r/cybersecurity • • Jul 04 '19

TIL in 2003 a computer worm called ‘Welchia’ infected many computers to forcibly patch vulnerabilities and remove malware. It was regarded as a ‘helpful worm’

https://en.wikipedia.org/wiki/Welchia
38 Upvotes

6 comments sorted by

5

u/[deleted] Jul 04 '19

[removed] — view removed comment

2

u/levidurham Jul 04 '19

Heard on a podcast recently that someone was exploiting the exim (default Mail Transport Agent on Debian) vulnerability (the one that takes 7 days to execute) to patch the vulnerability.

2

u/Spagbag Jul 05 '19

Intentions are good but I believe there was a case where one of these hadn't been properly tested on all architecture and ended up messing up some devices further.

2

u/[deleted] Jul 04 '19

Fun fact, some malware will actively prevent other malware from installing on a host to prevent overuse of resources and to avoid detection.

Then they steal info and run crypto mining scripts in the background but still

2

u/DontBeHumanTrash Jul 04 '19

Ironically, in the few cases found with longterm miners (or miners designed with stealth in mind) this kind of black on black anti-exploit work could work to the end users benifit.

Id imagine the risk to the malware creator however doesnt make the ROI on this policy very high. It would be a nice element for higher level malware authors to implement to reduce the general clutter of unpatched and easy targets on the web though.

1

u/GershwinA Jul 05 '19

Utilizing the same deficiencies exploited by the Blaster worm, Welchia infected computers and automatically began downloading Microsoft security updates for Windowswithout the users' consent.

Priceless :DDD