Mass worm attack could be imminent
By Joris Evers, Special to ZDNet
24 June 2005 Add your opinion
Forward in Format for
A surge in scanning on a port associated with a Windows flaw patched last week suggests that a mass worm attack may be imminent, experts have said.
A rise in activity on TCP Port 445 could be a sign that hackers are trying to exploit a flaw in the Server Message Block (SMB) protocol, Gartner analyst John Pescatore said Thursday in the US.
"Increased scanning does not always mean an attack will happen, but it greatly increases the odds that one will," Pescatore said. "I don't think this has a high probability of a worm, but if people get lax about patching the odds of worms goes way, way up."
Like would-be burglars knocking on doors looking for a likely target, Internet intruders sometimes scan random computers to see if a particular network port is available, as a precursor to attack.
TCP Port 445 is used by SMB, which Windows uses to share files, printers, serial ports and also to communicate between computers. Microsoft recently released a fix for the "critical" vulnerability in the protocol as part of its monthly patch cycle.
Increased port scanning has preceded major worm outbreaks in the past, Pescatore said. Alfred Huger, a senior director at Symantec Security Response, also said that a worm could be on its way.
Users should patch their systems as soon as possible, they both said.
However, Pescatore and Huger also noted that port scanning by suspected hackers is common after Microsoft discloses vulnerabilities. Furthermore, this particular Windows flaw is not easy to exploit, so the scanning may not be an ominous sign at all.
Symantec saw a spike in scanning on TCP Port 445 last week, but the probing of the port has since gone back to normal levels, Huger said. "I don't think we should be screaming the barn is burning by any means," he said.
Microsoft is not aware of any active attempts to exploit any Microsoft vulnerabilities via TCP Port 445, a company representative said Thursday in the US. Also, the software maker has not received any indication of malicious activity
COPY RIGHTS : TO AVOID COPYRIGHT VIOLATIONS, ALL POSTS ARE SHOWN ALONG WITH SOURCES FROM WHERE ITS TAKEN. PLEASE CONTACT ME IN MY EMAIL SALEEMASRAF@GMAIL.COM , IF YOU ARE THE AUTHOR AND YOUR NAME IS NOT DISPLAYED IN THE ARTICLE.THE UNINTENTIONAL LAPSE ON MY PART WILL BE IMMEDIATELY CORRECTED.
I HAVE SHARED ALL MY PRACTICAL WATER TREATMENT EXPERIENCES WITH SOLVED EXAMPLE HERE SO THAT ANYBODY CAN USE IT.
SEARCH THIS BLOG BELOW FOR ENVO ,COMPACT STP,ETP,STP,FMR,MBBR,SAFF,IRON,ARSENIC,FLUORIDE,FILTER,RO,UASB,BIO GAS,AERATION TANK,SETTLING TANK,DOSING,AMC.
SEARCH THIS BLOG
Sunday, June 26, 2005
Mass worm attack could be imminent
Environmental Entrepreneur,Green Biz.NRN Murthy of Infosys says that we Indians are weak in execution.We need to realize the need and practice of gud project management. Form a group of competent Managers,Give them responsibilities and review the project from day One.
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment