Westpac hit by Sasser worm

The Sasser worm has sent some of Westpac's banking systems into disarray, forcing staff to turn customers away from branches.

The worm struck the network underlying the bank's branch system mid-morning forcing staff to switch to "alternative procedures" for handling customers.

Customers were turned away from Westpac's branches and phone customer contact centre. There was little Westpac could do except redirect them to ATMs and its online banking service.

Westpac was today playing down the incident. A spokeswoman for the bank insisted that it had little impact on customers and gave assurances that their accounts and privacy had not been compromised during security breach.

Reports from Westpac customers affected by the incident offer a worrying illustration of Sasser's power to wreak havoc on systems that millions of people take for granted everyday.

One Westpac customer who contacted to ZDNet Australia reported being told by an operator "every computer in the call centre is black".

The spokeswoman said the bank was in the process of patching systems against the worm to counter-act the infection and that they were expected "to be fine for business tomorrow".

The worm causes components of Windows computers to crash and restart repeatedly, according to security analysts reports.

The worm spreads from infected computer to other vulnerable computers without user intervention, by creating a remote connection and downloading itself onto the new host.

There are worrying indications that Sasser could unleash chaos at a level matching the infamous MSBlaster worm, which is belived to have infected 8 million computers since last August.

Computer Associates senior security analyst, Daniel Zatz, today said that incoming calls to the computer security company's Melbourne response centre concerning Sasser had today reached similar levels as those created by MSBlaster.

Aside from direct damage caused by the worm, Zatz indicated that Sasser's was likely to slow down some corners of the Internet as machines infected with the worm flooded networks with thousands of requests.

Zatz today indicated organisations running large Microsoft-based systems that lay in the path of of the swathe of new worms released each year were now facing a no-win situation.

He said that while Microsoft often releases patches for its software to plug the security holes that worms like Sasser exploit, organisations are contending with increasingly shorter windows of opportunity to test them before new attacks occur.

"What they [organisations] would like to see is that when a patch gets released they know its going to work," said Zatz.

Zatz said Microsoft wasn't wholly responsible for such potential problems, as third-party applications were often the cause of software compatibility failures.

That said Zatz, is because virus writers are taking less time to figure out how to defeat un-patched Microsoft systems once the vulnerabilities are made public. It took miscreants 18 days to create Sasser while previous worms of similar sophistication have taken around 22 days.

Advertisement

Talkback 2 comments

    my westpac bank account was hit and i lost moneyAnonymous -- 31/03/07

    and i am waiting on the bank to sort somthing out ...
    hopefully ... are my creditors going to wait i dont think so
    they have there own agender .. and do the banks

    westpac sasser wormAnonymous -- 31/03/07

    I bank with Westpac bank and i have used the banking internet for as long as i could remember (Almost the year that internet banking started in Australia).

    But today things were very different i deposited my wages
    In my account as i do every 2 weeks ... i went and deposited in to the branch near my work.... by 1.30 pm my money was deposited and by 3.00pm the bank was hit with this sasser worm and at the time the bank was hit i entered my account via internet banking my account was withdrawn by over 1000 dollars

    but when i rang the bank they played it down by saying that did i take the money out ... and at this time they just shrugged me away telling me to wait until the next business day so that then i would have to call them and make an inquiry in to the wear about my money had gone and they kept saying that i could have transactions which i had forgotten about but i don’t let any one take money direct from my account. so by this time they did not even tell me that the bank was hit with a virus ... till i went back to the branch were they actually were on high alert and they were still not telling the customers any thing about the virus ... then i was called by there security division tell me that they have suspended my internet account until the matter was cleared up on how and where or whom had touched my money through my account ... i had no choice but to take what was left in my accounts ... but still i was not told about this worm until i came on your site ... here it is a bank has trouble but yet the bank is keeping things from there customers but when we have trouble they have the right
    to keep things from us and at the same time say it was our fault (i.e. the customer).

Add your opinion


Latest Videos

Blogs

  • Juha Saarinen TelstraUnClear
    Telstra's New Zealand arm TelstraClear is one strange company ...
  • Array E-health too unsexy for COAG
    There will always be something more politically sexy than e-health for state governments, meaning the National E-Health Transition Authority's business case for a national electronic medical record might just sit on the shelf gathering dust forever.
  • Array Will Rudd's bush backhaul bonanza deliver?
    Rural areas will be welcoming the government's decision to put its money where its politicising is, funnelling $250m into a regional fibre upgrade to six rural centres. Remedying over a decade of near-neglect at the hands of telecoms privatisation, the investment could be the firmest step yet for Labor's NBN dream — but with inevitable political questions and a looming election, Rudd and Conroy need to deliver, and quickly, to preserve the NBN's credibility.
  • More blogs »

Tags

Back to top

Featured