Sobig Worm Aims to Turn PCs Into Spam Machines
Wed August 20, 2003 09:46 PM ET
By Elinor Mills Abreu
SAN FRANCISCO (Reuters) - Several Internet worms that have besieged computers for over a week played havoc again on Wednesday, including one called Sobig.F whose aim was to turn PCs into spam machines and was believed to be the fastest growing virus ever, experts said.
Sobig.F drops software onto infected Windows computers that open them to be used later for distributing Internet spam -- unwanted e-mails and product promotions, experts said. It also represents a new trend in converging e-mail spamming and virus software writing, they said.
"We believe (Sobig.F) has been written by a spammer or spammers" looking for ways to get past spam filters, said Mikko Hypponen, manager of anti-virus research for Finnish security firm F-Secure. "For once, we have a clear motive for a virus -- money."
Security experts said it was difficult to ascertain how many computers had been infected by the Sobig.F worm. Worms are viruses that spread through networks.
Internet service America Online, however, said it blocked about 11.5 million copies while security firm MessageLabs stopped more than 1 million copies within the first 24 hours and dubbed Sobig.F the fastest growing e-mail virus ever.
Sobig.F hit the computing world as corporations were still recovering from several worms that spread through holes in Microsoft Corp.'s Windows operating systems, including the "Blaster" worm. Also called "LovSan," it has infected and crashed hundreds of thousands of computers since last week.
The "Welchia" or "Nachi" worm, which surfaced on Monday, infected 72,000 computers used by the U.S. Navy and Marine Corps and crippled Air Canada's reservation counters and call centers.
CSX Transportation said on Wednesday that a virus infection had slowed its dispatching and signal systems, forcing it to halt passenger and freight train traffic, including the morning commuter train service in Washington, D.C.
NEW TREND, SPAM-VIRUS CONVERGENCE
Sobig.F hit home users particularly hard, experts said. It arrives in an e-mail with an attachment that when opened infects the computer and sends itself on to other victims using a random e-mail address from the address book, making it difficult to trace the worm back to its source.
The Sobig family of worms represents a new trend in the convergence of worm and spam techniques for more widespread and faster deployment, experts said.
Virus writers are utilizing software that spammers employ to send bulk spam messages. Conversely, spammers are starting to use methods incorporated by virus writers to spread their messages and avoid detection, said Brian Czarny, marketing director at e-mail security company MessageLabs.
Previous Sobig versions loaded a program onto infected PCs that broadcast spam to other computers, thus turning the PCs into so-called "spam relays."
Sobig.F downloads a Trojan onto infected computers, which could later be remotely activated to send spam, experts said.
"There are computers scanning the Internet for open relays so spammers can jump from one machine to the next and be able to send millions of spam messages and have them not be traced back to them or be blocked," said Jimmy Kuo, research fellow at anti-virus vendor Network Associates Inc.
Sobig.F, which expires on Sept. 10, is spreading quickly because it sends multiple e-mails simultaneously and spreads to other computers on a shared network, said experts, who predict there will be another version in the near future. (Additional reporting by Bernhard Warner in London and Charles Grandmont in Montreal.)
Sobig Worm turns PCs into Spam Factories
Moderator: Thanas
- Darth Fanboy
- DUH! WINNING!
- Posts: 11182
- Joined: 2002-09-20 05:25am
- Location: Mars, where I am a totally bitchin' rockstar.
Sobig Worm turns PCs into Spam Factories
"If it's true that our species is alone in the universe, then I'd have to say that the universe aimed rather low and settled for very little."
-George Carlin (1937-2008)
"Have some of you Americans actually seen Football? Of course there are 0-0 draws but that doesn't make them any less exciting."
-Dr Roberts, with quite possibly the dumbest thing ever said in 10 years of SDNet.
-George Carlin (1937-2008)
"Have some of you Americans actually seen Football? Of course there are 0-0 draws but that doesn't make them any less exciting."
-Dr Roberts, with quite possibly the dumbest thing ever said in 10 years of SDNet.
-
- Jedi Master
- Posts: 1063
- Joined: 2002-08-13 04:52am
-
- Worthless Trolling Palm-Fucker
- Posts: 1065
- Joined: 2003-01-26 01:08pm
- Location: paul.barlow@embracerofdarkness.co.uk
- Darth Fanboy
- DUH! WINNING!
- Posts: 11182
- Joined: 2002-09-20 05:25am
- Location: Mars, where I am a totally bitchin' rockstar.
threa bumped, if only to give concerned computer users one last peek if they want.
"If it's true that our species is alone in the universe, then I'd have to say that the universe aimed rather low and settled for very little."
-George Carlin (1937-2008)
"Have some of you Americans actually seen Football? Of course there are 0-0 draws but that doesn't make them any less exciting."
-Dr Roberts, with quite possibly the dumbest thing ever said in 10 years of SDNet.
-George Carlin (1937-2008)
"Have some of you Americans actually seen Football? Of course there are 0-0 draws but that doesn't make them any less exciting."
-Dr Roberts, with quite possibly the dumbest thing ever said in 10 years of SDNet.
-
- Jedi Master
- Posts: 1063
- Joined: 2002-08-13 04:52am
- Darth Wong
- Sith Lord
- Posts: 70028
- Joined: 2002-07-03 12:25am
- Location: Toronto, Canada
- Contact:
That doesn't work on brand-new viruses, unless you're lucky enough not to get them until after the virus scanner companies identify the new infestation (note: this does not occur until many people have ALREADY been infected) and put out updates which you have already received and installed.Thunderfire wrote:This is a mail based Virus AFAIK. Getting a good Virus Scanner and Mail Filter is a better idea.Embracer Of Darkness wrote:*Fires up the firewalls and checks for uptdates.*
I'm getting sick of these worms.
Best solution is not to use Windows for E-mail. Use it for games or video editing or other things, but Internet activities should be carried out on a *nix platform if you're genuinely worried about security. And if you must use Windows, then DON'T USE OUTLOOK EXPRESS, for fuck's sake.
"It's not evil for God to do it. Or for someone to do it at God's command."- Jonathan Boyd on baby-killing
"you guys are fascinated with the use of those "rules of logic" to the extent that you don't really want to discussus anything."- GC
"I do not believe Russian Roulette is a stupid act" - Embracer of Darkness
"Viagra commercials appear to save lives" - tharkûn on US health care.
http://www.stardestroyer.net/Mike/RantMode/Blurbs.html
"you guys are fascinated with the use of those "rules of logic" to the extent that you don't really want to discussus anything."- GC
"I do not believe Russian Roulette is a stupid act" - Embracer of Darkness
"Viagra commercials appear to save lives" - tharkûn on US health care.
http://www.stardestroyer.net/Mike/RantMode/Blurbs.html
- His Divine Shadow
- Commence Primary Ignition
- Posts: 12791
- Joined: 2002-07-03 07:22am
- Location: Finland, west coast
My company's network escaped Sobig.F atleast, the installment of a virus scanner in the mailserver has greatly helped, also is nice when we have another layer of virus scanners on every workstation, and a draconian firewall.
There was a virus warning yesterday, when I was supposed to have the day off, apparently, a part of the nimda virus(only a part so it was inactive) had gotten left after the last sweep.
We did however get messages fom other mailservers that we had supposedly sent them Sobig.F, bullshit, I went through every computer with a program that was designed to find Sobig.F and remove it, every computer was clean.
Ofcourse Sobig.F can fake from headers so it wasn't really from us it came.
There was a virus warning yesterday, when I was supposed to have the day off, apparently, a part of the nimda virus(only a part so it was inactive) had gotten left after the last sweep.
We did however get messages fom other mailservers that we had supposedly sent them Sobig.F, bullshit, I went through every computer with a program that was designed to find Sobig.F and remove it, every computer was clean.
Ofcourse Sobig.F can fake from headers so it wasn't really from us it came.
Those who beat their swords into plowshares will plow for those who did not.
You ain't lying there, hoss.And if you must use Windows, then DON'T USE OUTLOOK EXPRESS, for fuck's sake.
The email program that I use is called Calypso Email.
Not only does it handle multiple accounts easily, it lets you turn off the goddamn HTML and scripting in the preview pane. It converts HTML messages to attached files that you can then look through the source code before you open them.
HTML and scripting are the reasons why OE is a virus and trojan magnet.
Best of all, it's now free
Download it from here and try it .
