Profile

unixronin: Galen the technomage, from Babylon 5: Crusade (Default)
Unixronin

December 2012

S M T W T F S
      1
2345678
9101112131415
16171819202122
23242526272829
3031     

Most Popular Tags

Expand Cut Tags

No cut tags
Monday, April 12th, 2004 11:19 pm

[livejournal.com profile] cymrullewes found this article about the Witty worm, which turns out to be a quite vicious and well-crafted little bugger.  (See CAIDA's nice detailed analysis.)  Exploiting a specific vulnerability in the ICQ Protocol Analysis Module in BlackIce Defender and RealSecure (both ISS products), Witty hit the net within 24 hours of disclosure of that vulnerability, targeted solely systems protected by those two firewalls, and reached saturation within 45 minutes leaving a trail of effectively destroyed machines behind it.

The dangerous part about Witty is perhaps less its fast turnaround time or its clever construction, but the paradigm shift that it demonstrates in worms.  Up until now, the prevailing wisdom was that a successful worm did not destroy its host, because as long as the host remained up, the worm could continue to infect new systems.  Witty, on the other hand, says that it's OK to go ahead and destroy your host, provided you reproduce first -- which Witty does, sending out 20,000 copies of itself before it begins trashing its host's hard disk.  All the major AV vendors got patches out against the worm -- but it was too little, too late.  By the time the updates could be distributed, Witty had already hit saturation.  This points up a study by HP Bristol that shows that the whole strategy of defending against a fast-spreading worm via signature distribution is fundamentally flawed, because the worm can spread faster than updates can be distributed.

The informal rules just changed, and the game just got a lot nastier.

Monday, April 12th, 2004 10:01 pm (UTC)
Why do these turkeys insist on violating the Tenth Commandment? All the world is NOT a Windows Box. A cheap K6 box with a few NICs and a Linux router distro running from CD and Mister Witty would've been DOA. Tango Uniform. I gave the lady a polite earful. (And pointed out that it isn't just Linux that can do this: Apple, Linksys, Netgear, anything like that.)

*sigh*
Monday, April 12th, 2004 11:01 pm (UTC)
I gave the lady a polite earful.

"the lady"?
Tuesday, April 13th, 2004 10:58 pm (UTC)
The lady as what wrote the article in the Register. From her reply, I still don't think she groks the idea of running an OS from uncorruptible media.... and she calls herself a security professional. *sigh*