The MSBlaster worm: going from bad to worse
Eugene Schultz · Network Security · 2003
Introduction On 11 August, 2003 a worm that exploited a vulnerability in the remote procedure call (RPC) protocol in Windows 2000 and XP systems was released on the Internet. This worm, most often called “MSBlaster,” but also “Blaster,” “LovSan (Note 1),” “W32/Lovsan,” “W32.Blaster,” “Win32.Poza,” “WORM_MSBLAST.A,” and “W32/Blaster-A,” spread dramatically. MSBlaster clogged many organizations’ networks with the traffic it created and many stories of massive disruption surfaced. A bank (including all of its branch offices) suffered a computing outage that prevented customers from making transactions for several hours, staff at a hospital were unable to access online patient data, and Maryland’s motor vehicle agency shut down for an entire day because of MSBlaster. According to Symantec, at least one-half million systems have became infected by this worm and its variants (such as MSBlaster.B) 1 . This paper describes the vulnerability that MSBlaster exploited, how MSBlaster and its major variant (Welchia) function, appropriate countermeasures, incident response strategies, and “lessons learned” from the MSBlaster experience.