A major Internet attack that installs hacker tools on users' systems is subsiding, security experts say. But more copycat attacks are possible in the days ahead.
A widespread attack that targeted major E-commerce sites and secretly planted hacker tools on the computers of Internet surfers is subsiding, security experts say.
Security experts estimate that thousands of Web sites were compromised in the past week. The attack, which may have begun as early as Sunday, didn't attract much attention until late Thursday evening when it was identified by Internet security firms.
Most of the Web sites known to have been infected have been cleaned, security analysts say. Also, Internet service providers have blocked access to, or "black-holed," the Russian server that was planting the hacker tools on user PCs.
While patches are available for most of the Internet Explorer vulnerabilities used in the attack, no patch is available for one of the flaws, commonly known as the ADODB vulnerability.
It's still unclear how the attackers managed to successfully compromise Web servers running Microsoft's IIS software, security experts say. "It's something we're looking into," Huger says.
It's possible, but unlikely, that systems running Microsoft IIS 5.0 software could have been attacked by a "zero-day" vulnerability, which is a new software flaw that's unknown and unpatched by software vendors, says Marcus Sachs, director, of The SANS Institute's Internet Storm Center. "That's the worst-case scenario," he says.
Other possibilities include Web servers that administrators believed to have been patched but were not, or Web servers that could have been attacked through vulnerabilities unrelated to IIS 5.0.
Security experts warn that future attacks are possible. "Others may attempt copycat attacks, especially if there is a zero-day attack in IIS," Sachs says.
Major antivirus companies have updated their software to spot the malicious code downloaded to end-user systems in this attack.
Microsoft is urging Web-site operators running Windows 2000 Server and IIS to apply a patch found in Microsoft Security Bulletin MS04-011.
[Interop ITX 2017] State Of DevOps ReportThe DevOps movement brings application development and infrastructure operations together to increase efficiency and deploy applications more quickly. But embracing DevOps means making significant cultural, organizational, and technological changes. This research report will examine how and why IT organizations are adopting DevOps methodologies, the effects on their staff and processes, and the tools they are utilizing for the best results.
2017 State of IT ReportIn today's technology-driven world, "innovation" has become a basic expectation. IT leaders are tasked with making technical magic, improving customer experience, and boosting the bottom line -- yet often without any increase to the IT budget. How are organizations striking the balance between new initiatives and cost control? Download our report to learn about the biggest challenges and how savvy IT executives are overcoming them.