Tilted Forum Project Discussion Community

Tilted Forum Project Discussion Community (https://thetfp.com/tfp/)
-   General Discussion (https://thetfp.com/tfp/general-discussion/)
-   -   Mydoom Worm Sets Speed Records (https://thetfp.com/tfp/general-discussion/43210-mydoom-worm-sets-speed-records.html)

Glad-I-Ate-Her 01-27-2004 03:55 PM

Mydoom Worm Sets Speed Records
 
Here is some info about the latest email threat. Protect yourselves.

Glad

~~~~~~~~~~~~~~~~~~~
http://www.pcworld.com/news/article/0,aid,114461,00.asp

Mydoom Sets Speed Records

New worm is spreading faster than Sobig.F, experts say.

PC World
Paul Roberts, IDG News Service
Tuesday, January 27, 2004
Mydoom, a new computer virus spreading by e-mail, is breaking records for new infections, antivirus vendors and security companies say.

Infected e-mail messages carrying the Mydoom virus, also known as "Shimgapi" and "Novarg," have been intercepted from over 142 countries and now account for one in every 12 e-mail messages, according to Mark Sunner, chief technology officer at e-mail security company MessageLabs.

That surpasses the Sobig.F virus record, which appeared last August and, at its peak, was found in one of every 17 messages intercepted by MessageLabs, he says.

Since first detecting the new virus at 1:00 PM GMT on Monday, MessageLabs intercepted almost 1 million infected e-mail messages carrying the virus, Sunner says.

The virus has "followed the sun," hitting hard in the U.S. and Canada late on Monday, then working its way through Asia and Europe on Tuesday, he says.

F-Secure of Helsinki estimates that around 100,000 computers have been infected with Mydoom so far, says Mikko Hypponen, manager of antivirus research at F-Secure.

Antivirus experts expect another large wave of infections in the U.S. and Canada on Tuesday morning, as workers who missed the virus late Monday return to their desks, he says.

Tech Talk
The worm arrives as a file attachment in an e-mail with a variety of senders and subjects, such as "Hello," and "test." The message body is often technical sounding, imitating the look and feel of an automatically generated message from an e-mail server, Sunner says.

For example, some e-mail messages telling recipients that "the message contains unicode characters and has been sent as a binary attachment," or "The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment."

Users who click on the attachment, which uses a variety of file extensions such as ZIP, SCR, EXE, and PIF, are infected with the virus.

The technical pitch is a new twist on so-called "social engineering" techniques used by virus writers to trick users into opening malicious file attachments. Mydoom's authors may have been counting on the fact that people trust the authenticity of computer generated messages more than those purporting to come from other humans, Sunner says.

Mimicking the language of a computer-generated administrative message may have also helped Mydoom spread within large corporations, where employees are used to receiving such messages from administrative systems, according to David Perry, public education director at antivirus company Trend Micro.

Going to Work
Trend Micro saw evidence on Monday of infections from 12 of the Fortune 100 companies, he says.

Once inside such companies, Mydoom could use the enormous bandwidth of those corporate networks and huge e-mail address books as a "springboard" to the rest of the Internet, Perry says.

While Mydoom has shattered Sobig.F records, in many ways the two viruses are the same, antivirus experts agree.

Both viruses scan infected computers for e-mail addresses that are then targeted by infected e-mail. Also, both Sobig.F and Mydoom are small and contain highly efficient SMTP engines for sending out copies of themselves. The efficiency of their mail engines means that even a small number of infections can generate a massive amount of e-mail traffic, Hypponen says.

Finally, both Sobig.F and Mydoom contain a Trojan horse program that gives remote attackers full control of the infected system, he says.

In the case of Sobig.F, experts theorized that the virus was being used to assemble "zombie" networks of machines for distributing spam e-mail. A similar motive may be behind Mydoom, though the virus writer's intentions are not yet clear, says Perry.

Turbine 01-27-2004 04:30 PM

Why is it that whenever these virii outbreaks occur I never get a single copy of it in my mailbox?

cheerios 01-27-2004 04:35 PM

'cuz you filter it, or your ISP does?

merkerguitars 01-27-2004 04:35 PM

Hehe thank god my isp has email protection built in :)

Reese 01-27-2004 04:38 PM

Turbine, maybe because no one has you in their address book.

I'm just wondering why this is spreading so much faster, haven't these people learned anything from the huge infections that keep sweeping the world.

sailor 01-27-2004 05:49 PM

Quote:

Originally posted by cybermike
Turbine, maybe because no one has you in their address book.

I'm just wondering why this is spreading so much faster, haven't these people learned anything from the huge infections that keep sweeping the world.

I keep wondering the same thing. This virus has all but choked our campus email. I have gotten several infected emails, but Im not one to open random attachments.

ratbastid 01-27-2004 05:51 PM

You know, I hate email virii as much as the next guy, but... This sucker is time-bombed to launch a massive DDoS against SCO. So I'm a little of-two-minds about it....

I hate to condone this sort of behavior. At the same time, it's going to hurt SCO.

brandon11983 01-27-2004 06:21 PM

This is why I'm glad I don't have any friends. I never get any shit like this.

sailor 01-27-2004 07:18 PM

Quote:

Originally posted by ratbastid
You know, I hate email virii as much as the next guy, but... This sucker is time-bombed to launch a massive DDoS against SCO. So I'm a little of-two-minds about it....

I hate to condone this sort of behavior. At the same time, it's going to hurt SCO.

I felt the same at first, but then I realized that the last thing the linux community needs in this fight is the bad press that this will generate. Make no mistake, this virus, while entertaining, is a bad thing.

mokle 01-27-2004 07:24 PM

Quote:

Originally posted by ratbastid
You know, I hate email virii as much as the next guy, but... This sucker is time-bombed to launch a massive DDoS against SCO. So I'm a little of-two-minds about it....

I hate to condone this sort of behavior. At the same time, it's going to hurt SCO.

That doesn't really matter. SCO deservers to be hurt in the courts. Virii hurt everyone in the process.

ApexgriN 01-27-2004 07:27 PM

Yay for MAC OSX!

suckers! ;)

grumpyolddude 01-27-2004 09:23 PM

So, what part of "Don't open email from strangers" does the world not understand yet?

fik 01-27-2004 10:06 PM

Quote:

Originally posted by grumpyolddude
So, what part of "Don't open email from strangers" does the world not understand yet?
Well a lot of viruses disguise the infected email into looking like it came from someone you know, someone that has your email in their address book.

Bivens 01-27-2004 10:53 PM

Quote:

Originally posted by ApexgriN
Yay for MAC OSX!

suckers! ;)

Your time will come.

Lebell 01-27-2004 10:58 PM

sigh,

just don't open attachments.

I never do, unless I confirm from the sender it's something I need.

skysooner 01-28-2004 07:19 AM

I got one at work, and they filter pretty heavily. Luckily I realized that an e-mail that says Hi and has a zip file attached from someone I don't know wasn't to be trusted. I passed it to IT, and they had most of it filtered pretty quickly.

omega2K4 01-28-2004 07:39 AM

You deserve to get a virus if you open e-mail attachments.

KWSN 01-28-2004 08:27 AM

Quote:

Originally posted by ApexgriN
Yay for MAC OSX!

suckers! ;)

Good for you guys, you don't get the virus!

All you need is a working OS now!

numist 01-28-2004 08:30 AM

My friend received the email in linux, realized what it was, and installed windows just so he could be part of the ddos.

I think I may contract it myself for the same purpose.

After all, the ends justify te means, do they not? :p
and KWSN - HAHAHAHAHAHA :lol:

bermuDa 01-28-2004 09:47 AM

A client of mine had about 35 quarantined e-mails that might've had the virus. No damage was done but he was still freaked out over it.

Redlemon 01-28-2004 09:48 AM

The damn thing is also inventing its own TO addresses. I have a domain, and I'm receiving about 10 a day to addresses that I've never set up.

tinfoil 01-28-2004 11:21 AM

Indeed it is, redlemon.

This one came on fast and tapered off fast as well. At work here, the gateway was picking them off at a rate of 6 a minute at it's peak, then tapering off to about 1 a minute for most of yesterday night and this AM.

All of a sudden they stopped. Very wierd.

hawkeye 01-28-2004 11:29 AM

Quote:

Originally posted by KWSN
Good for you guys, you don't get the virus!

All you need is a working OS now!

*rereads*
*falls off chair laughing*

Crack 01-28-2004 05:34 PM

Quote:

Originally posted by grumpyolddude
So, what part of "Don't open email from strangers" does the world not understand yet?
Hell, open all e-mails from strangers! Just don't open the attachment, that's all.

merkerguitars 01-28-2004 09:23 PM

Quote:

Originally posted by grumpyolddude
So, what part of "Don't open email from strangers" does the world not understand yet?
Yeah I don't get some people.....it's common sense that I wish most people had :(

runman 01-29-2004 02:33 AM

Go out and buy a decent operating system eh? You could drive a truck throught the sloppy mess that is windoze!

one OS to rule them all... X

teseniarkc 01-29-2004 05:59 AM

I think SCo deserves this. How are they going to sue when Linux is virtually built by everyday users that download it off of the internet and send back improvements to make the OS better. WTF! Every OS that I have seen steals from the other. Look at Bill Gates for example. He lied, cheated, and now he is rich. That is the way this world works. I don't know how this is going to be proved the amount of line code there is.

indiretto 01-31-2004 12:38 AM

What is SCO? A virus hit my comp yesterday. I don't know if it was this one, I rarely use e-mail but I have a friend who was checking his on my computer yesterday. What ever hit my computer fraged my whole computer. I lost everything and had to write zeros to my HD, bummer for me. So far my HD and computer seem to be doing ok with the reinstall though. As for all you Linux users out there I'm still playing with it. I’m impressed with how far Linux has come in the last few years; soon it will be as easy to use, and as compatible as Windows, its pretty close now, keep up the good work.

Jizzosh 01-31-2004 01:49 PM

Wow, I'm soo glad I don't do the security engineer thing anymore. Otherwise I'd be looking at those 12 hour days.

viper11885 01-31-2004 02:16 PM

Luckily, I don't open any attachments which I don't expect. Even from friends. But we usually do things over icq so I know what is going to be sent as an attachment by email. Helps keep things more secure as I don't need to open any emails at all that I don't expect.

riptide4070 01-31-2004 06:40 PM

no virus on my cpu, better knock on wood though

soccerchamp76 01-31-2004 07:11 PM

Could someone explain this thing between ddos, SCO, Linux, Windows, etc?
I have read all of these in this thread and I am very lost. What was the virus designed for? And what does it do on the site.


Edit: Googled and found out that it is an attack on the SCO site because of the lawsuit between Linux open-sourcer's and SCO.

If you have the virus, how will you know you have it and what does it do?

santafe5000 01-31-2004 08:39 PM

Guess this could also explain the slowness of the net foe the pasrt few days. My pages have been very slow in loading. Several times i couldn't log onto MSN. Lots of emails clogging the system. Haven't gotten any of the e-mails myself. Good VS program.

punx1325 02-01-2004 12:58 PM

My internet at school goes down daily because of this virus. The bastards that create these viruses need to be drug out in the street and shot. I have 2 online classes and can never get any work done. What is wrong with these people who have nothing better to do than make other peoples life hell???

Blistex 02-01-2004 10:19 PM

When are people gonna get it through their head that jokes attached to e-mails are seldom funny and are not worth the cost of re-installing your pc and having to explain to the boss why every computer in the office is now fragged!

Women are the worst. I used to have a summer job at an office and every day they'd open the same attachments and every day norton would go ape shit trying to keep up.

jwells777 02-01-2004 10:32 PM

Honestly in the past, if you didn't want your computer infected, it was relatively easy to avoid being infected. These days...computers are infected so quickly and easily. This summer I had to reinstall my research computer due to the blaster worm. While reinstalling, and before I could apply the patch, the computer was infected again...so irritating.


All times are GMT -8. The time now is 04:37 AM.

Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0 PL2
© 2002-2012 Tilted Forum Project


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360