Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

The Welchia virus: The "Cure" Causes More Trouble Than The Illness

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Archives » General Discussion (Through 2005) Donate to DU
 
Prisoner_Number_Six Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Aug-28-03 04:35 PM
Original message
The Welchia virus: The "Cure" Causes More Trouble Than The Illness
VirusList.com Virus Alerts & Virus News. Thursday, August 28, 2003
******************************************************************

The "Cure" Causes More Trouble Than The Illness

The Welchia virus has actually caused more Internet-wide problems than the Lovesan virus it was created to defeat.

The virus known as Welchia is a derivative of the Lovesan worm virus that spreads via the Internet to computers running Microsoft operating systems that have not been patched for the DCOM RPC vulnerability. Microsoft made the patch available on July 16, 2003.

Welchia is a sort of "anti-virus virus", but this does not mean it is a good thing. In fact, in this case the cure, 'Welchia', has been more problematic than the pest its creator(s) set out to stop, 'Lovesan'.

Welchia attempts to protect vulnerable computers by identifying those without the DCOM RPC patch and downloading it from Microsoft. Despite any potential good intentions the network traffic soaked up by Welchia caused Air Canada's ticketing system to fail. Welchia is also attributed with bringing down the railway signaling system of CSX Corp., causing delays and cancellations throughout the eastern U.S.

Welchia my not be as widely distributed as Lovesan, but it is a more technically advanced virus and is responsible for more total Internet traffic. Welchia, at one point last week had even been reported to be behind a few Internet backbone "performance issues".

The only way to stop Welchia and Lovesan is to get all computers patched against the DCOM RPC vulnerability.

Links to appropriate patches can be found at: http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-026.asp
Printer Friendly | Permalink |  | Top
LoneStarLiberal Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Aug-28-03 04:43 PM
Response to Original message
1. I Vote Welchia Worse Than Lovesan
That little bugger almost single-handedly froze our gigabit ethernet network here on campus last week. Damned ICMP packets flying everywhere.

Of course our ACL filtering kept Lovesan away from the outside.
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Sun May 05th 2024, 08:50 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Archives » General Discussion (Through 2005) Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC