News

'White Hat' Worm Tries to Remove Blaster

In what appears to be a misguided attempt to do good, someone released a worm that exploits the same DCOM RPC vulnerability that enabled the Blaster worm but that attempts to automatically download the Microsoft patch and remove the Blaster worm if it's present.

Security vendors assigned the names Welchia, Blaster-D and Nachi to the worm. Symantec rated the worm a 4 in severity on its 5-point threat scale.

In addition to exploiting the DCOM RPC vulnerability patched in MS03-026, to target and modify Windows XP systems, Welchia also exploits the WebDAV vulnerability patched even earlier with MS03-007, to target Windows 2000 systems running IIS 5.0.

Symantec warns that the worm causes system instability due to an RPC service crash on Windows 2000 machines and compromises system security by installing a Trivial File Transfer Protocol (TFTP) server on all infected machines. Microsoft officials added that the worm generates excess network traffic.

About the Author

Scott Bekker is editor in chief of Redmond Channel Partner magazine.

Featured

  • Windows 10 Preview Adds Ability To Display Linux Distro Files

    Microsoft on Wednesday announced Windows 10 preview build 19603, which adds easier access to installed Linux distro files using Windows File Explorer.

  • Microsoft 365 Business To Get Azure Active Directory Premium P1 Perks

    Subscribers to Microsoft 365 Business (which is being renamed this month to "Microsoft 365 Business Premium") will be getting Azure Active Directory Premium P1 licensing at no additional cost.

  • How To Use .CSV Files with PowerShell, Part 1

    When it comes to bulk administration, few things are handier than .CSV files. In this two-part series, Brien demos his top techniques for working with .CSV files in PowerShell. First up: How to create a .CSV file.

  • SameSite Cookie Changes Rolled Back Until Summer

    The Chromium Project announced on Friday that it's delaying enforcement of SameSite cookie changes, and is temporarily rolling back those changes, because of the COVID-19 turmoil.

comments powered by Disqus

Office 365 Watch

Sign up for our newsletter.

Terms and Privacy Policy consent

I agree to this site's Privacy Policy.