"You say that it is your custom to burn widows. Very well. We also have a custom: when men burn a woman alive, we tie a rope around their necks and we hang them. Build your funeral pyre; beside it, my carpenters will build a gallows. You may follow your custom. And then we will follow ours."- General Sir Charles Napier
Oderint dum metuant
Oderint dum metuant
- Crayz9000
- Sith Apprentice
- Posts: 7329
- Joined: 2002-07-03 06:39pm
- Location: Improbably superpositioned
- Contact:
Not really. The reason that Outlook Expres is a virus and trojan magnet is because Microsoft did not correctly implement the MIME standards. Then, in a flash of genius, they left scripting enabled by default.Glocksman wrote:HTML and scripting are the reasons why OE is a virus and trojan magnet.
Mozilla Mail (now Thunderbird) also supports HTML, but scripts are turned off by default, and it implemented MIME *correctly*.
A Tribute to Stupidity: The Robert Scott Anderson Archive (currently offline)
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF
- His Divine Shadow
- Commence Primary Ignition
- Posts: 12791
- Joined: 2002-07-03 07:22am
- Location: Finland, west coast
Interesting. The only reason I use Calypso (other than it's free) is because it allows me to turn all of that off.Mozilla Mail (now Thunderbird) also supports HTML, but scripts are turned off by default, and it implemented MIME *correctly*
One of my quirks is that I just don't like HTML email, and unless it's from someone I know, I delete it unread.
"You say that it is your custom to burn widows. Very well. We also have a custom: when men burn a woman alive, we tie a rope around their necks and we hang them. Build your funeral pyre; beside it, my carpenters will build a gallows. You may follow your custom. And then we will follow ours."- General Sir Charles Napier
Oderint dum metuant
Oderint dum metuant
- The Yosemite Bear
- Mostly Harmless Nutcase (Requiescat in Pace)
- Posts: 35211
- Joined: 2002-07-21 02:38am
- Location: Dave's Not Here Man
I use OE and my solution is simple. I delete ALL e-mail from people I don't know and if I recieve an attachment without prior warning of said attachment, I isolate the e-mail until I can contact the person.Darth Wong wrote:Best solution is not to use Windows for E-mail. Use it for games or video editing or other things, but Internet activities should be carried out on a *nix platform if you're genuinely worried about security. And if you must use Windows, then DON'T USE OUTLOOK EXPRESS, for fuck's sake.
"If the facts are on your side, pound on the facts. If the law is on your side, pound on the law. If neither is on your side, pound on the table."
"The captain claimed our people violated a 4,000 year old treaty forbidding us to develop hyperspace technology. Extermination of our planet was the consequence. The subject did not survive interrogation."
"The captain claimed our people violated a 4,000 year old treaty forbidding us to develop hyperspace technology. Extermination of our planet was the consequence. The subject did not survive interrogation."
I use Outlook Express on three separate PC's (with a total of 5 e-mail addresses) and have not had an infection in well over two years.
Considering that most of the people who get infected with viruses are ignorant of even basic security and OS concepts: exactly how do you expect them to run a Linux distro? And if they do have this knowledge, they should already know how to keep viruses off their PCs.
I find Windows works just fine for me 99% of the time, and I can't really complain about the massive security flaws in MS products because they make us money (Hell, Blaster has created a huge amount of business for us).
Considering that most of the people who get infected with viruses are ignorant of even basic security and OS concepts: exactly how do you expect them to run a Linux distro? And if they do have this knowledge, they should already know how to keep viruses off their PCs.
I find Windows works just fine for me 99% of the time, and I can't really complain about the massive security flaws in MS products because they make us money (Hell, Blaster has created a huge amount of business for us).
OE had the autoexecute nonsense, but nowadays that's off by default. However, most users are fairly computer illiterate and will open attachments without considering what it might be. My dad got a couple Sobig.E e-mails but didn't open it (and uses NS Messenger 7 anyways).
I personally use Ximian Evolution 1.4, which lets you turn off image linking in HTML mail - quite nice. No fucking up the formatting of a message while also protecting you from spam-verification images.
I personally use Ximian Evolution 1.4, which lets you turn off image linking in HTML mail - quite nice. No fucking up the formatting of a message while also protecting you from spam-verification images.
