Home  |  Forums  |  914 Info  |  Blogs
 
914World.com - The fastest growing online 914 community!
 
Porsche, and the Porsche crest are registered trademarks of Dr. Ing. h.c. F. Porsche AG. This site is not affiliated with Porsche in any way.
Its only purpose is to provide an online forum for car enthusiasts. All other trademarks are property of their respective owners.
 

Welcome Guest ( Log In | Register )

> OT new email worm, story from the AP Jan 27
seanery
post Jan 27 2004, 08:40 AM
Post #1


waiting to rebuild whitey!
***************

Group: Retired Admin
Posts: 15,852
Joined: 7-January 03
From: Indy
Member No.: 100
Region Association: None



E-mail worm spreading fast


Associated Press
January 27, 2004


SAN JOSE, Calif. -- A malicious program attached to seemingly innocuous e-mails was spreading quickly over the Internet on Monday, clogging network traffic and potentially leaving hackers an open door to infected personal computers.

The worm, called "Mydoom" or "Novarg" by antivirus companies, usually appears to be an e-mail error message. A small file is attached that, when launched on computers running Microsoft Corp.'s Windows operating systems, can send out 100 infected e-mail messages in 30 seconds to e-mail addresses stored in the computer's address book and other documents.

The attack was first noticed Monday afternoon. Within hours, thousands of e-mails were clogging networks, said Vincent Gullotto, vice president of Network Associates' antivirus emergency response team.

Besides sending out e-mail, the program appears to open up a backdoor so that hackers can take over the computer later.

"As far as I can tell right now, it's pretty much everywhere on the planet," Gullotto said.

Security software experts were scrambling to decrypt the details of the malicious program and were arriving at different conclusions.

Symantec, an antivirus company, said the worm appeared to contain a program that logs keystrokes on infected machines. It could collect username and passwords of unsuspecting users and distribute them to strangers.

Network Associates did not find the keylogging program.

The worm also appears to deposit its payload into folders open to users of the Kazaa file-sharing network. Remote users who download those files and run them could be infected.

Symantec also found code that would flood The SCO Group Inc.'s Web site with requests in an attempt to crash its server, starting Feb. 1. SCO's site has been targeted in other recent attacks because of its threats to sue users of the Linux operating system in an intellectual property dispute. An SCO spokesman did not return a telephone call for comment Monday.

Overall, the computer security firm Central Command confirmed 3,800 infections within 45 minutes of initial discovery.

"This has all the characteristics of being the next big one," said Steven Sundermeier, Central Command's vice president of products and services.

It appeared to first target large companies in the United States -- and their large address books -- but quickly spread internationally, said David Perry, global director of education at the antivirus software firm Trend Micro.

Unlike other mass-mailing worms, Mydoom does not attempt to trick victims by promising nude pictures of celebrities or mimicking personal notes. Instead, one of its messages reads: "The message contains Unicode characters and has been sent as a binary attachment."

"Because that sounds like a technical thing, people may be more apt to think it's legitimate and click on it," said Steve Trilling, Symantec's senior director of research.

Subject lines also vary. The attachments have ".exe," ".scr," ".cmd" or ".pif" extensions, and may be compressed as a Zip file.

Microsoft offers a patch of its Outlook e-mail software to warn users before they open such attachments or prevent them from opening them altogether. Antivirus software also stops infection.

Christopher Budd, a security program manager with Microsoft, said the worm does not appear to take advantage of any Microsoft product vulnerability.

"This is entirely a case of what we would call social engineering -- enticing users to take actions that are not in their best interest," he said.

He said the software giant was working with other companies to learn more about the worm, but that, as of yet, the information about the worm was still "very spotty." The Redmond, Wash.-based company was encouraging users to take precautions such as using an Internet firewall and using up-to-date antivirus software.

Mydoom isn't the first mass-mailing virus of the year. Earlier this month, a worm called "Bagle" infected computers but seemed to die out quickly. So far, it's too early to say whether Mydoom will continue to be a problem or peter out, experts said.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

Posts in this topic
seanery   OT new email worm   Jan 27 2004, 08:40 AM
SirAndy   yupp, got it today on one of my "dead" accounts. ...   Jan 27 2004, 11:38 AM
seanery   I just got notice that Norton has already updated ...   Jan 27 2004, 11:41 AM
SirAndy   <...   Jan 27 2004, 11:54 AM
Howard R   I received 3 emails with it at the office yesterda...   Jan 27 2004, 11:57 AM
smrz914   So I have a question about these worms and viruses...   Jan 27 2004, 04:55 PM
SirAndy   <...   Jan 27 2004, 05:14 PM
Gint   :agree: Most whole-heartedly I couldn't hav...   Jan 27 2004, 05:37 PM
smrz914   Well i don't have any info in my outlook and I...   Jan 27 2004, 06:07 PM
SirAndy   <...   Jan 27 2004, 06:11 PM
Gint   Friends don't let friends use outlook! At...   Jan 27 2004, 07:49 PM
campbellcj   We got a whole ton of these today. Be sure to upd...   Jan 27 2004, 11:22 PM
mikester   We started getting it late yesterday. The Symantec...   Jan 27 2004, 11:26 PM


Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 



- Lo-Fi Version Time is now: 17th May 2024 - 11:41 PM