Slashdot Mirror


Another Nasty Outlook Virus Strikes

Goldberg's Pants writes: "ZDNet and Wired are both reporting on a new virus that spreads via Outlook. Nothing particularly original there, except this virus is pretty unique both in how it operates, and what it does, such as emailing random documents from your harddrive to people in your address book, and hiding itself in the recycle bin which is rarely checked by virus scanners." I talked by phone with a user whose machine seemed determined to send me many megabytes of this virus 206k at a time; he was surprised to find that his machine was infected, as most people probably would be. The anti-virus makers have patches, if you are running an operating system which needs them.

388 comments

  1. Re:How long? by Anonymous Coward · · Score: 1

    I believe it was called the One-Half virus which was somewhat like this. It was even more insiduous because it installed itself in memory at boot time. Then it proceeded to slowly encrypt blocks of your hard drive over time. The memory resident portion decrypted them on the fly, keeping the user completely unaware.

    If you remove the virus, you can't easily get the encrypted blocks back. The only "safe" method to get rid of it was to back everything up to another machine while the virus was in memory, disinfect the backed up stuff, then reformat, then copy your data back over. Nasty.

    Of course luckily it's not an email virus so it doesn't have the ability to spread worldwide in a few hours...

  2. Re:solution: don't use outlook by Anonymous Coward · · Score: 1

    I have a better idea (not mine, though). Write a virus/worm/whatever that resets the region code on your DVD-ROM repeatedly, leaving it on, say, region 4. Then let the hardware manufacturers try to figure out what to do with hundreds of thousands of computer illiterate customers who are pissed that their DVD drive is horked. They manufacturers would just about have to release a firmware patch to reset/unlock them (yes, I realize such things already exist unofficially). I would do it myself, but I would just as soon not get thrown in jail. And I would worry about it not reaching "critical mass" and leaving just a few hundred people SOL.

  3. Re:There was an old DOS virus like that by Anonymous Coward · · Score: 1

    Woov. Nice.

    I once made one that stopped the mouse a few milliseconds, randomly (but it stopped doing it for a few minutes when you stopped moving). You ended up cleaning your mouse several times a day.

    I never put in the viral code, and only used it as a practical joke...

    Cheers,

    --fred

  4. Re:Sheesh... by Anonymous Coward · · Score: 1

    > The average luser will click on anything, regardless of whether its .vbs or .pl

    Ever heard of something called the 'execute permission bit' ?

    Cheers,

    --fred

  5. Re:It's the OS, stupid. by Anonymous Coward · · Score: 1

    Ever heard about 'local root exploits' ?

    This is what I do with untrusted executable atachment:

    /bin/rm -f attachment.exe

    Cheers,

    --fred

  6. Re:What does your post have to do with the OS? by Anonymous Coward · · Score: 1

    You sir are a dolt.
    You spout off how to do something but have no clue how to do it. You have to reboot win2k on exactly ONE occasion, adding the pc to a domain which can and in our environment is done when the machine is first imaged. Hell I believe that you can now combine multiple SP's and hotfixes and reboot only once. To run an executable with no permissions I simply unattach the file and right click on it and chose runas->guest. Simple No?

  7. Re:What does your post have to do with the OS? by Anonymous Coward · · Score: 1

    rightclick->runAs takes you quite a bit on the way already...

  8. Re:It's the culture, stupid. by Anonymous Coward · · Score: 2

    If microsoft cares so much about giving the users what they want, why don't they actually strive to create a situation where the users have what they want?

    What i mean: Users want the ability to run email attachments indiscriminately. They do not currently have this ability, not safely.

    Microsoft could make this safe. Microsoft could (at the LEAST, this could be done within the context of XP; create a user with no priviliges?) throw together something that would run executables attached to email in a sandbox that couldn't touch the hard drive or do anything "evil". Then the users would be happy.

