Zotob Worm Slams News Networks

By Nate Mook | Published August 17, 2005, 11:44 AM

Despite overall global infection rates remain low compared to viruses such as Sober, Windows 2000 systems at several news networks were hit hard by the Zotob worm on Tuesday, prompting CNN to break into regular programming to announce its computers were under attack and constantly rebooting.

Machines at the New York Times, ABC and a number of other organizations were also infected by Zotob, which copies itself into the Windows System folder and modifies a user's "hosts" file to prevent access to antivirus Web sites. The worm initiates an FTP server on port 3333 and scans IP addresses using port 445 for other vulnerable systems.

The critical vulnerability in Windows 2000 that opens the door for Zotob was actually patched by Microsoft last week, but system administrators claim they did not have enough time to roll out the update.

Microsoft on Friday chided security researchers for breaching "the commonly accepted industry practice of withholding vulnerability data so close to update release and have published exploit code."

Although Zotob itself does not have a destructive payload, variants of the worm are reported to cause computer shutdowns. The worms also include backdoor capabilities, which connect the infected computer to an Internet Relay Chat channel to await remote instructions from a malicious user.

"Around 5 p.m. problems began at CNN facilities in New York and Atlanta before being cleared up about 90 minutes later," the news organization said. Although most corporate networks are protected from outsiders, it is believed internal users were to blame for the problems by connecting already infected laptops.

Microsoft responded by downplaying the severity of the worm, calling it a "low threat for customers."

"News reports had indicated that there was potentially a new worm. We are not aware at this time of a new attack; instead our analysis has revealed that the reported worms are different variations of the existing attack called Zotob," Microsoft said in a statement.

"Zotob has thus far had a low rate of infection. Zotob only targets Windows 2000. Customers running other versions such as Windows XP, or customers who have applied the MS05-039 update to Windows 2000 are not impacted by this attack."

Comments

Windows 2000 is an excellent operating system, but poor users and administrators at these Media Companies obviously have no clue what they are doing.

When those security updates were released they were downloaded and installed to about 40 or so windows 2000 servers around our office. Only using terminal services to administrate that, which i consider to be the slowest approach.

How can multi-million dollar corporations with expensive tech support and on-site admin's miss those updates??

Score: 0

|

Microsoft responded by downplaying the severity of the worm, calling it a "low threat for customers."

WTF is this BS... Microsoft says that about every bug, glitch, & security hole people find... (Anyone remember how easy it was to steal files back in windows 95A?) Im so sick of being the guy handing out bills because I had to go fix a computer network for a business where they just don't know what to do themselves. Honnestly microsoft should be the bas****s paying the repair bills for a lot of companies.

www.borderrock.com
106.1 The Goat

Score: 0

|

That's probably a Microsoft "time to upgrade" notice.

Score: 0

|

"Machines at the New York Times, ABC and a number of other organizations were also infected by Zotob"

Man... that sounds like a virus I would write =p

Power to Zotob!!!

Score: 0

|

good thing where i work, we use Linux. wake up!!

Score: 0

|

And don't you forget that where you work, you use Linux, and have people that know what they're doing managing your systems.

Score: 0

|

anyone smart enough to run Linux, could make a worm eat itself.

Score: 0

|

CNN, ABC, The New York Times? ..and we're supposed to trust these people with the news.

Score: 0

|

That'll teach 'em. So there!

Score: 0

|

Are they trying to get win2k users to take a hint?

Score: 0

|

Before it can tackle Windows, Chrome must leave Safari in the dust

It's a little browser with dreams of becoming a bigger operating system some day. But while it's chasing Microsoft's dreams, Chrome's tail is being chased by Apple.

Silverlight 3 goes live on Microsoft's servers

Microsoft's answer to Adobe's Flash is (unofficially) here, with prospects of higher-speed, higher-resolution video and for the first time, 3D.

Best Buy-brand TVs to get TiVo

A new alliance will place the retailer's own brand alongide the manufacturers, and could also lead to future partnerships on services.

Three Android phones on the way from T-Mobile in 2009

T-Mobile's myTouch 3G, launched Wednesday, will be followed by two more Android phones later this year, but neither of them will be HTC's Hero.

LTE still lacks a voice

The 4G Wireless standard that Verizon hopes to show off before this year is out is still at a loss for (spoken) words.

T-Mobile's strategy to combat Apple's iPhone with Android

With a trio of Android phones now in the pipeline for 2009, T-Mobile hopes to break the iPhone's emerging stranglehold.

EC's Reding: Government should act as broker for media downloads

If Internet media services don't step up and build an attractive way for users to start paying for downloads, a commissioner says, government may do the job instead.

Sony TVs get Netflix, still no PS3

Though it's coming in behind LG, Samsung, and Microsoft, Sony will begin to offer Netflix streaming, too.

Google Chrome OS: Too little, too early

Carmi Levy: Wide Angle Zoom Don't start the revolution just yet, says Carmi, who isn't so certain Chrome OS will be the "Windows Killer."

GAO pen test brings the hammer down on federal rent-a-cops

But are the computers to blame for the contract-guard fiasco at FPS?

What's Next: Chrome OS will have at least some friends in high places

Also: South Korea takes another round of DDoS abuse, and Neelie Kroes and Steve Ballmer may shake hands before she exits stage left.

Data sharing among online advertisers: Is sanity in sight?

Lockdown with Angela Gunn In the middle of a 15-page plea not to get regulated, a spark of smart thinking.

PST Recovery Software 12.0

July 9 - 11:34 PM ET

Unistal Data Recovery 12.08.06

July 9 - 11:09 PM ET

BKF Repair 3.0

July 9 - 10:54 PM ET

Vuze for Windows 4.2.0.4

July 9 - 6:26 PM ET

UltraVNC 1.0.6.4

July 9 - 6:05 PM ET

WildBit Viewer 5.5 Beta 3.0

July 9 - 5:44 PM ET