Help - Search - Members - Calendar
Full Version: Computer Worm affectingWin2000 and WinXP
Invision Power Services > Community Forums > Community General Chat
.Pretender
http://www.cnn.com/2005/TECH/internet/08/16/computer.worm/index.html

QUOTE
Worm strikes down Windows 2000 systems

Microsoft in 'emergency response' as worm reported on three continents


Wednesday, August 17, 2005; Posted: 4:26 a.m. EDT (08:26 GMT)
WASHINGTON (CNN) -- A fast-moving computer worm Tuesday attacked[b] computer systems using Microsoft operating systems, shutting down computers in the United States, Germany and Asia.[/b]
Among those hit were offices on Capitol Hill, which is in the midst of August recess, and media organizations, including CNN, ABC and The New York Times. The Caterpillar Co. in Peoria, Illinois, reportedly also had problems.
A small number of computers in an administrative office at San Francisco International Airport also crashed, but they were not essential to the airport's operation, spokesman Mike McCarron said.
The FBI said the computer problems did not appear to be part of any widespread attack.
While the worm affects primarily Windows 2000, it also can affect some early versions of Microsoft XP, said Johannes Ullrich, chief technology officer of the Sans Institute, a network security firm based in Jacksonville, Florida.
Symptoms include the repeated shutdown and rebooting of a computer.
Microsoft has a downloadable patch on its security homepage, Microsoft.com/security.
The director of Microsoft's security response center, Debbie Fry Wilson, said the computer giant was in an "emergency response" mode. "Right now, we're mobilizing our two war rooms," she told CNN.
"The key thing I want to stress for customers is making sure that they install security updates as quickly as possible," Wilson said.
Although she said that the number of affected computers is unclear, most Windows 2000 customers are business users. And automatic security updates would have protected most home users, she said. Wilson added that "at least 200 million computer users worldwide" have downloaded the patch.
Business software provider AssetMetrix reported in June that Computers running Windows 2000 were on about half of all corporate desks.
Microsoft is working with law enforcement to track down those who unleashed the worm, Wilson said.
Lysa Myers, a virus researcher for the computer security firm McAfee, Inc., said the worm exploits a vulnerability in Microsoft's plug-and-play service. "How it's spreading is it's looking for machines that are unpatched and running itself," she said.
What was causing the damage was unclear, although experts pointed to a new worm called worm-rbot.cbq.
David Perry of Trend Micro, an Internet monitoring firm, said the latest worm may have been derived from the Zotob worm, which was first reported over the weekend.
Ullrich, of the Sans Institute, said Zotob "will connect to a control server to ask for instructions. It scans network neighborhoods and tries to infect them, as well."
Typically, the worm enters a system via a laptop connected to unsecured networks, Ullrich said. "This laptop will infect your systems from the inside."
Several versions of the worm have been released, some as late as Tuesday, he said.
Around 5 p.m. problems began at CNN facilities in New York and Atlanta before being cleared up about 90 minutes later.
The New York Times also was able to bring its systems back up, and "newspaper production will not be affected," spokeswoman Kathy Park said.
The White House said it did not have reports of computer problems.
Improved firewalls and faster patches may have limited the worm's spread, said Jeff Havrila, a technical analyst with the U.S. Computer Emergency Readiness Team, a coalition of public and private groups that combats computer attacks.
He also said it is unclear how long the worm may take to run its course, noting that many people are away on summer vacation and may be affected only when they return.
At any given time there are thousands of computer worms and viruses in existence. Last year, the Sasser worm shut down millions of computers worldwide. A German teenager has been sentenced to 21 months' probation (Full story).
.Wolfie
Hmmm.. Hey ZaK, how about if you test out the worm and report back to us what it does, from your personal observations.

:-"
DjZvEr
I thought it was just win 2000.
kafloo
oh boy


--------------------
filipino community
Wombat
QUOTE(DjZvEr @ Aug 17 2005, 11:56 PM) *
I thought it was just win 2000.


It exploits a hole in Windows 2000 and Windows XP's implementation of Plug & Play, only Windows 2000 however experiences problems (constantly restarting). XP is simply a "carrier" if you will.

(On a potentially unrelated note, half the sites I usually visit have suddenly gone unavailable... anyone else having problems?)
Brandon C
Zotob worm http://www.microsoft.com/security/incident/zotob.mspx
.Wolfie
It affects early unpatched versions of XP.
Dima
CNN also said that it affects Windows 96, 97, and 99!
.Wolfie
I thought it was a different one recently discovered that affects 95 to XP (95, 98, ME, NT, 2k, XP)

Maybe I misheard it though.
DjZvEr
QUOTE(Dima @ Aug 17 2005, 08:03 PM) *
CNN also said that it affects Windows 96, 97, and 99!

96,97,99. I have never heard of those. And I thouth I knew computers.
.Wolfie
QUOTE(Dima @ Aug 17 2005, 11:03 PM) *
CNN also said that it affects Windows 96, 97, and 99!
QUOTE(DjZvEr @ Aug 17 2005, 11:08 PM) *
96,97,99. I have never heard of those. And I thouth I knew computers.

OMG DUDE...

I like so missed that. laughing.gif
Dima
QUOTE(DjZvEr @ Aug 17 2005, 11:08 PM) *
96,97,99. I have never heard of those. And I thouth I knew computers.


That's because they don't exist. CNN made a boo boo.
DjZvEr
QUOTE(Dima @ Aug 17 2005, 08:14 PM) *
That's because they don't exist. CNN made a boo boo.

Sarcasim. people.
Davy
The bank where I work got it, well some people did...
Brendon Koz
Did they get sick and say they had to go home early and take sick pay?

...on a more serious note, the UnPnP program from grc.com works wonders, and he released that right after XP was on the shelf for mainstream purchase.
eek-1
QUOTE(Dima @ Aug 18 2005, 11:03 AM) *
CNN also said that it affects Windows 96, 97, and 99!

..and also "Microsoft" 2000, or so I heard.
=?
THR
And all those stupid news networks got affected.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2008 Invision Power Services, Inc.