    Hm. A secure sandbox that programs in emails or webpages can run inside of. You know what would be a good way to give the users this? Give them the ability to double click and run java applets from their email, then encourage joe cartoon and everyone to distribute their attachments as if for the java vm. Oh, wait, i just remembered-- Microsoft just struck java vm access from outlook for "security" reasons, didn't they? silly me. Well, i guess it's good to know that microsoft is doing something to send a signal that security is more important to them than the things the users frivolously want.

  9. Re:An observation... by Anonymous Coward · · Score: 2

    Perhaps you have no friends TO send you mail.

  10. Re:solution: don't use outlook by Anonymous Coward · · Score: 2

    Any mailer that displays even plain HTML as soon as you view the message can be attacked, and ones that do Javascript are INSANE.

    Don't be rediculous here. How can you say that ANY MAILER that renders HTML is vulnerable to an attack? Does that apply to my browser accessing my webmail account?

    Though Outlook may have some problems here, it is entirely acceptable to believe that a mailer can render HTML emails in a safe and protected way. And the same for Javascript - Javascript can be annoying, but the security holes it has introduced have not been severe. The security problems here are not inherent to HTML and Javascript, they are caused by poor mail clients. It is important to not confuse the problem.

  11. Re:solution: don't use outlook by mosch · · Score: 1
    No Unix mail program would ever do such a thing because it's so obviously stupid

    setup your mailcap files and use almost every unix mail app. WHOOPS, they autoexecute code too! hell, EMACS was one of the first apps to make the 'execute untrusted code' screwup.

    everything old is new again!

    --

  12. Re:unfortunately, by mosch · · Score: 2

    yeah, there are NO viruses for outlook express. oh wait, i was thinking of netscape on macintosh, my bad!

    --

  13. Re:How long? by abischof · · Score: 2

    F-Secure (the F-Prot people) have more information on One Half.

    Alex Bischoff

    --

    Alex Bischoff
    HTML/CSS coder for hire

  14. Re:These virus writers have no imagination... by Alan · · Score: 1

    I did hear of one that used your browser to sign a couple of petitions or something, popped up a messagebox to appologize for using your resources and thanking you for understanding, and then mailed itself off to everyone. Some sort of political activist or something. Interesting, but probably still a big annoyance.

    Glad I don't run an OS where the mail and browser are integrated so closly into the OS as to allow that sort of thing though ;)

  15. Media is now just as slow as about a decade ago by Alex+Belits · · Score: 3

    I have received the first email sent by that thing three days ago and reported some brief analysis to bugtraq, got a "rejected, send to incidents" response, sent to incidents, and apparently there is still nothing in the archives -- I have no idea why, incidents list posts all kinds of "I have seen a big spider hanging over my keyboard, I think he tried to hack me" stuff.

    .

    For everyone interested, messages with virus and extracted infected documents are here.

    --
    Contrary to the popular belief, there indeed is no God.
    1. Re:Media is now just as slow as about a decade ago by Caspuh · · Score: 1

      Several new virii are found every day. You can't expect bugtraq to start a thread or two for each one. That's for more specialized lists.

  16. Re:documents by caferace · · Score: 1
    >... but from all the stuff I received over the weekend, I noticed it's just the name of the document it uses... the actual content is the virus itself; an executable disguised as a document...

    I got it too, as a supposed .doc file. But when I opened it in a hex editor there was indeed what looked like legitimate content. Don't be too sure it's not a privacy concern.

  17. Re:These virus writers have no imagination... by jbuhler · · Score: 5

    > Why can't these virus writers do something cool?

    You don't want virus writers with imagination. You *really* don't. A truly imaginative virus writer would likely devote all sorts of creative energy toward thinking up nasty things to do to your computer.

    I'm still waiting for the trojan that silently installs itself, then once every day looks for spreadsheets on your system and randomly changes three numbers in every fifth file. Or perhaps it finds your Word documents and randomly removes the words "do not" from a few places. Or maybe it flips a few bits in your swap file, or munges your C++ compiler so that your programs randomly destroy the user's partition table one time out of a thousand. Maybe it sends death threats in your name to president@whitehouse.gov, or anonymously tells Microsoft that your company is pirating Windows.

