Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


January 2004

Plug the Mobile Worm Hole

Or risk unpleasant consequences
RSS
Subscribe to Windows IT Pro | See More Antivirus Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

The problems started the day I returned from my most recent trip. Due more to a stroke of luck than to good planning, my office workstation is near my network router, and about an hour after I started working, I saw the router's WAN activity light turn solid white and stay that way.

Although this light is often on, it typically doesn't stay on for long. With a growing sense of alarm, I toured the office and saw that no one was performing any work on the Internet. Glancing at my network switch, I noticed that three connections were very active and knew that I had a problem. I pulled the plug on the connections, and sure enough, the WAN activity light immediately went out.

Two of the active connections went to network client and server systems that I use primarily for testing. The other connection went to my wireless access point (AP), which not coincidentally was connected to the laptop that I took on my recent trip. To be sure that the WAN activity was related to one of those three systems, I plugged one of the connections back in and watched my WAN activity light jump back to life. My fears were confirmed: I had some type of virus on my network. I wasn't sure how the virus got through my defenses or which virus it was, but something was there.

Digging into the Problem
One of my test systems was running Windows XP Service Pack 1 (SP1). I had recently rebuilt the other systems and hadn't installed the latest hotfixes on them. Because all these machines are test systems, I hadn't installed antivirus software on them.

First, I needed to eliminate the virus. Then, I wanted to find out how it got on my network. I run a firewall and my production systems use antivirus software, so determining how the virus was introduced was essential to preventing similar vulnerabilities in the future.

After scanning the infected systems, I found that the source of the problem wasn't the MSBlaster worm that I expected to find. The culprit was the "good" variant of that worm, known as MSBlast.D, which, ironically, automatically patches systems that the MSBlaster worm has exploited. MSBlast.D basically replaces the dllhost.exe and svchost.exe files with its own versions of these programs, then performs a Trivial FTP (TFTP) transfer with the Windows Update Web site to download fixes. Nice, had it worked—but it didn't. Instead, MSBlast.D locked up every system it ran on, requiring me to boot the systems in Safe mode to get rid of it. Additionally, by using up all my bandwidth, MSBlast.D essentially caused a Denial of Service (DoS) on my network—proving that there's no such thing as a good worm.

By the time I'd repaired all three systems, I knew that I had brought the worm into my network on my laptop. I'd been using a new laptop for the past couple of months and switched back to my old laptop just before my trip, grabbing the old laptop out of a drawer and putting it directly into my bag. I hadn't patched the machine or updated its antivirus definitions. I'm sure that the laptop became infected when I plugged it into the wireless network that I used on my trip. Some PC on the wireless network had the worm and merrily spread it to every other PC on the same subnet.

Protect Your Mobile Systems
Although unpleasant, this experience pointed out a couple of areas in which I hadn't been vigilant enough. The first and most important of those is the need to run a personal firewall on my mobile systems, especially when using public networks. This precaution alone would have stopped the worm in its tracks. The worm spread across port 135—the port that Microsoft networking uses. While traveling, I want my laptop to communicate over port 80 so that I can browse the Web and use Microsoft Outlook Web Access (OWA). Occasionally, I might need standard POP3 access through port 110. But I certainly don't want access to Microsoft networking over port 135. Using a personal firewall to shut down all unwanted (and unneeded) ports would have drastically reduced my attack surface.

Second, all mobile systems should always have the latest patches and antivirus definitions. Although I thought my networks were protected from the outside, I learned that networks aren't really secure until you've plugged the mobile worm hole.

End of Article



Reader Comments
Although this is sound advice and I completely agree how does one go about achieving this in a large enterprise?

When I say how I don't just mean technically I also mean raising management and user awareness that this is an essential task rather than the IT techs just saying so?

Thanks and keep writing the mag I find the articles very informative and helpful.

Chris Marsden January 02, 2004


I just waisted my time reading this article because you were to lazy to patch your laptop before you went out on a trip.

Kevin January 14, 2004


it would be nice to know of other detection systems we can make instead off hand-eye methods.

rostand January 15, 2004


I can tell Kevin's English teachers *wasted* their time, because his writing looks way *too* much like that of a grade-school kid. But he does prove that the World Wide Web is easy enough for a moron to use, without a doubt.

(Great article Michael, keep it up!)

Mark McGinty January 16, 2004


I thought this was a very good article, epsecially when one considers wireless public networks. I've always considered myself "protected" behind a firewall, never stopping to consider the potential, albeit short-term, exposure to others while in public. I believe I'll make it a standard to configure the personal firewall software existing in Windows XP on all roving laptops.

Jeff Ebert January 18, 2004


You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
Friday at PASS Europe 2006

Kevin talks about the closing day of the event and shares a funny Microsoft film. ...

Escape From Yesterworld

Kevin points you to the funniest SQL Server website ever! ...

The Desktop tab is missing from the Display Properties in Windows XP?

...


Security Whitepapers Anti-Virus Is Dead: The Advent of the Graylist Approach to Computer Protection

Getting the Job Done: Comparing Approaches for Desktop Software Lockdown

Instant Messaging, VoIP, P2P, and games in the workplace: How to take back control

Related Events Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.

Job Openings in IT


ADS BY GOOGLE SPONSORED LINKS FEATURED LINKS

WinConnections Conference Fall 2008
Don’t miss the premier event for Microsoft IT Professionals in Las Vegas, November 10-13. Register and book your room by August 25 and receive a FREE room night (based on a three night minimum stay).

Maximize your SharePoint Investment – 8 Cities
Discover best practices and tips for both architecting and administering SharePoint. Early Bird Price of $99 through Sept 15th.

Find a new job now on the all new IT Job Hound!
Search jobs, post your resume, and set up job e-mail alerts!

Master SharePoint with 3 eLearning Seminars
Learn how to build a better SharePoint infrastructure and enable powerful collaboration with MVPs Dan Holme and Michael Noel. Register today!

Top Tools for Virtualization Disaster Recovery & Replication
View this web seminar on August 14th to learn about two tools that will result in faster backup and restore with P2V disaster recovery.

SharePointConnections Conference Fall 2008
Don’t miss the premier event for Microsoft IT Professionals in Las Vegas, November 10-13. Register and book your room by August 25 and receive a FREE room night (based on a three night minimum stay).

VMworld 2008 - Sign Up Today!
Join your peers on September 15-18 at The Venetian Hotel in Las Vegas as VMware hosts VMworld 2008, the leading Virtualization event.



When managing just VMware isn’t enough
Plan/Manage/Secure – NetIQ VMware management. Download whitepaper.

What’s up with your network? Find out with ipMonitor
Availability monitoring for servers, applications and networks – FREE trial

Microsoft® Tech•Ed EMEA 2008 IT Professionals
Advance your thinking with new ideas and practical real-world solutions at Microsoft’s FIVE day technical infrastructure conference 3-7 Nov., 2008. Register before 26 September 2008 to save €300.

Order Your Fundamentals CD Today!
Gain an introduction to Exchange, learn server security requirements, and understand how unified communications can play a role in your messaging strategies with this free Exchange CD.

Are You Really Compliant with Software Regulations?
View this web seminar that will help you with compliance best practices and check out a management solution to assure that you won’t be in jeopardy of an audit.

Virtualization Congress Oct. 14-16 in London
Don't miss Virtualization Congress, the premiere EMEA conference dedicated to hardware, OS and application virtualization. Oct. 14-16 in London.
Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technical Resources Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing