Skip Links

MyDoom makes it past execs

By Winn Schwartau, Network World
February 23, 2004 12:06 AM ET
Schwartau
  • Print

Recently I got a panicky phone call from Henry, the security administrator of a California hospital I have done business with for years. It seems the hospital had been hit by a nasty case of the MyDoom virus that began its explosive growth during the last week of January. After attempting to calm Henry down, I asked how MyDoom got released inside the hospital, which has about 2,000 desktops, 1,000 remote machines, and the usual assortment of Windows and Linux servers.

"That's the really bad part," he harrumphed. "Our execs did it."

"Your execs? What do you mean they did it?"

"They clicked."

"No!" I was flabbergasted. "They clicked on an attachment that says, 'Virus detected, do not open'?"

"Yes."

"But what about your corporate security policy we spent so much time on, which clearly states, 'Do not click on unknown attachments'?"

"They ignored it," he sighed. "Five of them."

Five executives in his hospital had clicked on MyDoom - and brought the e-mail system to a grinding halt. I thought about this for a second and postulated, "You know, Henry, if you or some of your desktop users had done the same thing, you would all be hung out to dry, at least according to your corporate policies. I suppose, then, our security awareness program isn't doing as well as we thought?"

"No, quite the opposite, in fact!" Henry sounded more upbeat now. "Over a hundred from our general user community called the help desk and asked what to do. The staff did their part; the execs failed us."

I heard similar stories from several other large organizations and frankly was astounded. The corporate executives who demand IT perfection from their administrators want 100% availability on all services and expect everyone in their company to follow security policy - these are the people at the root of the problem.

When I heard that on Feb. 2 China reported hundreds of thousands of computers infected with MyDoom, I could understand. China has a low level of security awareness and a widespread absence of efficient anti-virus software among its 78 million online population; thus, it is especially vulnerable to worm attacks. But in the U.S., where executives authorize the spending of tens of thousands of dollars and more annually to manage effective anti-virus defenses and educate their online user base, I am sorry - there is no excuse for falling victim to MyDoom.

Too many corporate executives set down edicts, contract out the security awareness services and then ignore their own advice. They expect everyone else to do the dirty work.

This is a patently unacceptable approach to security and just goes to show how much we in the security world depend on the average IT user to help protect networks. I can't buy the argument "I didn't know about it" as a valid excuse to misbehave on your own network and click on an infected attachment, even if it did come from your closest friend.

That's part of how the bad guys are getting to us: through social engineering. They are preying upon the fact that we like to trust our friends, and we like to trust the e-mails they send us.

  • Print
What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?

Videos

rssRss Feed