    No, I'm quite happy with the current crop of dull, stolid, entirely *un*imaginative virus writers, thank you very much!

  18. Re:MacOS by Chris+Johnson · · Score: 3
    Depends on how you look at it.

    I'm on MacOS using _eudora_ and all these sorts of files are dead inanimate matter to me.

    Almost a megabyte of dead inanimate matter over a 56K modem just since this afternoon alone...

    I am _so_ _pissed_ _off_ at this crap. I've taken to spamcopping the victims, using this note to their postmasters (where applicible):

    "Please suspend this user's account. They are propagating the SirCam worm, and that must stop directly.
    -postmaster@airwindows.com"

    I have it as a clipping ready to be dragged into the spamcop personalize box, which is what I do when I am so overloaded with spam that I can't get time to type, but not so overloaded that I just give up- which has been the case until recently and this is what brought me back into the fray. _I_ _hate_ _this_... can't we declare Outlook illegal or something? Classify it as a weapon for denial of service attacks.

  19. Re:An observation... by shogun · · Score: 1

    (you do you oil computers, right?

    Well I do, got a squeaky fan? Pull the sticker off the axle cover, and the rubber plug if it has one two, put a drop or two of sewing machine oil in theres and its nice and quiet again.

  20. Re:This isn't really an Outlook worm! by Pinky · · Score: 1

    This is irrelevent. The implication here is that outlook is being used or required to spread the virus. This is nonsence and a potentialy dagerous assumption!

  21. Re:solution: don't use outlook by drsoran · · Score: 1

    Well, then it wouldn't get very far unless it's attacking Unix boxes. How many Windows or Mac machines have you seen with a C compiler on them? (well, barring MacOS X which is Unix). Now... a Perl worm would be funny.

  22. Re:But Unix has been able to do this for 30+ years by extra88 · · Score: 2

    Windows NT has had user level security for something like 8 years. Windows 2000 added the "runas" command which is a lot like "su" and some other improvements. What they both lack is sufficiently restricted permissions by default and don't discourage putting user accounts in the Administrators. Since Win2k, having an account in only the Users group and applying the Basic security template, makes it reasonably restricted.

  23. Re:What does your post have to do with the OS? by Tim+Macinta · · Score: 4
    OK, so you've shown that if a friend emails you a suspicious .exe, you create a phony account with no permissions then run it from that account. This is also possible in Win2K and Windows XP. So what's your point?

    So why doesn't Outlook do this automatically? Seriously - Outlook could set up a dummy user account at installation time and whenever an attachment is to be executed it could use the previously created dummy user to execute it. To all the posters who wrote that setting up a dummy user to execute attachments is too hard for most users, too cumbersome, or too inconvenient, what's the problem if this is built into Outlook and transparent to the user?

  24. there's a mushware version, too by hawk · · Score: 2
    every few months I get notices from a turkish political party, apparently urging me to vote that day . . .


    hawk

  25. good bloody luck . . . by hawk · · Score: 2
    > The only way that this sort of activity can
    > be stopped is by making it socially unacceptable (improper netiquette)
    > for anyone to send executables through email.


    For crying out loud, we can't even get people not to send messages in html . . .

  26. Re:These virus writers have no imagination... by hawk · · Score: 3
    > You don't want virus writers with imagination. You *really* don't.


    absolutely not. One of the things I learned practicing law is that the reason we're not in serious danger from the criminal element is because *criminals are stupid*. They don't draw the connection between crime and punishment. THeir planning is lousy. I actually had one where five of them stole 70,000 (using my client's mother'ss car as a getaway vehicle), and each took their $5,000 share. It took the police ten minutes to get it through to them that the ringleader ripped them off.


    Or the one that had to be rescued by the police after getting toasted, robbing a bar with a toy uzi, and then *going back in*, whereupon it was recognized and he was stabbed nearly to death . . .


