Companies escape Sasser infection

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS
The Sasser worms continued to wriggle into computers on Tuesday, hitting home users hard while affecting companies to a lesser degree than previous attacks, security experts said.

Antivirus software maker Network Associates believed that as many as 80 percent of those infected were home users and students. That poses a much greater problem than compromised corporate computers, in terms of Internet safety, said Vincent Gullotto, vice president of Network Associates' McAfee Anti-Virus Emergency Response Team.

"The problem is that most of those infections are not going away any time soon," he said. "Those people (home users) don't generally know what to do."

The Sasser worm, which started spreading Friday, has infected an estimated 500,000 to a million systems, according to security experts. Nearly 1.5 million customers visited Microsoft.com and used the Sasser scanning and cleaning tool in the first 48 hours of its availability, the software giant said on Tuesday. The number is not a reliable measure of infection, because many of those users may not have been compromised by Sasser, a company representative said.

The worm does little damage and, unlike previous fast-spreading worms, has not caused overwhelming network disruptions. However, in many cases, the worm does cause infected Windows XP and Windows 2000 computers to repeatedly reboot.

Two new variations of Sasser -- Sasser.C and Sasser.D -- started spreading on Monday. Like the original and the Sasser.B variant, the new worms take advantage of a vulnerability in unpatched versions of Windows XP and Windows 2000 systems. The worms infect vulnerable systems by establishing a remote connection to the targeted computer, installing an FTP (File Transfer Protocol) server and then downloading themselves to the new host. Unlike mass-mailing computer viruses -- such as MyDoom and Sobig -- Sasser does not spread from computer to computer through email.

The original version of the Sasser worm spread slowly, but on Saturday, online vandals released Sasser.B, which infected computers much faster. By Monday, two new variants had appeared, and the worm had spread to hundreds of thousands of systems.

On Tuesday, security company Symantec updated the number of infections it had confirmed to 100,000, 10 times higher than the company's Monday figure. Most of that increase is due to the security software maker aggressively scanning for compromised computers, meaning that the rise doesn't necessarily represent how fast the program is spreading, said Alfred Huger, senior director of Symantec Security Response.

Many compromised systems may not be visible to external security surveys and detection, so the actual number of infected systems could be higher. Although Symantec and others that monitor Internet security believed that the recent MSBlast worm had spread to perhaps 500,000 computers, Microsoft later discovered that almost 10 million computers had so far been infected.

In another measure of the effects of the worm, Symantec had received almost 8,000 reports of the virus from customers. Like those logged by rival Network Associates, the overwhelming majority of the reports were from home users, Huger said, but he added that the number of submissions from home users is typically higher, because each generally represents a single PC.

"Ten home users are going to give 10 different submissions, but each corporate report represents many infections," he said.

Huger also stressed that the damage -- in terms of productivity lost -- will largely result from corporations cleaning up the worm.

This time around, telephone company and Internet service provider SBC Communications tried to minimise the problem for its Net customers. The company warned them by email this weekend about the worm and urged them to patch their systems.

"It is extremely important you [patch your systems] now, because it's likely you will not be able to take these measures, if your computer becomes infected," the company told customers.

"We saw an initial increase in network traffic, and we have seen that stabilise since taking some actions," said Larry Meyer, spokesman for SBC.

Many home users still connect their computers directly to their broadband Internet line and don't use security software. SBC warned those users to patch their systems, turn on the firewall and install antivirus software to protect against Sasser and Gaobot, also known as Agobot, which the company considered to be a greater threat.

"Sasser is the more rapidly spreading of the two, but Gaobot is potentially much more dangerous, because it gives access to the infected computer," Meyer said.

The original worm did not spread very quickly on Friday and Saturday, according to security experts. But some Windows XP users asked for help by way of a support list when, as a side effect of infection, their computers displayed an error message and restarted.

Still, "the number of home users seeking help on cleaning the Sasser worm in the MS Windows XP Technical Support newsgroup is far less than last year, when the MSBlast worm was released," said Yan Kei "Kenrick" Fu, a Hong Kong college student and a frequent adviser to users of Microsoft's support lists.

At the University of Massachusetts at Amherst, 1,100 computers were compromised with Sasser, after students connected their already infected computers to the campus networks Monday.

Delta Air Lines encountered problems in Atlanta with its computers for more than six hours, resulting in delays. Although the carrier said it has solved the problems, it wouldn't comment on what caused the issues, spokesman Anthony Black said on Tuesday.

In August, airline Air Canada cancelled flights due to its network being infected with a variant of the MSBlast worm. The MSBlast.B worm, also called Welchia and Nachi, spread so aggressively that it inundated many companies' networks with data. Air Canada said its network couldn't deal with the amount of traffic generated by the hostile program.

Other reports, including several mentions of a German company that had 300,000 compromised computers, have turned out to be erroneous.

Network Associates' Gullotto said that overall, companies have not had a high percentage of infections. Corporations of 50,000 or more users may have had hundreds of compromised computers, but in general, less than 1 percent of systems are being affected, he said.

"When we see Sobig, Blaster, we -- my antivirus group -- get hammered," he said. "We aren't seeing that this time. We aren't seeing the pain."

Talkback

Earlier this week, I purchased your software with firewall. I was told that a firewall would prevent this type of "people generated" sabatoge (developing viruses just to hurt innocept people). The filewall does prevent viruses from attacking a personal computer, correct? If not, what is the intended use of a firewall. Thank you for your help.

via Facebook 5 May, 2004 22:28
Reply

DO Roberts: A firewall will help, yes. It's not completely infallible, but someone would really have to want to hack into your system to get round it. Basically it's like putting a lock on your front door rather than having it wide open. It'll stop chancers that might just hop in, see a TV and take it, but it won't stop a professional burglar that's seen a 10 grand plasma screen TV through your window.

If you want to test how good your firewall is, go to www.grc.com and use their ShieldsUp test.

via Facebook 7 May, 2004 11:28
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Freebies202

Duplicate comments are not made intentionally. Its very good to know that now you are keeping check on this problem because sometimes a commenter...

2 hours ago by Freebies202 on Microsoft fixes blog comments, speeds up blogs with open source
kevinmchapman

"the very significant number of users" and "many (most) of us" - you have no evidence for these statements. It is a fact that most users are saying...

10 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
Marg Menzies Harrison

Another grammar faux pas is the improper use of "you". When sitting down down in a restaurant, for example, I get cringe when the waitress...

12 hours ago by Marg Menzies Harrison via Facebook on 10 flagrant grammar mistakes that make you look stupid
zdnetukuser

And NOW, folks, for Canonical's next trick... Kubuntu is late. Here's a pencil. Draw your own conclusions. cf.:...

12 hours ago by zdnetukuser on Linux Minterface
Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

14 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

16 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

17 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

18 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

18 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

19 hours ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

21 hours ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

1 day ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

1 day ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

1 day ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

1 day ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

1 day ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

1 day ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

1 day ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint