MSMVPS.COM

The Ultimate Destination for Blogs by Current and Former Microsoft Most Valuable Professionals.
Welcome to MSMVPS.COM Sign in | Help
in Search

Harry Waldron - Microsoft MVP Blog

Security News and Best Practices for corporate and home users

Witty Worm - "Patient zero" Analysis of First PCs attacked

A recent study was completed related to the Witty worm, which represents one of the most sophisticated attacks using a few vulnerability in the Black Ice Firewall system.  The randomized IP generation and destructive disk algorithms used by Witty are detailed in the Long Version of the Slide show below. 

Internet Storm Center
http://isc.sans.org/diary.php?date=2005-05-26

Security Focus Article
http://www.securityfocus.com/news/11235

Article - Outwitting the Witty Worm
http://www.cc.gatech.edu/~akumar/witty.html

Slide Show - Long Version
(esp. pages 11-17, 41-42)
http://www.cc.gatech.edu/%7Eakumar/witty_slides.pdf

Slide Show - Short Version
http://www.cc.gatech.edu/%7Eakumar/wisp.pdf

Reflections on Witty: Analyzing the Attacker
http://www.icsi.berkeley.edu/%7Enweaver/login_witty.txt

Only published comments... May 27 2005, 04:54 PM by Harry Waldron

Leave a Comment

(required) 
(optional)
(required) 
Submit
Powered by Community Server (Commercial Edition), by Telligent Systems