see more and more of: the crossover between the hacking and virus writing, and moving away from email-borne worms," said Vincent Weafer, director of software maker Symantec's antivirus research centre. The worm spreads by exploiting a known flaw in Microsoft's flagship Web server software, called the Internet Information Service (IIS). The vulnerability, dubbed the "Web server folder traversal" flaw, affects Microsoft IIS 4.0 and 5.0. Although Symantec researchers found the flaw last October, the security hole had been fixed by a previous patch released in August 2000. Once it infects a server, the worm starts scanning 10 million Internet addresses, looking for more vulnerable servers to infect. The worm also initiates an attack on Microsoft, sending a flood of data to overwhelm its Web servers. Known as a denial-of-service (DoS) attack, almost 4,000 such attacks take place every week, according to a recent study. Microsoft Web sites were crippled by a series of DoS attacks in January. In addition, the worm will send a constant stream of e-mail to "gates@microsoft.com" with the message "F**k you!" The address is believed to be invalid, causing the emails to bounce back to the sender. Microsoft representatives were not immediately available for comment. Only a handful of Symantec customers have reported finding DoS.Storm, said Weafer, who does not expect it to spread far. "If people update their security patches, it should not be a problem," he said. "The crunch question is, of course, how many people have patched." Moreover, the worm's activities make it fairly easy to detect, he added. The program's search for other vulnerable servers combined with the deluge of data and mail tends to redline the capacity of most corporate network connection, tipping off even the most inexperienced system administrators. "Anyone with a good firewall and intrusion-detect system can see this thing easily," Weafer said. Rival anti-virus company Trend Micro had no indications of the worm from its customers. Is your PC safe? Find out in ZDNet UK's Viruses and Hacking News Section. Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum. Let the editors know what you think in the Mailroom. And read other letters.

Post your comment

In order to post a comment you need to be registered and logged in

Log in or create your ZDNet UK account below

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Membership FAQ

ZDNet UK Live

chaycon1

Online Fiber Optic Certification Join a talented group of professionals, who are dedicated to Fiber Optic Networking technology. The online course...

1 hour ago by chaycon1 on BT launches 40Mbps fibre-based broadband
chaycon1

Online Fiber Optic Certification Join a talented group of professionals, who are dedicated to Fiber Optic Networking technology. The online course...

1 hour ago by chaycon1 on Google to build gigabit broadband to the home
J.A. Watson

Hi Dava, I'm glad to hear from you, and glad that you see things from the other side. I think that is the most important point of the whole...

2 hours ago by J.A. Watson on Ubuntu 10.04 (Lucid Lynx) and the Latest Tempest
dava4444

please please please please please please kill that spam bot.

2 hours ago by dava4444 on ZDNet UK: faster, smarter, still IT all the way
253chelisa253

hi

3 hours ago by 253chelisa253 on How security will look in 10 years
lezlow

it is only greedy[microsoft]?

4 hours ago by lezlow on Researchers break into BitLocker
dava4444

it didn't post the link it's 'Ubuntu 10.04 Lucid Lynx Beta-1 First Look' on youtube :) Dava

5 hours ago by dava4444 on Ubuntu 10.04 (Lucid Lynx) and the Latest Tempest
dava4444

Hi James I disagree, Ubuntu needs a GUI update and this one IMO is quite good. your pics show a low res. here's a high res. on YouTube* The...

5 hours ago by dava4444 on Ubuntu 10.04 (Lucid Lynx) and the Latest Tempest
dava4444

Hi any news on the comment bot? knocking me back from my own blog is a bit cheeky lol *Mulder to Scully* "I think it has an agenda.." I know, I...

6 hours ago by dava4444 on ZDNet UK: faster, smarter, still IT all the way
benny boy

if you look at the Brentwood exchange on samknows it servers 21,000 residential propertiesm, Lowestoft serves 31,000! Come on BT sort yourselves...

6 hours ago by benny boy on BT fibre broadband coming to 69 more towns
pbreddit

[programming] H.264 - a sting in the tail http://reddit.com/bfu4q [zdnet.co.uk]

reddit

H.264 - a sting in the tail [programming] 13 points, submitted by zigzag [zdnet.co.uk] http://reddit.com/bfu4q

cybfor

Malware infects second Vodafone HTC phone: [zdnet.co.uk] A second Android-based HTC Magic from Vodafone has been... http://dlvr.it/KhKx

miyabi81

Chatter preview http://www.zdnet.co.uk/news/application-development/2010/03/17/salesforce-opens-up-chatter-developer-preview-40088348/

cybfor

US gov t considers undercover social networking: [zdnet.co.uk] The Obama administration has considered sending... http://dlvr.it/Kh3L

sudipta_vodafone

Please give me chance in the vodafone essar Ltd as back office executive

13 hours ago by sudipta_vodafone on Vodafone culls 375 'mainly back-office' jobs
sudipta_vodafone

I want to get a back office job in vodafone direct payroll

13 hours ago by sudipta_vodafone on Vodafone culls 375 'mainly back-office' jobs
Xwindowsjunkie

I also find it harder to use. It used to scale properly in Firefox. Text would size up and down without dragging all the right edge debris with it....

17 hours ago by Xwindowsjunkie on ZDNet UK: faster, smarter, still IT all the way
dava4444

that comment bot is a nutter, it just referred me to the moderator on my own blog. shocked look. please help thank you Dava I'm afriad to...

20 hours ago by dava4444 on Welcome to the new ZDNet UK community!
dava4444

Hi Rupert! Don't think I could fill the above shoes... but if your ever looking for a consumer rights Tech blogger..tip me the wink lol peace Dava

22 hours ago by dava4444 on Fancy working for ZDNet UK?

Featured white papers

Achieving PCI Compliance for:Privileged Password Management & Remote Vendor Access

For multi-store outlets, including retail, banking, grocery, gas, hospitality, convenience stores and others, reducing (or avoiding) the cost of in-store system support and maintenance while maintaining compliance with PCI and other requirements has become a strategic challenge.

Download now

Web 2.0 Security Threats: How to Protect Your Enterprise Network

Speaker: Dr. Chenxi Wang, Principal Analyst, Security and Risk Management, Forrester Research, Inc. As Enterprises are increasingly connected to the Internet and as hard organizational boundaries are fast disappearing, security professionals are facing fresh challenges in Enterprise computing.

Download now

MindManager - Tutorial for New Users - Short

This tutorial is for new MindManager users and teaches you how to get started, by creating maps, reading maps and organizing your information.

Download now