    If they had what we generally think of as "Average intelligence," we'd be in serious trouble (of course, this would in many cases keep them from criminal behgavior, too).


    virus writers are just another kind of criminal . . .


    hawk, esq., etc.

  27. But Unix has been able to do this for 30+ years! by Omega · · Score: 1
    Sure, you CAN do this with 2000 & XP, but how long did it take MS to come up with BASIC security like this? How many focus groups, how many wishlists, or how many marketing managers were necessary for MS to implement security that's been standard in Unix for the past 30+ years?

    He's not saying you can't do this in Windows, but he is pointing out that you couldn't do this in Windows until RECENTLY.

    P.S. How is it that you can STILL be infected by Word Macro viruses under WinNT/2K/XP even though they have user level security?!

  28. Devil's Advocate by Outlyer · · Score: 5

    Ok, I have to respond to some of the folks here who believe that "Don't run Outlook" is an option. Well, pray tell, what should I do if I'm on a corporate Exchange server? With no other option? It's all well and good to suggest things, but the fact is, if the Exchange Admin won't use LDAP, you're out of luck, and quite stuck.

    That said, the SP2 release of Office/Outlook prevents anything from accessing your address book, and will pop up a confirmation. It doesn't prevent idiots from opening the attachments, but it does create some thought beforehand.

    I can appreciate the idealism of using Linux for everything (I'm a Debian developer for god's sake) but for my job, I have to use Outlook, so I do, because I like my job, and I'm not going to quit because of that minor inconvenience.

    I suppose this qualifies as a rant, and possibly will be modded to "Flamebait" or "Troll" but let's try and tolerate some dissent on this board for a change.

    --
    ----------------- "I have a bone to pick, and a few to break." - Refused -------------------
    1. Re:Devil's Advocate by iabervon · · Score: 2

      The solution to that is, of course, don't have your admin run Exchange. Really, it should be the admins who tell you not to run Outlook, not slashdot, because it's their job to understand what people should be doing with their email and so forth. Users have better things to do than really understand what's going on with their generic programs. That is, of course, why they should not be trusted with anything as hazard-prone as Outlook. Sure, they can run it safely, but if they know how to do this, they're spending brain power they should be devoting to actual work.

    2. Re:Devil's Advocate by iabervon · · Score: 2

      So configure Exchange to work with other clients than Outlook and have people use something more secure. And tell the voice mail vendor you want their next version to be more portable.

    3. Re:Devil's Advocate by wirefarm · · Score: 2

      I think your post underscores a lot of the frustration that people feel. What can you do?
      Probably nothing.
      It's as if your company's policy is to have a night watchman who invites his friends over at night to go through your desk and try to trash your stuff and see what they can embarrass you with.
      Since the PHB's are incapable of seeing that this is a bad idea, you are forced to live with it, by not keeping anything personal in your desk and keeping important files backed up and encrypted.
      If Microsoft would publish a protocol for connecting to Exchange servers, this problem and all its waste would _vanish_ as other clients emerge.
      POP 3 is a pretty good standard in that it lets users use any mail client that they like to get their mail.
      I use Sylpheed for Linux - I could just as easily use Outlook Express or Netscape or whatever...
      All you can do at your company is to be as careful as you can in protecting your files and be ready to explain the alternatives to anyone who is starting to realize that Outlook is a Bad Idea.
      In the mean time, well, hang in there.

      Cheers,
      Jim

      MMDC Mobile Media

      --
      -- My Weblog.
    4. Re:Devil's Advocate by RallyDriver · · Score: 2

      Outlook's so-called "workgroup" features are a thin pastiche of what is possible with Lotus Notes. And no, I don't like either of them.

    5. Re:Devil's Advocate by mewse · · Score: 1

      I'm on a corporate LAN with an Exchange server. Here's what I did:

      I got one of the old PCs that nobody wanted any more (P-200), stuck two 2-gig drives into it, and installed Debian Linux (any other UNIX-style OS would work just as well -- I just happened to have my Debian CDs with me at the time). I then installed fetchmail and mutt, and set up /etc/email-addresses to convert my local user name into my address on the exchange server.

      I configured fetchmail to grab my e-mail from the exchange server via POP3, using the user name and password that I use to connect to the network (this means that I have to adjust my .fetchmailrc every two months or so, when it insists I change my network password). That's all there is to it!

      So far as I've experienced, the standard Exchange server setup allows POP3 connections, and downloading mail through POP3 is much, MUCH faster than through Outlook's proprietary protocol!

      And of course, it means that I get to have a reliable Linux box for e-mail and web browsing on my left, even if I have to do the main part of my development work on a Win2k box.

    6. Re:Devil's Advocate by BlueUnderwear · · Score: 2
      > Lotus Notes.

      True enough. However, it has its own slew of problems:

      • although it has POP support, the access through this protocol is severely limited: you cannot delete or file mails, just read them. Why, o why don't they add a full-featured IMAP support?
      • There is still no Linux client, although technically feasible (but it runs nicely under wine).
      • If you receive spam in Lotus Notes, there's no way of tracing it, as Lotus hides all relevant headers (Received/from/by). There is a menu option to show more headers, but the Receiver/from/by headers are still not shown!
      • For certain versions of Domino (Lotus Notes server), the server is incredibly easy to crash: just log in to a protected Web page, and supply a bad password...
      --
      Say no to software patents.
    7. Re:Devil's Advocate by BlueUnderwear · · Score: 2
      > Notes includes full Internet Headers in the message, although in a hidden field. You can see it via a properties dialog,

      Interesting. Indeed, the second tab of the properties dialog gives access to "Received" header fields. Thanks for the info, our local Notes gurus didn't know that ;-) Now, I'll finally be able to stem the tide of spam that is swaping my Notes account by complaining to the spammer's ISP. That's so much easyer to do now that I know where it is coming from.

      > It also supports IMAP/LDAP if someone turns it on.

      This is also interesting. Our guys here claim that the best that can be done is (limited) POP3. Could you post a small description of how to enable Imap? Is the Imap support reasonably full featured, i.e. does it allow deleting mails, and moving mails between folders?

      Thanks

      --
      Say no to software patents.
    8. Re:Devil's Advocate by Lxy · · Score: 2

      First off, there's some blatant misconceptions about this trojan. It is *NOT* an OutCrook only trojan. The trojan does a MAPI lookup so anything that gets stored in the Windows Address Book is vulnerable. An SMTP server embedded in the attachment is what does the real work. That way it can sneak right by the network virus scanners because it's not using the e-mail system (Groupwise, Exchange, etc) that's being scanned. Unless you've made some really neat filter that sits on your T1 router and watches packets, you'll never catch it.

      Now, in refernece to other OutCrook-only virii. There is a neat hack floating around that allows Evolution to connect to an Exchange Server through the HTML interface. I haven't done any research so I can't provide a URL, but it's out there. Might help you in your situation.

      I believe that many of these virii/trojans/whatevers are just because users are dumber than hammers. With the exception of the auto-open exploit type virii (I think they patched that awhile ago in OutCrook) all attachments have to be executed. That requires the end user to open attachments. No matter how many viruses knock out companies and parts of the internet, there will be idiots who open attachments. As an experiment, I should write up some VBscript that uses the standard "e-mail to everyone in MAPI" trick with the subject line "This is a virus" and a body of "this attached script is a virus. Please don't open it" and see how far it propogates.

      --

      There is no reasonable defense against an idiot with an agenda
      :wq
    9. Re:Devil's Advocate by frankie · · Score: 2
      what should I do if I'm on a corporate Exchange server? With no other option?

      Well, one easy option is Get a Mac. Fully compatible with Exchange, except for worms and trojans.

