-Caveat Lector- NetTrends: The Other Y2K Problem -- Hacker Attacks http://news.excite.com/news/r/990902/02/net-column-nettrends Updated 2:52 AM ET September 2, 1999 By Dick Satran SAN FRANCISCO (Reuters) - Billions of dollars have been spent to make sure the world's computers are ready for the year 2000 -- but hackers of all descriptions are going to try their best make them fail, security experts say. With just a few months to go before computers' clocks change over to the new year, engineers are busy locking down systems whose code has been certified as free of the Y2K problem -- the inability to read the year in date-activated programs. But some system managers may be ignoring another potentially serious problem posed by intruders who use the frenzy and confusion of the Y2K changeover as a cover for malicious attacks. "The threat ranges from the pranksters -- people who celebrate the millennium by hacking a few computers -- to cyber-terrorists who want to bring modern civilization to its knees," said Constance Fortune, vice president for computer consultant Science Aplications International Corp. The world's largest computer security company, Network Associates (http://www.nai.com), said it is launching a new campaign this week to publicize the threat with a new Web site that will list the potential dangers of Y2K hackers. "Network administrators will be looking for system failures -- but not necessarily virus writers," said Sol Viveros, of Network Associates. "We've started this initiative to let people know that they really do have to worry about this." When systems crash at the start of the year 2000, technicians are going to be quick to blame the Y2K problem, which is exactly the kind of vulnerability that malicious hackers love to exploit. All crashes look alike, but the root causes differ dramatically. The teams assembled to manage computers through the rocky early days of the new year will probably be heavily weighted with systems experts who may not have much expertise on computer intrusions. "You need people who recognize the signs of an attack, and who are trained to shut down the system as soon as possible when it hits," said Fortune. As long as the system keeps running it can be released "into the wild," and create a broader infection over the Internet. Outbreaks this year like the Melissa and Chernobyl viruses hit thousands of computers and caused millions of dollars worth of damage. The Chernobyl virus, in particular, draws a parallel to the Y2K problem because it is a "date-activated" virus. A hacker created a program that was triggered when computer clocks hit the anniversary of the Soviet nuclear plant meltdown, one of the technology world's worst-ever disasters. Y2K already appears to be inspiring a wave of hackers who like to create digital time bombs. "We've been monitoring various virus-writing newsgroups (Internet bulletin boards) and we've seen quite a few postings, with people discussing the fact they plan on creating viruses that will begin striking during the millennium," said Network Associates' Viveros. "We're already seeing lots of (Y2K hacker) postings," added SAIC's Fortune. The programs that erase hard disk drives or cause system failures could be implanted deeply within a user's system, where the remain hidden from sight until the date change. Viveros said some systems managers may lock down their systems prematurely and miss the hidden invaders. SAIC's Fortune said the programmers handling the heavy amounts of programming to fix Y2K problems may have left "backdoor" openings for hackers to enter. One group reported to be targeting such openings is Streets, which first hit City of London financial district computers on June 18. Space Rogue, editor of Hackernews (http://www.hackernews.com), an Internet-based service that reports on hacking exploits, said the threat of such attacks is probably overestimated because "it requires a lot more knowledge than most people have." Rogue said that attacks are "possible" but the security industry is overplaying the threat to build up its own services. "Fear sells," said the editor. At Network Associates, Sol Viveros said it's important to raise the alarm because it reminds computer users to prepare for potential problems. A global alert helped dramatically reduce the impact of Melissa and other virus-type outbreaks this year. Once notified of a threat, system administrators can shut down their systems and run anti-virus software. His company will be among the scores of software firms that will be celebrating new year's this year with round-the-clock surveillance of customers' computers, trying to spot threats before they cause too much damage. "It all boils down to security awareness," said SAIC's Fortune. (The NetTrends column appears weekly. If you have comments or questions, you can send e-mail to dick.satran(at)reuters.com.) Swedish Firm Pumps Up Volume Of Online Music (Previous story) Internet: Rocky Road To Information Superhighway (Next story) DECLARATION & DISCLAIMER ========== CTRL is a discussion and informational exchange list. Proselyzting propagandic screeds are not allowed. Substance�not soapboxing! These are sordid matters and 'conspiracy theory', with its many half-truths, misdirections and outright frauds is used politically by different groups with major and minor effects spread throughout the spectrum of time and thought. That being said, CTRL gives no endorsement to the validity of posts, and always suggests to readers; be wary of what you read. CTRL gives no credeence to Holocaust denial and nazi's need not apply. Let us please be civil and as always, Caveat Lector. ======================================================================== Archives Available at: http://home.ease.lsoft.com/archives/CTRL.html http:[EMAIL PROTECTED]/ ======================================================================== To subscribe to Conspiracy Theory Research List[CTRL] send email: SUBSCRIBE CTRL [to:] [EMAIL PROTECTED] To UNsubscribe to Conspiracy Theory Research List[CTRL] send email: SIGNOFF CTRL [to:] [EMAIL PROTECTED] Om
