Spread of MSBlast worm slows

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS
The MSBlast worm has infected as many as 100,000 computers in the past 24 hours, but the program's spread has slowed, said security researchers on Tuesday.

Click here for information on combating the worm.

The worm's infection rate climbed throughout the day on Monday, but overnight the spread of the program dropped off, said Alfred Huger, senior director of engineering for security company Symantec. The reason for the slower spread is likely because of the poor programming of the worm, rather than a lack of vulnerable computers, he said.

"This is the best-case worm," Huger said. "This didn't turn out to be Slammer, which is good for us, but there is still all the variants" that are likely to crop up.

On Tuesday, new hosts were being claimed by the worm about 40 percent slower than as of the same time Monday, Huger said.

Meanwhile, Microsoft confirmed it is working with law enforcement to find the person or group who released the worm.

"We are working diligiently to make sure that we are going to handle the increase in traffic from the worm," said Stephen Toulouse, security programme manager for Microsoft's security response centre, adding the customers can also download patches from the Microsoft Download Centre.

The worm, which security experts believe started spreading early on Monday, scans for vulnerable computers so widely that an unpatched Windows XP computer on the Internet could be infected in as little as 25 minutes, according to Symantec studies.

Network performance measurement company Keynote Systems reported something of a drop in performance in two of the primary backbones that carry Internet traffic. But for the most part, Keynote found that the worm caused very little slowdown.

"Unlike the Slammer worm, which had significant negative effects on the Internet's infrastructure, the Blaster worm is not having a similar effect, as it is programmed to propagate much more slowly," Lloyd Taylor, Keynote's vice president of technology and operations, said in a statement.

The introduction of the MSBlast worm -- also known as W32.Blaster and W32/LuvSan -- ends nearly a month of speculation over when a programmer would commit the obvious crime of writing a worm to take advantage of a vulnerability in a widely used feature of Microsoft Windows.

The new worm pieces together code to exploit the most recent major flaw in Windows with publicly available tools, such as the Trivial File Transfer Protocol (TFTP) server.

The worm is programmed to cause infected computers to send a flood of data to Microsoft's Windows Update service, starting on Saturday morning. The denial-of-service attack could slow down, and even halt access to, the primary way Microsoft customers receive updates for their computers.

The Update service suffered a different kind of denial-of-service attack on Tuesday as people rushed to patch their PCs. The increased volume slowed, or prevented, access to the service. Multiple attempts to connect to the service from CNET's offices failed.

Microsoft representatives were not immediately available for comment.

MSBlast's first attack will last until the end of the year, security researchers said, adding that the coding of the worm will cause it to continue the attack in the latter half of each month for the first six months of 2004.

The worm still hasn't reached the levels of Code Red II, which infected more than 300,000 servers in 10 hours. However, the original Code Red spread very slowly until some online vandal modified the worm and fixed a critical flaw in how it spread. Symantec's Huger worries that someone might do the same with the MSBlast worm.

"This was written very poorly," Symantec's Huger said. "It's the children of Blaster that I fear now."

Talkback

oh my god i am so scared of this im shaking.
one of 4 have the worm in my house!
This is crazy!
can someone please catch the person who did this and punch him in the gut for me......
i have no way of expressing this, its just wrong!!!!!

i hoope everyone goes well in this epidemic.

i say save urselves!
to every one who are not taking precautions.
this thing is very easy to catch.
all i did was get on the net and read some news on this bug. then all of a sudden my comp cllosed. i followed the steps at www.windows.com/security
this is a place where they help.

save urselves man!!!!

via Facebook 13 August, 2003 13:15
Reply

Another way of combatting this would be to right click on your isp in the nework connections in control panel go to properties advanced and click on protect my computer. Go to settings and click on whatever you use. I clicked HTTP and the FTP access when you check each one a box will come up.. click ok on each one. click ok on the main an it should be ok... atleast that is what works for me.