    10. Re:Devil's Advocate by twitter · · Score: 2
      What exactly are you advocating?

      "Don't run Outlook" is what every PHB that reads this site needs to see. They also need to see and read parts of Building Linux and OpenBSD Firewalls, Published by Wiley, 2/2/2000 where the authors point out exactly what's wrong with it, MSIE, non Mozilla Netscape, and Windows. They recomend never using Windows to connect to the internet, ever.

      I work in a place that uses NT. When asked I will give my honest and full opinion of such things. I have my doubts that MS will ever fix its little problems, and know that free and superior alternatives exist.

      Oh yeah, you know as well as I do that nothing is going to keep rouge applications from reading or writing your Outlook address book. Saying things you don't believe to garner ignorant responses is also known as trolling.

      --

      Friends don't help friends install M$ junk.

    11. Re:Devil's Advocate by Caspuh · · Score: 1

      So after all this, did you have any time left to actually do your job? Companies hire IT staffs so that 'tards like you don't have to waste hours installing and learning unsupported software.

    12. Re:Devil's Advocate by vex24 · · Score: 1

      Thanks Tim, but we'll have to wait for meta-moderation to clear that up... ah well, luckily I've got karma to burn :)

      --

      People shape laws. Not the other way around.

    13. Re:Devil's Advocate by vex24 · · Score: 2

      If you can convince the Exchange admin to turn on IMAP support on your Exchange server, you can run any email client you want (I run Mozilla, even though my clients are "standardized" on OL98). The only thing I need Outlook for is my calendar, which I look at about once a day, leaving Outlook safely closed the rest of the time. True, I don't have a 10,000 entry addressbook, but I seem to get by without it... (note: Exchange also supports POP if you're into outdated protocols ;)

      --

      People shape laws. Not the other way around.

    14. Re:Devil's Advocate by sasha328 · · Score: 1

      Well said. If I hadn't already posted a reply to somone else, I would have modded your reply up.

      It seems that the majority of slashdotters shoot their replies without thinking. Just because there are alternatives to Outlook, doesn't mean that their functionality also covers everything that outlook does. For all it's failings, Outlook is a very powerful and customisable application. Just because Microsoft is the "corporate enemy number 1" does not mean it doesn;t produce good applications. For what it does, Outlook is great.

      What other workgroup systems give you email, calendar, and the ability to share your email/calendar with your assistant/colleagues?

      If you want to complain about the system, you have to provide alternatives. For corporations, it is very hard to beat Microsoft Outlook.

    15. Re:Devil's Advocate by BigTimOBrien · · Score: 1

      Wait! who mod'd this reply to Offtopic. It isn't offtopic at all, the user was trying to provide a correction to the previous post in saying that you don't need to use Outlook if you are running Exchange server.

      The Slashdot moderator system is becoming the censorship of the masses and is dumbing down the content.

      --
      ------ Tim O'Brien
    16. Re:Devil's Advocate by Grishnakh · · Score: 1

      In that case, I wouldn't worry about it too much. If you're required to use Outlook and you get an email virus that crashes your system, oh well. You can't very well be blamed for that, can you? Plus, it'll get you out of all your deadlines....

    17. Re:Devil's Advocate by Pravada · · Score: 1

      What other workgroup systems give you email, calendar, and the ability to share your email/calendar with your assistant/colleagues?
      Lotus Notes. I'm not promoting it (Used it when I used to work for Big Blue and hated the UI) - I use Eudora and my Vx and say "screw sharing" :) - but it does exist, and offers some cool security features.

      --
      --- On the other hand, you have five fingers.
    18. Re:Devil's Advocate by benspionage · · Score: 1
      A pity it was kinda wasted cause out of everything I've read, this anonymous post has summarised it best

      The funny thing is that all of these people who go through all the trouble of installing alternative email in their corp environment are also the people who are aware enough not to open an infected email.

      ...

      Most people could live without Outlook for email. There are lots of alternatives. However, try living without the calendar, appointments, meeting management, and address book. We have well over 100k employees in 10+ divisions. Try finding the email address of someone without the corporate address book. Sure, i could use the one on the web, but that takes 20 times longer and is a clunky interface compared to searching in Outlook.

