New virus preys on old IE flaw

By Ina Fried
19 September 2003 09:00 AM
Tags: swen, gibe.f, worm, virus, anti-virus, mail, disclose, prey
A new e-mail worm has started to spread quickly, taking advantage of an Internet Explorer vulnerability that was first disclosed two years ago.

The bug, which has been alternately dubbed Swen and Gibe.F, appears to exploit a flaw that Microsoft first disclosed in a March 2001 security bulletin.

Ken Dunham, manager of malicious code intelligence for iDefense, said that Swen preys upon people's best intentions, appearing as an e-mail that purports to be a security update from Microsoft.

The worm is programmed to send an official-looking e-mail that says it contains a "cumulative patch" for several Internet Explorer, Outlook and Outlook Express vulnerabilities.

A Microsoft representative noted that the software maker does not send out patches as e-mail attachments.

In addition to spreading via e-mail, experts said, Swen can be transmitted over services such as Internet relay chat (IRC) and through peer-to-peer networks. The virus turns on file sharing--if it is not already turned on--and creates a shared directory with multiple copies of itself under various file names, said Kevin Haley, a group product manager at Symantec Security Response. Among the files Swen tries to disguise itself as are virus removal tools.

Haley said the social engineering that the virus writer used is most troubling.

"Those things are pretty interesting and pretty dangerous," he said.

The threat posed by Swen is rated fairly low by antivirus companies such as McAfee and Symantec, despite the worm's growing prevalence. "It doesn't look like it is causing a lot of trouble at least right now," Haley said. The threat is somewhat higher for home users and users outside the United States who are more likely to be using older, unpatched software, McAfee said.

"Swen is quickly gaining ground in Europe and has the potential to become very widespread in a short period of time," Dunham said in an e-mail.

The emergence of Swen comes as security companies have warned that a potentially major bug could soon emerge based on a recently disclosed Windows vulnerability. Experts said earlier this week that code that could quickly be used to create such a bug is already being distributed on underground hacker sites.

Advertisement

Talkback 0 comments

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal Love me, tender
    Considering how expensive and drawn-out tender processes can be to solve problems that might be very immediate, it's little wonder that the Victorian Police IT department tried to work the tender exemptions system.
  • Array 2009 funding drought rolls on
    For Australian start-ups looking for venture capital, 2009 was a very bad year. 2010 may be no better.
  • Array Can not-so-smart meters help the NBN?
    It was interesting to witness Conroy's recent enthusiasm to spruik the NBN's role in supporting the Smart Grid, Smart City initiative. What a pity that Conroy hadn't yet seen the damning report from the Victorian auditor-general about that state's smart-meter roll-out.
  • More blogs »

Tags

Back to top

Featured