Feared RPC worm starts to spread

Security experts on Monday warned of the first self-propagating virus to take advantage of a widespread vulnerability reported last month in Microsoft Corp.'s Windows operating systems.

Known by various names, including Blaster and Lovesan, the worm virus has begun to infect computers at homes and businesses and could clog the Internet with traffic and allow a malicious hacker to steal or corrupt data stored in an infected system, experts said.

The vulnerability, a buffer overrun in a Windows interface that handles the RPC (Remote Procedure Call) protocol, was acknowledged by Microsoft in a security bulletin posted July 16. Along with government and private security organizations, Microsoft has been urging customers to install a security patch in order to protect against attack.

The flaw affects several versions of Windows, including Windows NT 4.0, Windows XP and Windows Server 2003, making potential targets of millions of desktop and server computers. Experts have warned of the potential for serious disruption of the Internet, although it wasn't immediately clear Monday how rapidly the worm was spreading.

Security vendor Trend Micro Inc. said it had received reports of several infected machines Monday. The worm was observed scanning for vulnerable systems and then sending itself to those machines using port 135, the company said. The worm also will launch a denial of service attack against Microsoft's windowsupdate.com Web site on Aug. 16 and Aug. 31, and on every day from Sept. 1 through the end of the year, Trend Micro said.

Trend Micro gave the worm an overall risk rating of medium but rated the damage and distribution potential as high. Network Associates Inc.'s McAfee unit also rated the worm "medium on watch" for both home and business users.

Daniel Zatz, senior security consultant from Computer Associates in Sydney said the worm was unique in that it was targetting the operating system and not an application. Where most worms come to users via attachments in e-mail, this one is coming from the RPC exploit. As a result, those consumers who have not updated their antivirus signatures on their PCs "are not going to know they have been affected", he said.

Netsolve Inc., an IT services company in Austin, Texas, that provides managed security services to about 1,000 businesses, said the worm was spreading rapidly and had been observed in several of its customers' networks Monday afternoon. However, Chuck Adams, the company's chief security officer, said it was too early to say for sure how much damage, and what type of damage, the worm will cause.

"The impact is pretty small right now, but based on the analysis we've done on the (exploit) code we've captured, it's going to be a propagation pattern similar to SQL Slammer," he said, referring to a widespread worm that affected Microsoft's SQL Server 2000 database earlier this year.

However, based on Netsolve's early observations, Blaster isn't likely to spread as widely as SQL Slammer, Adams predicted.

"I don't think it will be as large because there are some limitations" to Blaster, he said. For example, SQL Slammer tried to take advantage of multiple Windows vulnerabilities, while Blaster appears to exploit only one, he said.

According to Zatz, Computer Associates has already had some of its Australian customers affected since fist detecting the worm at about 7am AEST. "It is still early days," he said.

The most troubling aspect of Blaster is that as well as propagating itself, the worm installs a "back door" program on infected systems and reports back to an Internet relay chat server that the system has been compromised, Adams said. A malicious hacker could use that information to identify a compromised system and then attempt to delete or access data stored on it, he said.

(Howard Dahdah contributed to this report.)

Join the newsletter!


Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

James Niccolai

IDG News Service
Show Comments

Brand Post

Most Popular Reviews

Latest Articles


PCW Evaluation Team

Aysha Strobbe

Microsoft Office 365/HP Spectre x360

Microsoft Office continues to make a student’s life that little bit easier by offering reliable, easy to use, time-saving functionality, while continuing to develop new features that further enhance what is already a formidable collection of applications

Michael Hargreaves

Microsoft Office 365/Dell XPS 15 2-in-1

I’d recommend a Dell XPS 15 2-in-1 and the new Windows 10 to anyone who needs to get serious work done (before you kick back on your couch with your favourite Netflix show.)

Maryellen Rose George

Brother PT-P750W

It’s useful for office tasks as well as pragmatic labelling of equipment and storage – just don’t get too excited and label everything in sight!

Cathy Giles

Brother MFC-L8900CDW

The Brother MFC-L8900CDW is an absolute stand out. I struggle to fault it.

Luke Hill


I need power and lots of it. As a Front End Web developer anything less just won’t cut it which is why the MSI GT75 is an outstanding laptop for me. It’s a sleek and futuristic looking, high quality, beast that has a touch of sci-fi flare about it.

Emily Tyson

MSI GE63 Raider

If you’re looking to invest in your next work horse laptop for work or home use, you can’t go wrong with the MSI GE63.

Featured Content

Product Launch Showcase

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?