News

'White Hat' Worm Tries to Remove Blaster

In what appears to be a misguided attempt to do good, someone released a worm that exploits the same DCOM RPC vulnerability that enabled the Blaster worm but that attempts to automatically download the Microsoft patch and remove the Blaster worm if it's present.

Security vendors assigned the names Welchia, Blaster-D and Nachi to the worm. Symantec rated the worm a 4 in severity on its 5-point threat scale.

In addition to exploiting the DCOM RPC vulnerability patched in MS03-026, to target and modify Windows XP systems, Welchia also exploits the WebDAV vulnerability patched even earlier with MS03-007, to target Windows 2000 systems running IIS 5.0.

Symantec warns that the worm causes system instability due to an RPC service crash on Windows 2000 machines and compromises system security by installing a Trivial File Transfer Protocol (TFTP) server on all infected machines. Microsoft officials added that the worm generates excess network traffic.

About the Author

Scott Bekker is editor in chief of Redmond Channel Partner magazine.

Featured

  • MIT Finds Only 1 in 20 AI Investments Translate into ROI

    Despite pouring billions into generative AI technologies, 95 percent of businesses have yet to see any measurable return on investment.

  • Report: Cost, Sustainability Drive DaaS Adoption Beyond Remote Work

    Gartner's 2025 Magic Quadrant for Desktop as a Service reveals that while secure remote access remains a key driver of DaaS adoption, a growing number of deployments now focus on broader efficiency goals.

  • Windows 365 Reserve, Microsoft's Cloud PC Rental Service, Hits Preview

    Microsoft has launched a limited public preview of its new "Windows 365 Reserve" service, which lets organizations rent cloud PC instances in the event their Windows devices are stolen, lost or damaged.

  • Hands-On AI Skills Now Outshine Certs in Salary Stakes

    For AI-related roles, employers are prioritizing verifiable, hands-on abilities over framed certificates -- and they're paying a premium for it.