|
|
|
|
 |
|
|
| Moderated by: Saida.M, safetyblitz, Raven, Miss Brighter Days, LadyDay, Kunjufu, Kibibi, Happiness, Dillinger, Breadfruit, Backatya |
|
|
| Author | |
|---|
LadyDay Super Moderator

| Joined: | Thursday October 2nd, 2003 |
| Location: | United Kingdom |
| Posts: | 6156 |
| Photo: | [Download] |
| Status: |
Offline
|
| Mana: |     |
Click here for your Black Profile
Search for Black Sites
|
Posted: Thursday August 18th, 2005 16:44 |
|
http://news.bbc.co.uk/1/hi/technology/4162124.stm
Windows 2000 bug starts virus war
A war has broken out between hackers behind viruses that exploit a recently discovered loophole in Windows 2000.
The viruses written by the competing hacker groups are fighting it out for supremacy on infected machines.
Some of the variants seek out and delete rival viruses they find on machines they manage to penetrate.
The slew of malicious programs exploiting the loophole caused trouble for many organisations early this week as the bugs began infecting computers.
War zone
A patch for the vulnerability being exploited by the 11 viruses turned out by the rival groups was released on 9 August and code to exploit it appeared only a few days later. The weakness occurs in the Plug-and-Play component of Windows 2000.
The loophole does not affect PCs running Windows XP, or those who have installed a security update to Windows 2000.
Separate virus writing groups have used the exploit code to create malicious programs. Earlier this week organisations including the Financial Times, heavy plant maker Caterpillar, ABC News and CNN reported that they had been hit by the viruses.
PLUG-AND-PLAY BUGS
Zotob.A, B, C
IRCbot.ES, ET, EX
Bozori.A, B
Rbot.YN
SDbot.ADB
Codbot
Although Windows 2000 is the most prevalent version of the operating system used in large organisations, Microsoft said the number of firms infected was relatively low.
The software giant has released a free tool to automatically remove the Zotob worm and its variants from infected PCs.
Now newer versions of the viruses have been created that try to destroy bugs from rival groups, reported security firms Clearswift and F-Secure.
"We seem to have a botwar on our hands," said Mikko Hypponen, chief research officer at F-Secure.
"There appears to be three different virus-writing gangs turning out new worms at an alarming rate," said Mr Hypponen, "as if they were competing to build the biggest network of infected machines."
Variants of the Bozori and IRCbot viruses that exploit the Windows 2000 loophole will delete some of the Zotob, RDbot and SDbot virus programs if they find them on machines they manage to compromise.
Microsoft urged users to turn on auto-updates and make sure anti-virus and other security programs were up to date.
"Our analysis has revealed that the reported worms are variants of the existing worm called Zotob," said the company in a statement.
"Microsoft is working closely with law enforcement to help identify and bring to justice those responsible for this malicious activity."
Last edited on Thursday August 18th, 2005 16:46 by LadyDay
____________________ I am too blessed to be stressed and too anointed to be disappointed!
Think outside of the box...Think in spirit
Act as if it were impossible to fail!!!
____________________
Click here for your Black Profile
|
|
|
 Current time is 16:04 | |
|
|
 |
|
|
|
|

Join the
Blacknet
mailing list
|
|