» Tune of the week: Gary Maguire - Are You Real
 » Classic of the week: Blank & Jones - Beyond Time
 » Album of the month: Solarstone - Innermost
 ç¥´ personal  
 
Username:    Password:      Autologin    
   Not a registered user? Click >here< to register now. 
   It's free, you get access to all features and can win great prizes!
Search Search:       

As antivirus experts complete a more detailed analysis of the Nimda worm and companies clean up their networks on Wednesday, several security groups are worried that home computer users will not secure their PCs.

A coalition of government security officials and antivirus software industry experts released a warning to home computer users on Wednesday morning to take Nimda--and the security of their computer systems--seriously.

"It is still out there, and home users are going to be the primary mechanism for the e-mail spread of this virus," said Vincent Weafer, a senior director of Symantec's security response center, who took part in the coalition's discussions on Tuesday.


Nimda--which is "admin," the shortened form of "system administrator," spelled backwards--started spreading early Tuesday morning and quickly infected PCs and servers across the Internet. Also known as Readme.exe and W32.Nimda, the worm is the first to use four different methods to infect not only only PCs running Windows 95, Windows 98, Windows Me and Windows 2000, but servers running Windows 2000 as well.

The worm spreads by e-mailing itself as an attachment, scanning for--and then infecting--vulnerable Web servers running Microsoft's Internet Information Server software, copying itself to shared disk drives on networks, and appending Javascript code to Web pages that will download the worm to Web surfers' PCs when they view the page.

Much of the worm's virulence is due to its automated spread.

The e-mail attachment will open automatically under Microsoft's Outlook e-mail program if the program's security settings are at "low" and a security patch has not been installed. On PCs that don't use Outlook, the worm can still spread using its own e-mail engine, but it won't execute automatically.

In addition, the worm generates an avalanche of Internet traffic when it scans local chunks of the Internet for vulnerable servers to which it can spread. The automated scanning caused many connectivity problems for businesses on Tuesday.

"It seems to randomly be going through every IP (address) of my network," said Ian Neubert, director of information services for online telecommunications equipment seller TWAcomm, which found itself inundated with scans from infected machines. "This is ridiculous."

By midday Tuesday, each of TWAcomm's IP addresses had seen upwards of 9,000 scans from infected machines.

Other companies' Web servers had become infected with the worm, putting at risk any PC user viewing a Web page hosted on such a server.

In one case, the marketing site for fast-food chain Carl's Jr. had been

CNET Networks' Rose Aguilar helps us understand what makes "Nimda" tick. (1:44)

Play clip


infected with the worm. Several News.com readers noticed the compromised server when the site attempted to upload the Nimda worm to their PCs.

"That server is hosted elsewhere," said Daniel Baker, director of IT security for Carl's Jr. parent company CK Restaurants. "They are aware of the problem and will have it resolved soon." Baker added that the worm had not infected the company's own network.

Other companies weren't so lucky.

A representative of network-protection service Counterpane Internet Security said that several of its customers' servers had to be shut down to clean them of the Nimda worm. Security services firm Neohapsis also confirmed that a Fortune 500 client's network had been extensively infested with copies of the worm.

Antivirus firm Trend Micro upped the number of infections reported through its World Virus tracking Center to 26,000 from 15,000 late Tuesday.

Yet most businesses seem to be controlling the infections, said Symantec's Weafer.

"They have a handle on the initial problem of blocking the virus," Weafer said. "Now it's recovery mode, and that can take weeks and months." Almost 700 customers reported incidents of infections to Symantec on Tuesday, he said, evenly split between businesses and home users.

It's those home users that have antivirus experts worried.

Owners of home PCs generally fall behind in securing systems with new software updates and the latest virus definitions for antivirus software, Weafer said.

"Yesterday, the large part of the problem was getting good analysis of the worm," he said. "Today, it's getting home users to protect their systems."

David Dittrich, senior security engineer for the University of Washington and a computer forensics expert, agreed.

"The home users are the hardest ones to deal with," Dittrich said. "We have tried to get the word out that they need to do something, but they don't listen."

Dittrich said software makers will have to become more pro-active about contacting customers when major security threats like Nimda arise. Rather than post an advisory on a hard-to-find Web site, software companies should send e-mail to customers telling them to update their software immediately.

"Somehow, as the number of patches coming out is going up exponentially, the word has to get out to a larger number of people to apply the patches," he said. "In the end, it may be like automakers, with recalls and everything."

Related links Related Links
None
Tell a friend Tell a friend
Share this article by clicking the button below.

Bookmark and Share
comments powered by Disqus
 

Latest news
´Strangers´ by Christian Burns (Original and Krismi Remix)
   (11:53 - May 4, 2026)
Push - Future Fall
   (09:05 - May 4, 2026)
Sarah de Warren x CIRCA96 - Breathing Underwater
   (08:56 - May 4, 2026)
Mr Sam Reworks Da Fresh 'Broken Dream' For Serious Beats
   (22:13 - April 29, 2026)
Hypnotised Presents Balearic Trance
   (08:12 - April 23, 2026)
The Debut Album From Lorenzo Raganzini 'Techno Rebels'
   (23:21 - April 14, 2026)
Christian Burns & Little Foot - I Will Follow
   (07:53 - April 14, 2026)
HALIENE & Ilan Bluestone - Eclipsed By You
   (13:22 - April 13, 2026)
PUSH - BREAKPOINT
   (10:39 - April 13, 2026)
SARAH DE WARREN - GAMES
   (10:07 - April 13, 2026)
Latest reviews
Paul van Dyk & Phuture & DJ Pierre - Acid Traxxx EP [VANDIT Records]
   (22:40 - October 23, 2023)
Darren Tate - Ether [Mondo Recordings]
   (23:45 - July 26, 2022)
Paul van Dyk & Kolonie - Wishful Thinking [VANDIT Records]
   (01:22 - December 10, 2021)
Petr Vojacek - Feel Free [Alter Ego Recordings]
   (00:37 - March 4, 2020)
Paul van Dyk & Elated - Parallel Dimension [VANDIT Records]
   (21:39 - November 21, 2019)
O.B.M Notion - Marina [Interplay Records]
   (22:34 - June 10, 2019)
Paul van Dyk & Jordan Suckley - Accelerator [VANDIT Records]
   (00:59 - March 15, 2019)
David Forbes Presents. Hal Stucker - Celeste
   (19:05 - January 6, 2019)
John Askew - Midnight Oil [VII]
   (18:59 - December 5, 2018)
Paul van Dyk Featuring. Plumb - Music Rescues Me [VANDIT Records]
   (22:11 - September 12, 2018)
Latest interviews
i:Vibes Interviews Chris Metcalfe
   (19:08 - October 3, 2014)
i:Vibes Interviews Will Atkinson
   (23:35 - September 18, 2014)
i:Vibes Interviews Johan Ekman
   (21:35 - August 30, 2014)
i:Vibes Interview Photographer
   (22:56 - June 18, 2014)
i:Vibes Interviews RAM
   (14:12 - June 1, 2014)
i:Vibes Interviews Genix
   (21:45 - April 18, 2014)
i:Vibes Interviews Zaxx
   (21:01 - April 11, 2014)
i:Vibes Interviews ReOrder
   (17:10 - April 7, 2014)
i:Vibes Interviews Judge Jules
   (23:20 - September 24, 2013)
i:Vibes Interviews Sean Tyas
   (12:01 - August 16, 2013)
Latest party reports
Nature One Review
   (09:13 - August 26, 2009)
Ibiza 2007
   (23:06 - October 11, 2007)
South West Four Cardiff
   (21:37 - October 11, 2007)
Reporting from Marco V's Combi:Nations II Tour
   (16:33 - November 21, 2006)
Party Report: Marcel Woods presents Musical Madness
   (20:58 - November 8, 2006)
Latest tutorials
Extensive Tutorial On Copyright Laws
   (13:21 - December 2, 2003)
How do I set up my own label?
   (15:20 - July 10, 2003)
Music Production Tutorial In Reason [01 - FAQ]
   (13:22 - March 4, 2003)
Tutorial, Scratching Techniques
   (20:16 - April 23, 2002)
Learning To DJ [05] - Scratching
   (17:49 - September 27, 2001)
Latest what is...
An Album That Reminds You of Christmas Time
   (00:42 - December 19, 2023)
Tune, Classic & Album of the week Updated July 12
   (00:34 - June 24, 2004)
The Meaning of Music
   (16:00 - September 28, 2003)
Your predictions for best remixer in 2003, via our poll
   (13:22 - February 11, 2003)
The [i:Vibes] Visitors predictions for best DJ in 2003 ?
   (16:09 - January 21, 2003)