Not-so-witty Worm Destroys System Data Through BlackIce Firewalls

Virus and Security News - 22 March 2004

A fast-spreading worm got loose on the Internet Saturday, crawled through a vulnerability in Internet Security Systems' BlackIce firewall, has infected between 10,000 and 50,000 systems worldwide, and can trash infected hard drives.

The worm--dubbed "Witty," for a comment embedded in its code--exploits a stack overflow vulnerability within BlackIce that was disclosed just two days before the worm first appeared.

Unlike most other worms, Witty doesn't need human interaction to spread. Rather than rely on users to open a file attachment--the typical way worms propagate--Witty simply scans for vulnerable systems, then uses UDP port 4000 to infect the machine. This auto-spread strategy was last used to wreak havoc by 2003's Blaster worm.

Witty is particularly dangerous, said experts, because after it executes, it opens a random drive on the PC and writes 65 Kbytes of data to a random location on the disk. It repeats that process until the system is rebooted or the computer crashes.

"This worm is highly malicious, slowly destroying the systems it infects," security firm Lurhq said in an alert posted on its Web site. "Rather than simply executing a 'format C:' or similar destructive command, the worm slowly corrupts the file system while it continues to spread. Any infected machine will likely have its operating system and partition data destroyed along with most files on the physical drives, depending on how long the worm runs on the machine."

Internet Security Systems said its analysis indicated that only about 2% of its customers could be open to Witty's attack, but other analysts have tagged the number of infected machines at significant levels.

"It's unlikely that many computers will be patched against this vulnerability at this time," said Ken Dunham, director of malicious code research at iDefense, in an E-mailed statement. "Early data suggests about 10,000 infected computers worldwide." Others have put forward the number at 50,000.

Experts such as Dunham urged ISS customers to disable the firewall until it has been patched, and, where feasible, block traffic on UDP port 4000. ISS recommended that infected systems be disconnected from the network to stop the worm's spread.

Updates to BlackIce that plug the vulnerability may be downloaded from ISS's Web Site.

 Printable Version

News
Virus and Security News
Atlantech recommends CounterSpy
eWeek says ""CounterSpy is the most affordable and richly featured product we reviewed... Sunbelt's CounterSpy Enterprise provides the best mix of management, reporting and cleaning capabilities we've seen, at the most affordable price. With its CounterSpy Enterprise solution, Sunbelt exhibits its experience in designing enterprise-class software. CounterSpy Enterprise has the best reporting tools we've seen by far, offering a wide array of high-level and heavily detailed reports that can be organized by date ranges."
Consulting >>
Introduction to Security
An information system with a weak security foundation will eventually experience a security breach. Examples of security breaches include data loss, data disclosure, loss of system availability, corruption of data, and so forth. Depending on the information system and the severity of the breach, the results could vary from embarrassment, to loss of revenue, to loss of life.
Consulting >>
More Internet Bank Account Fraud!
Fraudsters have developed phishing emails capable of automatically stealing bank log-in details
Consulting >>
IE cross-zone privilege escalation vulnerability
Active exploitation of a cross-zone privilege escalation vulnerability in Internet Explorer has been observed.
Consulting >>
Not-so-witty Worm Destroys System Data Through BlackIce Firewalls
A fast-spreading worm got loose on the Internet Saturday, crawled through a vulnerability in Internet Security Systems' BlackIce firewall, has infected between 10,000 and 50,000 systems worldwide, and can trash infected hard drives.
Support and Maintenance >>
2004 worms (well 4 anyway!)
Virus generates massive support traffic to helpdesks - confusion abounds....
Support and Maintenance >>
Apple Mac OS X vulnerability
Apple MacOS X DHCP Response Root Compromise
Consulting >>
Breaking into Microsoft - "Tougher than you think!"
Microsoft repels 2500 to 3000 electronic attacks every day--or almost 100,000 a month.
Consulting >>
Worm Alert
Don't be caught by the new "Credit Card Worm Scam"!
Support and Maintenance >>