-Caveat Lector-

NetTrends: The Other Y2K Problem -- Hacker Attacks

http://news.excite.com/news/r/990902/02/net-column-nettrends

                                             Updated 2:52 AM ET
September 2, 1999

 By Dick Satran

 SAN FRANCISCO (Reuters) - Billions of dollars have been spent to make
sure the world's
 computers are ready for the year 2000 -- but hackers of all
descriptions are going to try their best
 make them fail, security experts say.

 With just a few months to go before computers' clocks change over to
the new year, engineers
 are busy locking down systems whose code has been certified as free of
the Y2K problem -- the
 inability to read the year in date-activated programs.

 But some system managers may be ignoring another potentially serious
problem posed by
 intruders who use the frenzy and confusion of the Y2K changeover as a
cover for malicious
 attacks.

 "The threat ranges from the pranksters -- people who celebrate the
millennium by hacking a few
 computers -- to cyber-terrorists who want to bring modern civilization
to its knees," said
 Constance Fortune, vice president for computer consultant Science
Aplications International
 Corp.

 The world's largest computer security company, Network Associates
(http://www.nai.com), said it
 is launching a new campaign this week to publicize the threat with a
new Web site that will list the
 potential dangers of Y2K hackers.

 "Network administrators will be looking for system failures -- but not
necessarily virus writers,"
 said Sol Viveros, of Network Associates. "We've started this initiative
to let people know that
 they really do have to worry about this."

 When systems crash at the start of the year 2000, technicians are going
to be quick to blame the
 Y2K problem, which is exactly the kind of vulnerability that malicious
hackers love to exploit.

 All crashes look alike, but the root causes differ dramatically. The
teams assembled to manage
 computers through the rocky early days of the new year will probably be
heavily weighted with
 systems experts who may not have much expertise on computer intrusions.

 "You need people who recognize the signs of an attack, and who are
trained to shut down the
 system as soon as possible when it hits," said Fortune.

 As long as the system keeps running it can be released "into the wild,"
and create a broader
 infection over the Internet. Outbreaks this year like the Melissa and
Chernobyl viruses hit
 thousands of computers and caused millions of dollars worth of damage.

 The Chernobyl virus, in particular, draws a parallel to the Y2K problem
because it is a
 "date-activated" virus. A hacker created a program that was triggered
when computer clocks hit
 the anniversary of the Soviet nuclear plant meltdown, one of the
technology world's worst-ever
 disasters.

 Y2K already appears to be inspiring a wave of hackers who like to
create digital time bombs.

 "We've been monitoring various virus-writing newsgroups (Internet
bulletin boards) and we've
 seen quite a few postings, with people discussing the fact they plan on
creating viruses that will
 begin striking during the millennium," said Network Associates'
Viveros.

 "We're already seeing lots of (Y2K hacker) postings," added SAIC's
Fortune.

 The programs that erase hard disk drives or cause system failures could
be implanted deeply
 within a user's system, where the remain hidden from sight until the
date change. Viveros said
 some systems managers may lock down their systems prematurely and miss
the hidden invaders.

 SAIC's Fortune said the programmers handling the heavy amounts of
programming to fix Y2K
 problems may have left "backdoor" openings for hackers to enter.

 One group reported to be targeting such openings is Streets, which
first hit City of London
 financial district computers on June 18.

 Space Rogue, editor of Hackernews (http://www.hackernews.com), an
Internet-based service that
 reports on hacking exploits, said the threat of such attacks is
probably overestimated because "it
 requires a lot more knowledge than most people have."

 Rogue said that attacks are "possible" but the security industry is
overplaying the threat to build
 up its own services. "Fear sells," said the editor.

 At Network Associates, Sol Viveros said it's important to raise the
alarm because it reminds
 computer users to prepare for potential problems. A global alert helped
dramatically reduce the
 impact of Melissa and other virus-type outbreaks this year. Once
notified of a threat, system
 administrators can shut down their systems and run anti-virus software.

 His company will be among the scores of software firms that will be
celebrating new year's this
 year with round-the-clock surveillance of customers' computers, trying
to spot threats before
 they cause too much damage.

 "It all boils down to security awareness," said SAIC's Fortune.

 (The NetTrends column appears weekly. If you have comments or
questions, you can send e-mail
 to dick.satran(at)reuters.com.)

 Swedish Firm Pumps Up Volume Of Online Music (Previous story)
 Internet: Rocky Road To Information Superhighway (Next story)

DECLARATION & DISCLAIMER
==========
CTRL is a discussion and informational exchange list. Proselyzting propagandic
screeds are not allowed. Substance�not soapboxing!  These are sordid matters
and 'conspiracy theory', with its many half-truths, misdirections and outright
frauds is used politically  by different groups with major and minor effects
spread throughout the spectrum of time and thought. That being said, CTRL
gives no endorsement to the validity of posts, and always suggests to readers;
be wary of what you read. CTRL gives no credeence to Holocaust denial and
nazi's need not apply.

Let us please be civil and as always, Caveat Lector.
========================================================================
Archives Available at:
http://home.ease.lsoft.com/archives/CTRL.html

http:[EMAIL PROTECTED]/
========================================================================
To subscribe to Conspiracy Theory Research List[CTRL] send email:
SUBSCRIBE CTRL [to:] [EMAIL PROTECTED]

To UNsubscribe to Conspiracy Theory Research List[CTRL] send email:
SIGNOFF CTRL [to:] [EMAIL PROTECTED]

Om

Reply via email to