-
- Worthless Trolling Palm-Fucker
- Posts: 1065
- Joined: 2003-01-26 01:08pm
- Location: paul.barlow@embracerofdarkness.co.uk
Kmail does not enable HTML. By default, it shows you the source, and allows you to render it after checking it's contents.
ah.....the path to happiness is revision of dreams and not fulfillment... -SWPIGWANG
Sufficient Googling is indistinguishable from knowledge -somebody
Anything worth the cost of a missile, which can be located on the battlefield, will be shot at with missiles. If the US military is involved, then things, which are not worth the cost if a missile will also be shot at with missiles. -Sea Skimmer
George Bush makes freedom sound like a giant robot that breaks down a lot. -Darth Raptor
- Crayz9000
- Sith Apprentice
- Posts: 7329
- Joined: 2002-07-03 06:39pm
- Location: Improbably superpositioned
- Contact:
Mozilla Thunderbird (and the mail in version 1.3 and above) have the same feature.phongn wrote:I personally use Ximian Evolution 1.4, which lets you turn off image linking in HTML mail - quite nice. No fucking up the formatting of a message while also protecting you from spam-verification images.
A Tribute to Stupidity: The Robert Scott Anderson Archive (currently offline)
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF
- haas mark
- Official SD.Net Insomniac
- Posts: 16533
- Joined: 2002-09-11 04:29pm
- Location: Wouldn't you like to know?
- Contact:
So is there a way to get rid of this?
~ver
~ver
Robert-Conway.com | lunar sun | TotalEnigma.net
Hot Pants à la Zaia | BotM Lord Monkey Mod OOK!
SDNC | WG | GDC | ACPATHNTDWATGODW | GALE | ISARMA | CotK: [mew]
Formerly verilon
R.I.P. Eddie Guerrero, 09 October 1967 - 13 November 2005
Hot Pants à la Zaia | BotM Lord Monkey Mod OOK!
SDNC | WG | GDC | ACPATHNTDWATGODW | GALE | ISARMA | CotK: [mew]
Formerly verilon
R.I.P. Eddie Guerrero, 09 October 1967 - 13 November 2005
-
- Jedi Master
- Posts: 1063
- Joined: 2002-08-13 04:52am
Filtering based on the suffix of the attachment should work against mostDarth Wong wrote: That doesn't work on brand-new viruses, unless you're lucky enough not to get them until after the virus scanner companies identify the new infestation (note: this does not occur until many people have ALREADY been infected) and put out updates which you have already received and installed.
mail viruses.
- Vertigo1
- Defender of the Night
- Posts: 4720
- Joined: 2002-08-12 12:47am
- Location: Tennessee, USA
- Contact:
This folks, is why you should never use Outlook, and open attachments from strange e-mails, no matter who sent it. Hell, running a mail client that doesn't allow you to disable HTML rendering is just ASKING to get bit.
For those that don't already know, to kill HTML rendering in Mozilla Mail (aka Thunderbird) just do the following:
Click view, click on Message Body As, and select "Plain Text". Now all you'll get is the source code. (hell, I'm so anal that I delete any HTML e-mail on sight, no matter who sent it.)
For those that don't already know, to kill HTML rendering in Mozilla Mail (aka Thunderbird) just do the following:
Click view, click on Message Body As, and select "Plain Text". Now all you'll get is the source code. (hell, I'm so anal that I delete any HTML e-mail on sight, no matter who sent it.)
"I once asked Rebecca to sing Happy Birthday to me during sex. That was funny, especially since I timed my thrusts to sync up with the words. And yes, it was my birthday." - Darth Wong
Leader of the SD.Net Gargoyle Clan | Spacebattles Firstone | Twitter
Leader of the SD.Net Gargoyle Clan | Spacebattles Firstone | Twitter
Even if the email is from someone you know, don't trust it. Many viruses read the victim's address book and mail from the victim's address.
ah.....the path to happiness is revision of dreams and not fulfillment... -SWPIGWANG
Sufficient Googling is indistinguishable from knowledge -somebody
Anything worth the cost of a missile, which can be located on the battlefield, will be shot at with missiles. If the US military is involved, then things, which are not worth the cost if a missile will also be shot at with missiles. -Sea Skimmer
George Bush makes freedom sound like a giant robot that breaks down a lot. -Darth Raptor