Sasser risk 'not yet over'

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS
Although the damage wrought by Sasser failed to reach the levels of MSBlast and other major infections, security experts are warning that there could still be more trouble to come from the worm.

One researcher warned on Thursday that the group of online vandals suspected of creating both the Sasser worm and several variations of the Netsky virus could combine the two threats.

The resulting blended threat could dodge security inside corporate systems via email messages and then spread quickly, once inside those networks.

"Sasser is inhibited by gateways, and adding the email aspect would bypass the gateways," said Jimmy Kuo, a researcher and a McAfee fellow at security company Network Associates. The technique is "rather obvious," he said, defending the decision to publicise the strategy in an alert. "I don't think I am giving a clue to the virus authors," he said.

The six-day-old Sasser worm has begun to spread more slowly, as companies clean up existing infections, according to security researchers. However, as with previous worm programs, it's unlikely that Sasser and its offshoots will ever truly disappear from the Internet. While new versions of a particular worm tend to have a smaller effect than the original, variants that add different ways to disseminate themselves -- whether by exploiting other flaws or by fooling users -- could have more impact.

After Code Red struck Web servers almost three years ago, an unknown programmer modified the code to allow the worm to spread via network shares and email attachments. The resulting program, called Nimda, caused so much damage that Microsoft had to assuage its customers' concerns by embarking on a security initiative, known as Trustworthy Computing.

Security problems are once again becoming an issue for the software giant's customers. This week, business intelligence firm Gartner warned companies that use Microsoft products to consider the money they spend in responding to worms and other threats as part of a product's total cost of ownership. In an online research advisory, Gartner warned that corporate information technology teams will have to apply patches more quickly and buy additional tools to make sure that Windows-based computers are secure.

"Two working weeks is a really short time for an enterprise to get the patch, test the patch and get the patch on its systems," said John Pescatore, vice president of Internet security at Gartner.

It seems, however, that Microsoft has learned from past incidents: it has put its weight into providing an easier way for customers to clean their systems of Sasser.

Within 24 hours of the worm's appearance on the Internet, the company had released instructions on getting rid of the program. On Saturday, it released an ActiveX program that would could remove the worm automatically from a system. By Sunday night, 1.5 million people had downloaded the cleaning tool, according to Debby Fry Wilson, the director of marketing communications at Microsoft's security response unit.

In addition, a significant number of visitors to Microsoft's Sasser information page downloaded the tool, according to Wilson, who declined to be more specific about the amount.

On Wednesday, Microsoft added the Sasser clean-up program to its Windows Update service so that PC users could easily patch and clean their systems automatically. A similar move in January meant that Microsoft was able to give out the best estimate to date -- about 10 million -- of the number of systems infected by MSBlast, an earlier major worm.

With Sasser, however, the software giant is hesitant to release its numbers. "We want to be careful that we don't give too much visibility to the people that have caused this havoc," Wilson said. "From a policy perspective, it is something we need to be careful about."

Sasser, like previous worms, will probably die off only slowly. Both Code Red and Nimda continue to spread on the Internet.

"People never clean them off fast enough," said Alfred Huger, the senior director of the incident response team at Symantec. "Our worry is: what kind of damage is going to be done, post-worm? The problem for us is that these machines being compromised pose a threat."

To date, Symantec has verified that 190,000 computers have been infected by the Sasser worm and its variants. However, for the MSBlast worm, similar methods led the security firm to estimate that 500,000 computers had been infected -- an amount 20 times smaller than Microsoft's likely more accurate tally.

That difference could be due to the inability of such network analysis to see past corporate firewalls. Fully accounting for that "dark matter" of the Internet could significantly boost the Sasser infections represented by Symantec's reported numbers, putting the estimate near 4 million.

Other researchers doubt that the number could be so high. "We don't see anything that supports millions," said Jose Nazario, a researcher into Internet attacks at network protection firm Arbor Networks. "The service-level disruptions that we saw with MSBlast -- we aren't seeing (them) with Sasser."

Arbor said he believed that tens of thousands of systems are infected.

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

25 minutes ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

2 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

2 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

2 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

3 hours ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

5 hours ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

11 hours ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

13 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

13 hours ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

14 hours ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

15 hours ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

16 hours ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

16 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

16 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

17 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
ramwellian

Your comments would seem pretty naive and immature. Your 'solution' appears to be, "gee, let's all just give in to the hackers and give them...

17 hours ago by ramwellian on Cloud computing security: no more oxymoron?
BugStalker

"Interesting thought ... If you installed Win7 as a dual boot on a machine that previously only had Linux, and it wrecked your Linux installation,...

18 hours ago by BugStalker on Windows 7 Declares War on GRUB
whs001

This is an excellent summary of Ubuntu and Mint and the interface differences between them. Most such articles take a very partisan position for...

18 hours ago by whs001 on A tale of two distros: Ubuntu and Linux Mint
Moley

@ewallace. Not so clear. Anyone can obtain the text, for example from here http://www.ustr.gov/webfm_send/2379. I support ACTA so long as it and...

18 hours ago by Moley on ACTA: Facts, misconceptions and questions
45283

I think WinRT is fantastic. I just wish it was an option for people that didn't want to go through Microsoft's App Store with its attendant...

21 hours ago by 45283 on Why Windows 8 needs architectural hygiene for WOA