Share

Related Stories

  • Zero Day of the Dead
    The data load that has accompanied the globalization of trade would make even Atlas stagger. And that’s without the added burden of counter-terrorisAs you read this, zombie programs are flitting across the internet like a pestilence to infect and drain the life from innocent computer systems. Yet, for all the aggravation and grief they cause, you may never know you are part of a global invasion of the system snatchers, says William Knight. Unless…
  • Searching for Security
    With more than 30 000 web pages being compromised every day, search engine results could increasingly lead to malware infection. Kari Larsen asks what the search engines are doing to mitigate security threats, and how users can protect themselves
  • Search for security
    With more than 30 000 web pages being infected every day, search engine results could increasingly lead to malware infection. Kari Larsen asks what the search engines are doing to mitigate security threats, and how users can protect themselves.
  • Reverse engineering specialist dissects the Morto worm
    Tomer Bitton, a reverse engineering specialist with Imperva, has successfully dissected the operation of the Morto worm, a malware executable that is notable for being the only worm seen to date that exploits Microsoft's remote desktop protocol (RDP).
  • Windows autorun trojan tops November malware chart
    The latest monthly malware chart from BitDefender claims to show that the largest risk to computer users is currently Trojan.AutorunINF.Gen, a generic family of trojan malware abusing the autorun feature in Windows.

Top 5 Stories

News

Downadup Worm Continues to Spread

12 January 2009

More evidence has appeared of the spread of a network work based on the RPC vulnerability that was found in Microsoft Windows in October. The network worm Downadup has failed to gain much traction on the open internet, according to anti-virus firm F-Secure, but is getting into corporate networks on a consistent basis.

According to researchers at the SANS Institute, the worm may have been responsible for an
infection at the Vancouver School Board. Network accounts at the organisation were blocked in a way that is synonymous with the worm's method of using dictionary attacks to crack Active Directory passwords.

"The malware uses server-side polymorphism and ACL modification to make network disinfection particularly difficult," said F-Secure in an update for its customers. "A sign of infection is that user accounts become locked out of an Active Directory domain as the worm attempts to crack account passwords using a built-in dictionary. When it fails, it leads to those accounts being locked."

Downadup, which can also be distributed on removable media, makes an HTTP server on an infected machine and then uses the RPC exploit to force other machines to download its code within local networks. It is used to install malware downloaders that can then call out to other servers for subsequent installations.

Microsoft gave the Downadup worm an exploitability index rating of one (meaning that consistent exploit code was likely). The exploitability index was created in August as a means of helping customers ascertain the real-world risk to their networks from specific exploits.

The operating system vendor patched the RPC problem that allowed this exploit in October. Clearly, many customers have failed to apply the patch, thus allowing themselves to be infected by the worm (which doesn't require user interaction to propagate). F-Secure provides specific instructions on how to disinfect machines on a local network here.

This article is featured in:
Internet and Network Security • Malware and Hardware Security

 

Comment on this article

You must be registered and logged in to leave a comment about this article.