via Facebook 13 August, 2003 13:55
Reply

I think it's wrong to say this worm was written poorly. Yes, it's speared slows quickly, but think about it:
Our worm-writer included messages to Microsoft and Bill Gates in his code, right? I don't believe he/she/the group actually ever intended to really hurt the MS-buying public. I really think that what they wanted to do was more like spread a little panic, and bring to Microsoft's and the public's attention that there's always holes and such in Microsoft's systems and browsers. This was basically meant to take a blow at Microsoft, that's what I think. Despite that the flow of infected computers has slowed, the programmer(s) seems to have accomplished EXACTLY what they wanted. - A.C. age 14

via Facebook 13 August, 2003 15:05
Reply

Little jerkoffs that produce viruses deseve to be locked up and the key thrown away.
They need to get a life.

via Facebook 13 August, 2003 15:39
Reply

Can someone please pressure MS into distributing through agents (at least) and on request quarterly update CDs? This will ease congestion at their website and spare the agony of dialup uers.

via Facebook 13 August, 2003 16:07
Reply

For anyone out there who is very concerned about this worm virus, don't be. For one, it can only infect computers with 2000, ME, NT, or XP. Other wise, its harmless. For those of you who already have it, it sucks just let me say that. I am a gamer for say and I build systems as a hobby, and of all the viruses that i have experience with, i think by preference i hat this one the most. Random power offs, and occasional denied internet access is really crappy, especially if you are in the middle of installing a new service pack.
The most disturbing thing is that somebody has nothing better to do with their time but create this crap to infect other computers, in order to 'get back' at a company. The message, "Billy Gates why did you make this possible? Quit making all that money and fix your software!" clearly adresses a hostilitiy towards microsoft. Another solution is someone got bored and decided to be a complete and total dick head and create a virus that would infect thousands.
The good news is it is easy to get rid of. Download the fix it file from anywhere, and then go and download the patch for whatever operating system you are running.
That will ensure that the virus cannot get BACK onto your computer.
An interesting note also is that this virus or WORM has the capability to replicate and infect without an email or download interface.
If your computer is hooked up to a network, and one of the computers in the network got the virus, then it is very possible that you will have it too. All it needs is for your computer to be on. In other words, its airborn, in a more kind of a biological way of speaking.
Good luck

via Facebook 15 August, 2003 02:38
Reply

It's unfortunate that there's snerts out there that have nothing better to do than to wreak havoc on the public. On the other hand, if MS didn't make such a piece of crap of a product, things like this wouldn't happen nearly as often. The ONLY reason I applied the msblast patch was to assist those people trying to get to the update site. As far as MS is concerned, I couldn't have cared less. I believe the poster named Mancy has a good idea with MS sending us CDs. But that's too idealistic. Bill Gates wants your $$! Because MS' OSes is pretty much the only game in town, they can dictate to hardware and software makers how/what/when. When will this monopoly end? When WE the consumer public will stop accepting the idea of "well, XP IS better than '98/'95" and DEMAND an OS as good as MAC X, Linux, etc. When I get off my lazy butt, I WILL migrate totally to Linux, open-source! MS can go straight to hell, imo!

via Facebook 20 August, 2003 06:17
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Freebies202

Duplicate comments are not made intentionally. Its very good to know that now you are keeping check on this problem because sometimes a commenter...

4 hours ago by Freebies202 on Microsoft fixes blog comments, speeds up blogs with open source
kevinmchapman

"the very significant number of users" and "many (most) of us" - you have no evidence for these statements. It is a fact that most users are saying...

12 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
Marg Menzies Harrison

Another grammar faux pas is the improper use of "you". When sitting down down in a restaurant, for example, I get cringe when the waitress...

14 hours ago by Marg Menzies Harrison via Facebook on 10 flagrant grammar mistakes that make you look stupid
zdnetukuser

And NOW, folks, for Canonical's next trick... Kubuntu is late. Here's a pencil. Draw your own conclusions. cf.:...

14 hours ago by zdnetukuser on Linux Minterface
Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

16 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

18 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

19 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

19 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

20 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

21 hours ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

22 hours ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

1 day ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

1 day ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

1 day ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

1 day ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

1 day ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

1 day ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

1 day ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint