Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


August 17, 2005

Microsoft: Worm Attack is Your Fault

RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints
Or get the Monthly Online Pass—only $5.95 a month!

Rival hackers have unleashed competing computer worms on the Internet which are designed to exploit recently revealed flaws in various versions of Microsoft's Windows operating systems. The worms are most notable for their arrival speed: They are quickly spreading around the globe less than a week after Microsoft announced the flaws they exploit. Microsoft, however, remains surprisingly unimpressed by the fact that its customers are being forced to take their PC systems offline.

"We are not aware at this time of a new attack," the company noted in a statement it issued last night. "Instead our analysis has revealed that the reported worms are different variations of the existing attack called Zotob. Microsoft has reviewed the situation and continues to rate the issue as a low threat for customers."

This statement bears little comfort for companies such as ABC, Caterpillar Company, CNN, Daimler Chrysler, The Financial Times, Kraft Foods, The New York Times, The San Francisco International Airport, SBC Communications, United Parcel Service (UPS), and Walt Disney, all of which suffered from computer crashes, downtime, and repeated reboots because of the worm attacks. According to reports, there are at least six separate worms that exploit Microsoft's recently-revealed flaws. David Maynor, a security researcher at Internet Security Systems in Atlanta told The New York Times that the hackers responsible were essentially involved in a "turf war" to control computers in the largest networks around the world.

Despite Microsoft's "low threat" assertions, security firms are rating this attack being more severe. Trend Micro is using the "medium" designation to describe the attack, while Symantec grades the Zotob attacks as a 3 on a 1 to 5 scale.

But back to Microsoft, which you'd think would be reaching out to customers and not explaining how they'd be fine if they simply upgraded to XP or installed patches the day they were released. "Zotob has thus far had a low rate of infection," the aforementioned statement continues. "Zotob only targets Windows 2000. Customers running other versions such as Windows XP, or customers who have applied the MS05-039 update to Windows 2000 are not impacted by this attack."

Only Windows 2000, eh? According to AssetMatrix, Windows 2000 is the most-often used Windows version in medium- and large-sized corporations, edging out XP 48 percent to 37 percent. Put another way, roughly half of all Windows installs in corporations are Windows 2000.

So we have an interesting situation. Hackers are now able to exploit Windows flaws within days, and when they do so, corporations are admonished by Microsoft. No offense to the world's largest software company, but that's no way to talk to customers.

End of Article



Reader Comments
*yay*

Anonymous User August 17, 2005 (Article Rating: )


Hey, like many posters here at WinInformant, they're simply assigning blame to the user rather than their swiss-cheese-security software. It's easier to do that than accept responsibility and put the blame squarely where it belongs.

Anonymous User August 17, 2005 (Article Rating: )


Paul, I agree with your assessment, but I also have to ask who is asleep at the wheel at thos corporations? You would think, no matter which platform they have deployed across their servers and clients, that they would have both a defined patch management solution better than just running Windows Update (such as SUS, WSUS, SMS, or any other litany of patch management packages available), and that they would also have AV software on each desktop, that is both a modern version, and kept up to date on a daily basis. This would greatly mitigate this worm from spreading very far if those simple precautions are taken. I think that infection would be more prevalant in small to midsize businesses that don't have the money or expertise for a full fledged patch management and virus solution, not at big companies with huge bankrolls.

Anonymous User August 17, 2005 (Article Rating: )


My main question... So does it or does it not effect Windows XP. I just bought a new computer about a month ago. Do I need to worry?

Anonymous User August 17, 2005 (Article Rating: )


I'll have to agree that more blame needs to be put on the systems administrators. About 50% of our network is Windows 2000. Not one machine has had a problem. Why? Because we use antivirus software. Because we use patch management software. Because we use firewalls.

The point is that the tools are there to be used. Some free of charge. You don't blame Ford when you get something stolen out of your car when you forgot to lock the doors.

MorfiusX August 17, 2005 (Article Rating: )


"You don't blame Ford when you get something stolen out of your car when you forgot to lock the doors."

Well, I would definitely blame Ford if they sold me a car without locks and something was stolen, which is the case here w/Windows and Zotob and even Blaster.

Anonymous User August 17, 2005 (Article Rating: )


I'd blame Ford if they sold me a car that LOOKED like it had locks, but actually didn't or locks that could be slim-jimmed with a pencil. I'd also be annoyed if Ford expected me to drop by their service department daily to make sure there wasn't a service patch for my car. And I'd kick Ford's great grand kid square in the nads if he blamed me for not taking the time to drop by his service department to update the POS car he sold me! Maybe we should all consider Linux or Mac instad of Ford - er, Microsoft.

mwrisner August 17, 2005 (Article Rating: )


If Apple had 90% of the computer market share, would they not also be under the same attacks? Isn't the real issue about building a secure operating system.

Anonymous User August 17, 2005 (Article Rating: )


I work for a fortune 50 company. I am currently monitoring our networks and our tickets, and so far we have zero reports of this virus on our network.

Why? Because our testing and review process of Microsoft patches is quick. We utilize complete firewall protection. We use up-to-date virus protection.

Blaming Microsoft is Lame, anyone in their position would have to deal with this. I think there a bunch of security professionals who need fired from each of these companies.

This report is lame. Try supporting a company before you pass judgement. This was totally avoidable.


Anonymous User August 17, 2005 (Article Rating: )


"If Apple had 90% of the computer market share, would they not also be under the same attacks?"

No, that is just plain typical Micro$oft fanatical FUD. If a hacker was able to create a worm/virus that could successfully attack Mac OS X, he'd go down in history for the achievement. It hasn't happened. This is what hackers pursue notoriety.

"Isn't the real issue about building a secure operating system."

Are you not listening?! Apple OS X is far more secure then your precious Windoze.

All ports blocked by default, Zero viruses available for Mac OS X, Zero worms, Zero trojans and Zero ad/spy-ware programs for OS X.

I don't need or even use Antivirus software or a firewall with my copy of Mac OS X, it's that secure!!!

Anonymous User August 17, 2005 (Article Rating: )


 See More Comments  1   2   3   4   5   6   7   8   9   10   11   12 

You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
Windows Chief Leaving Microsoft

Kevin Johnson, the man most directly responsible for current and future versions of Windows, as well as Windows Live and Microsoft's online services, is leaving the company for a position at Juniper Networks. Johnson has been co-president or president ...

How can I limit Exchange mailbox size?

...

The Memory-Optimization Hoax

Don't believe the hype. At best, RAM optimizers have no effect. At worst, they seriously degrade performance. ...


Security Whitepapers Anti-Virus Is Dead: The Advent of the Graylist Approach to Computer Protection

Getting the Job Done: Comparing Approaches for Desktop Software Lockdown

Instant Messaging, VoIP, P2P, and games in the workplace: How to take back control

Related Events Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.


ADS BY GOOGLE SPONSORED LINKS FEATURED LINKS

Shortcut Guide to SQL Server Infrastructure Optimization
With right tools and techniques, you can have a top-performing SQL Server infrastructure without having to cram your data centers so that they're overflowing. Download this eBook to learn how.

WinConnections Conference Fall 2008
Don’t miss the premier event for Microsoft IT Professionals in Las Vegas, November 10-13. Register and book your room by August 25 and receive a FREE room night (based on a three night minimum stay).

Become a fan of Windows IT Pro on Facebook!
Join us on Facebook and be a fan of Windows IT Pro!

Continuous Data Protection and Recovery for Exchange
Read this white paper to learn about Continuous Data Protection (CDP), Exchange 2007's local continuous replication and cluster continuous replication features.

Rev Up Your IT Know-How with Our Recharged Magazine!
The improved Windows IT Pro provides trusted IT content with an enhanced new look and functionality! Get comprehensive coverage of industry topics, expert advice, and real-world solutions—PLUS access to over 10,000 articles online. Order today!

Tips to Managing Messaging
Discover three fundamental mail and messaging management services - security, availability and control services - and how you can implement them in a Microsoft-centric mail and messaging environment.

Get It All with Windows IT Pro VIP
Stock your IT toolbox with every solution ever printed in Windows IT Pro and SQL Server Magazine plus bonus Web-exclusive content on hot topics. Subscribe to receive the VIP CD and a subscription to your choice of Windows IT Pro or SQL Server Magazine!



Solving PST Management Problems
In this white paper, read about the top PST issues and how to administer local/network PST files.

Bandwidth Monitoring Tool from SolarWinds
Identify largest bandwidth users in seconds. Get the free download now.

Transform Your Data Center at Brocade Conference 2008
Storage networking industry’s premier event at the MGM Grand, Las Vegas, September 22 - 24, 2008

Are You Litigation Ready?
Collecting and processing electronic data for e-discovery can be time-consuming and expose a business to significant legal risks. Get prepared with this free white paper

Order Your Fundamentals CD Today!
Gain an introduction to Exchange, learn server security requirements, and understand how unified communications can play a role in your messaging strategies with this free Exchange CD.

KVM over IP Solutions
Learn about a KVM over IP solution that is specifically designed to meet the needs of the distributed IT environment.
Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound
IT Library Technical Resources Directory Connected Home Windows Excavator SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing