Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Witty Extinction
Kelly Martin, 2004-04-07

The Witty worm set a dangerous precedent on the Internet because it introduced a number of evil new "firsts" in the ever-changing world of modern worms and viruses.

Comments Mode:
But they WEREN'T current with their patches... 2004-04-07
InvisiBill
From http://news.zdnet.co.uk/software/developer/0,39020387,391500
16,00.htm...
-------------------------------
Johan Beckers, director of technology solutions at ISS EMEA, told ZDNet UK that all of ISS's "legal" customers could have updated their systems to avoid Witty but he admitted that the 12,0...

[ more ]  [ reply ]
Witty Extinction 2004-04-07
Matthew Murphy
Kelly's article attempts to make a very interesting point, though it is not all that clear. The fact that Witty destroyed victims made its propagation and demise period fast enough that by the time it had been discovered spreading, it was no longer much of a media spectacle.

This interferes with...

[ more ]  [ reply ]
Witty Extinction 2004-04-08
Anonymous
Actually, having been released only one day after the announcement would seem to imply that the heart of the virus was already written.

Only the destructive payload needed to be added....

[ more ]  [ reply ]
Witty Extinction 2004-04-08
Leonidas
Awesome Writeup! Software Security Vendors should be held accountable, as this is their main line of business. If THEY are not expected to uphold a high standard in writing secure code, then we might as well not expect it from anybody else....

[ more ]  [ reply ]
Witty Extinction 2004-04-08
Anonymous Coward
I think that equally disturbing, as some of the other firsts that were prevalent in this worm, was the response by ISS.

Effectively: no support contract - no patch.

There may be people who were pro-active in attempting to patch vulnerable software, who were not willing to shell out more money...

[ more ]  [ reply ]
Let's not allow ISS to rewrite history..... 2004-04-08
carter_ronin
The Vulnerability was discovered on the 8 March 04. Reported to the X-force (ISS's research arm) on the ninth, Published on the 18 March 04, by everyone. The PC protection "ccg" patch wasn't available until the 19th (ten days?), and still had to be followed up days later by cch!

....do is sound p...

[ more ]  [ reply ]
DiD is the key 2004-04-09
Anonymous (1 replies)
They key here is not the exploitation of a vulnerability in a single product line. It is that even home users need to consider DiD. I've seen many businesses that have fallen for the "integrated management" offered by single source vendors and so have one style of security product in each defence ca...

[ more ]  [ reply ]
DiD is the key 2004-04-15
Reality
With all due respect I both agree and disagree.

Yes, DiD is a good thing and could have prevented a "witty" infection. Yes, using multiple types of defenses at the different layers stops more attacks.

However, here in the real world we are dealing with a user base that is barely aware of the i...

[ more ]  [ reply ]
Witty Extinction 2004-04-13
Anonymous
InvisiBill said on Apr 7 2004 7:09PM
---------------------------------------------
Johan Beckers, director of technology solutions at ISS EMEA, told ZDNet UK that all of ISS's "legal" customers could have updated their systems to avoid Witty but he admitted that the 12,000 systems affected by Witt...

[ more ]  [ reply ]
Witty Extinction 2004-04-13
Anonymous
The information often presented in the example of website defacement is that many attacks are performed through unreleased vulnerabilities (www.zone-h.org). Who's to say that such a worm didn't take longer to develop, but it's release nicely coincided with the release of the vulnerability? Just beca...

[ more ]  [ reply ]
ISS not to be blamed 2004-04-14
Mohammed Abdel Kader
Had the people who bought ISS products updated their products the worm would not have affected them in any way. So no one can really blame ISS for this, a patch was available before the worm was in the wild....

[ more ]  [ reply ]







 

Privacy Statement
Copyright 2009, SecurityFocus