      Myself, I've tried around 20 email applications including Eudora, Messenger etc. I am not biased towards any corporation/operating system/system whatever.

      For me, outlook has been excellent for overall management and organisation of contacts and tasks I usually forget etc. Give me something better I'll use it. For email, as the anonymous poster said, use whatever the hell you like.

      Outlook also makes synchronisation with my Pocket PC easy (probably *too* easy). That's all I usually ask of given piece of software though, to make my "real" life easier in some aspect.

    19. Re:Devil's Advocate by cREW+oNE · · Score: 1
      You're oh so right.

      But the problem isn't really outlook. It's the combination Outlook + Ignorant user.

      I've been running outlook (professional, not express) for years, without any problems or successful attacks from viri.

      And anyone that suggest pine as a real alternative to Outlook XP as a business mail suite needs to wake up, check his calender, and realize this is the 21st century, not the 70's.

      --

      --

      +++ATH0

  29. Serious Solutions? by vinod · · Score: 1
    Even if we replace Execute-On-Click with Save-Unzip-And-Then-Execute sequences, it is unlikely to solve the main problem: You don't know what you are executing. I think this is a interesting challenge. Here are my thoughts on
    a high level solutions:

    • Use VMWare like virtual machine to execute the binary. Only thing it will share with main OS is the display. It will be nice to have Linux as VM's OS here - provided we have very strict control of what can be allowed to run. (This is different from using Java because we are assuming full fledged OS support for executables, and controlled net access via bridge etc.)

    • Develop a P2P network that identifies the executables using the checksum, and before you execute the binary, it will check if any peer has executed it, and found the problems. The idea is to attach the "ownership" with every executable. If you have produced the executable, you have "owned" it. By establishing trust relationships with certificates and all that, you can possibly
      be warned.

    • An easier mechanism to identify and manage outgoing networking connections from your machine, and map them to user actions + applications. The analysis can be done by some AI techniques.

    These suggestions could possibly be implemented using some plug-ins. If, instead, new linux distributions include similar solutions as a core feature, GNU/Linux can be very attractive to organizations.

    -Vinod
  30. Re:Why continue using Outlook? by Eric+E.+Coe · · Score: 1
    I used Netscape mail for years (Windows and Linux), and never has a virus problem. But Netscape crashed on me too many times when I had nearly finished a multipage letter (or a long post to /. :) ). So, I switched to mutt - which I set up to run Emacs. Result: I get to use my favorite editor, and I never lose my mail during composition. And of course, Mutt has well-integrated crypto support (PGP/GPG).

    I get to laugh at viruses/html/javascript mail dangers. Viruses are just another ignorable (except for the size) attachment, and obnoxious HTML mail is converted to text with 'lynx -dump'; which is fine by me. After all, who needs dancing baloney in their mail?

    But a charatcter-mode mail reader like mutt, no matter how full-featured, is probably too much for Outlook lusers who are addicted to click-and-drool interfaces... *sigh*. People forget that email is first and formost a text application.
    --

    --
    An esoteric scratched itch:
    Homeworld Map Maker Tool
  31. Re:Why continue using Outlook? by Eric+E.+Coe · · Score: 1
    No. Mutt has excellent attachment support, based on it's excellent mime support. Email attachments (and their nested structure, if any) is shown as a listing at the end of the main message view, and in a seperate (view attachements) page, individually selectable and manipulatable (save, print, view with mailcap entry).

    (Example not provided beacuse of the /. lameness filter mangled it.)

    To operate on an attachment, move your cursor to the line in question, and perform the action you wish.

    The essence of mutt is that it is totally mime-controlled. You could set it up to do dangerous things (like pop up HTML in Netscape, or worse). But you get to choose, and it won't do these things by default.
    --

    --
    An esoteric scratched itch:
    Homeworld Map Maker Tool
  32. Re:Yeah, I got a couple this evening by jonabbey · · Score: 1

    <>
    - jon

  33. Yeah, I got a couple this evening by jonabbey · · Score: 2

    Seems this one is pretty popular. I never got any I LOVE YOU mail or anything of that ilk, but I've had a couple of copies already today, both with attachments named after somebody's Excel spreadsheets.


