Dr. Dobb's is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them. Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.


Channels ▼
RSS

Security

Worm Adds MS06-040 To Four-Bug Attack Kit


A network-aware worm that's added the MS06-040 vulnerability to its bag of exploitable bugs is on the make, Symantec said Tuesday.

Dubbed "Randex.gel," the worm opens a back door on any compromised computer, then tells the system to listen for additional commands over an IRC (Internet Rely Chat) channel.

"It looks like it's a derivative of other Randex variants," said Oliver Friedrichs, director of Symantec's security response group. "But it's added the MS06-040 vulnerability."

Earlier variations of the Randex worm clan exploited other patched flaws in Windows, including three fixed by MS04-007, MS05-017, and MS05-039. The last of those, a patch that quashed a bug in Windows' Plug and Play service, was used by the Zotob worm to hammer enterprises, in particular media companies, in 2005.

Randex.gel adds the vulnerability in the Windows Server service that Microsoft patched Aug. 8 to the three-some. "It's usually just hours before [attacks] plug in new exploit code to existing worms to build something new," said Friedrichs. The exploit in Randex.gel appears to be identical, or if not, very similar to the code released two weeks ago by HD Moore of Metasploit.

The new Randex variant can spread in several different ways, Symantec's analysis reported, including via the MSN Messenger, AOL Instant Messenger, Yahoo Messenger, and ICQ instant messaging clients. It will also propagate through network shares and Microsoft SQL servers. If Randex.gel finds an SQL server, it will try to execute a job to infect any databases on the system.

In addition, the worm tries to steal account information when users of the eGold electronic payment system log onto the egold.com Web site.

But although Randex packs a punch, it's not the doomsday worm some were expecting after Microsoft patched the Server service with MS06-040.

"There are a good number of systems that have been infected [by MS06-040 exploits]," said Friedrichs. "But it's not reached epidemic proportions.

"For the most part, if you've taken an aggressive approach to patching, which has been much improved on the part of both businesses and consumers, the overall impact has been low."

Friedrichs also answered the general criticism that security companies and the media overplay potentially-harmful vulnerabilities, sometimes to the point of turning them into scares that end up all sizzle, no steak.

"What would happen if we didn't cry wolf?" he asked. "If we sat back, there's a good change that this might have played out to be more than it was," he argued.


Related Reading


More Insights






Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Dr. Dobb's encourages readers to engage in spirited, healthy debate, including taking us to task. However, Dr. Dobb's moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing or spam. Dr. Dobb's further reserves the right to disable the profile of any commenter participating in said activities.

 
Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.