NT government reeling as Sasser goes bush

The Northern Territory government has put its hand up as being among the victims of the Sasser worm, which began spreading across global computer networks Saturday.

The territory government's IT security manager David Pears said Sasser struck the network at 10 am yesterday.

He confirmed that the worm managed to touch every part of the 12,000 seat network which serves the entire territory's administrative departments, which are sprinkled across a vast geographic area from Darwin south, around 1000 kilometres, to Alice Springs.

"The territory is small enough that all the government agencies share the infrastructure; the email system...we have one gateway to the network; one firewall," said Pears.

Pears said it was difficult to assess Sasser's impact on the territory's government agencies during the incident.

"It really depends -- most of the public servants will go do something else if they log on and they can't access their email; a nurse will go help a patient; the police will go and look for some [criminals]," he said.

"Anyone who's completely dependant on the computer would obviously be affected, and reasonably severely, yesterday through to early afternoon".

However Pears gave assurances that critical services such as health and social security would not have been affected significantly as they took priority in the territory's IT disaster recovery plan.

As in other cases where Sasser infection has taken place, the territory's public servants had to contend with infected machines shutting down and restarting continually.

However, there was also a secondary impact from the worm's presence on the network. Sasser, like its ancestral cousins such as Blaster, generates a large amount of network activity as it attempts to spread from infected computers to other vulnerable computers nearby.

Pears compared the effect of the network activity to that of a large Distributed Denial of Service (DDoS) attack.

"What we've been doing patching [our systems] like mad," said Pears.

Government technical staff managed to stabilise the network yesterday afternoon, but it was today still carrying out patching exercises to protect computers in remote regions of the territory.

In other corners of the industry an IT administrator in Pears position might be sharply critical of Microsoft for allowing such vulnerability in its software to go unchecked for so long. However, Pears comments regarding the software giant's security performance, oozing outback stoicism, were almost complimentary.

"I think for the amount of lines of code in Windows XP, they're doing a pretty reasonable job," he said.

Advertisement

Talkback 4 comments

    It surprises me why people like Pears are still in a job when there has been a widely publicised patch available for some time. Oh, I forgot, its only a government dept and no-one is really accountable.Anonymous -- 05/05/04

    It surprises me why people like Pears are still in a job when there has been a widely publicised patch available for some time. Oh, I forgot, its only a government dept and no-one is really accountable.

    Don't these so called "IT" people know how to patch? My god how many times does this have to happen? Having worked in large IT departments I know how hard it is to get everything patched but the alternative is far worse. The administratorsAnonymous -- 06/05/04

    Don't these so called "IT" people know how to patch? My god how many times does this have to happen?
    Having worked in large IT departments I know how hard it is to get everything patched but the alternative is far worse. The administrators of these systems don't deserve to be in a job.

    It boggles my mind how some IT network administrators people with tertiary qualifications and healthy paypackets cant even be bothered to check reguarly for new security risks and take appropriate measures to protect the networks they have been entrusted Anonymous -- 07/05/04

    It boggles my mind how some IT network administrators people with tertiary qualifications and healthy paypackets cant even be bothered to check reguarly for new security risks and take appropriate measures to protect the networks they have been entrusted to protect.

    It "boggles my mind" how someone who can't spell "businessman" feels able to comment on someone else's ability to do a job they clearly don't understandAnonymous -- 11/06/04

    It "boggles my mind" how someone who can't spell "businessman" feels able to comment on someone else's ability to do a job they clearly don't understand

Add your opinion


Latest Videos

Blogs

  • Chris Duckett PayPal launches Aussie developer program
    PayPal announced the opening of its certification program for Australian developers today, making Australia the first country outside of the US to offer certification.
  • Array Cash cow in a BigTinCan?
    Around one third of Australia's telcos have shut their doors over time, but that isn't stopping new ventures hoping to chip away at carriers' mobile call bonanza. By fighting carriers at the smartphone rather than the home phone, could the latest two contenders be onto something big?
  • Array A third of the way to a zettabyte
    This week on Twisted Wire we look at how internet usage is changing in Australia and around the world. How are we meeting this demand and how is the cost structure changing for the service provider?
  • More blogs »

Tags

Back to top

Featured