Skip to navigation
Latest News

Blaster worm set to attack Microsoft's update service

By Alun Williams

Posted on 15 Aug 2003 at 16:49

The world is watching this weekend to gauge the full effect of the Blaster worm. Already widespread, the worm is timed to attack Microsoft's Windows update service after midnight tonight.

The Blaster worm first appeared Tuesday 12 August 2003 - New worm infects with an eye on Windows Update site. Also known as Lovsan, MSBlaster or Poza, it exploits Microsoft's well-known DCOM RPC vulnerability. This is a flaw in Windows (from NT to XP) that occurs through an error in the way malformed messages received over the Remote Procedure Call (RPC) protocol.

As part of its malicious behaviour, the worm is setting up a distributed denial-of-service attack on Windows Update, which will take place after 15 August. Note however that the worm targets the URL www.windowsupdate.com, which seems to have already been taken down by Microsoft. The alternative URL of windowsupdate.microsoft.com is healthy and up and running.

Graham Cluley, senior technology consultant for Sophos Anti-Virus, said on the arrival of Blaster: 'By attempting a denial of service attack on the windowsupdate.com website, the virus author is deliberately trying to make it difficult for computer users to download the patch they need to secure their copies of Windows against the worm. It's an extremely devious trick by Blaster's author.'

He added: 'System administrators should note that Blaster doesn't spread by email - so Internet email scanning services will not be able to detect this worm, and an absence of reports at your email gateway does not mean you can rest on your laurels.'

The Microsoft homepage - itself temporarily off-line this morning - highlights the security issues, and repeats the advice to enable firewall protection and ensure that software is kept up to date with patches. You can find the detailed steps for securing your computer at www.microsoft.com.

See also

Critical hole in Microsoft's Windows

Subscribe to PC Pro magazine. We'll give you 3 issues for £1 plus a free gift - click here

From around the web

Be the first to comment this article

You need to Login or Register to comment.

(optional)

advertisement

More From PC Pro
Latest Blog Posts Subscribe to our RSS Feeds
Latest ReviewsSubscribe to our RSS Feeds
Latest Real World Computing

advertisement

Sponsored Links
 
SEARCH
SIGN UP

Your email:

Your password:

remember me

advertisement


Hitwise Top 10 Website 2010
 
 

PCPro-Computing in the Real World Printed from www.pcpro.co.uk

Register to receive our regular email newsletter at http://www.pcpro.co.uk/registration.

The newsletter contains links to our latest PC news, product reviews, features and how-to guides, plus special offers and competitions.