    - jon
  34. Someone did... by cirby · · Score: 1

    There was an Office macro worm a while back that altered Excel spreadsheets somewhat at random. There have also been versions that tweaked Word documents.

  35. Re:Why continue using Outlook? by sphealey · · Score: 5

    >This isn't a problem with Outlook, it's a problem with idiot users clicking on every damn thing they're emailed.
    >>Furthermore, Outlook actually helps out the "idiot" users.

    There is a principle in the Toyota Production System that goes something like this: "If a worker makes a mistake once, it may be the workers fault. If a worker makes a mistake twice, it is the supervisors fault. If a worker makes a mistake three times, it is management's fault".

    Most human beings on the face of the earth are not technically minded and DO NOT WANT to understand the details of how the tools they use work. If every time Joe Homeowner flipped on a light switch there was a 1% chance of a nuclear power plant melting down, we wouldn't be using much electricity, now would we?

    While Microsoft is to blame for creating insecure tools (keeping in mind that larger market share means more attaraction for attackers), responses along the line of "stupid users don't understand how to use e-mail" are not acceptable, either.

    sPh

  36. How 'bout several alternatives... by Svartalf · · Score: 2

    Bynari Insight client/server
    Lotus Notes
    GroupWise

    These all provide the same general functionality as Exchange/Outlook does.

    Of them, Bynari works both on Windows and on Linux.

    And, I'd beg to differ about the "hard to beat" since most companies can get the same functionality and most of them don't really use the thing to it's fullest anyhow.

    --
    I am not merely a "consumer" or a "taxpayer". I am a Citizen of the State of Texas
  37. Win2k running idle IIS by default...yeah, but... by Tumbleweed · · Score: 2

    Please to note that many Linux distributions have done this for a long time, and not just a web server, either.

  38. Re:These virus writers have no imagination... by Joe+Decker · · Score: 1
    Why can't these virus writers do something cool? Like install the SETI@home client on every infected machine?

    There've been distributed.net-installing trojans.

    --j

  39. Re:The depressing thing about these worms... by Joe+Decker · · Score: 1
    Nobody has me in their contact list :(

    Cheer up, it's better than that. It just means that the folks who have you on their contact lists are smart enough to use something besides Outlook. :)

    --j

  40. Re:Exchange Calendar is BROKEN. by Joe+Decker · · Score: 1
    Let's see... A mail-based calendaring system requires a particular client to work?

    Yes. It's an interesting, and I think poor, design choice. Frustratingly, it is almost usable with other clients else, "new meeting" requests are just funneled into what appears as an IMAP4 "Calendar" folder, which is something that's trivial to manage with a filter. However, updates/cancellations to existing meetings, etc., require a little more "smarts" to do the right thing.

    If your company puts up with apps that force you to use particular other apps to get generic functionality (like, say, MicroSquish Exchange), then it has a serious management problem.

    Relax, dude, get a life. :) This particular decision was poor, but on the whole, it's a very high quality organization, probably the most talented managment team I've worked for in the last twenty years. My personal stuff is well-separated, my anti-virus protection is updated quite often, and I have good "attachment hygeine". I'll live.

    --j

  41. Re:Exchange Calendar is BROKEN. by Joe+Decker · · Score: 1
    It would be if it were an engineering design choice, not a marketing one. That choice and its consequences was not an accident.

    You know that for a fact, do you?

    --j

  42. Re:Why continue using Outlook? by Joe+Decker · · Score: 2
    I have Outlook running for my work email, even though it is the viral target of choice, becuase having it run is required for the Exchange Calendar system to work, which my company seems to be stuck on. More of the Microsoft "use one of our products, use all of our products" strategy, I guess.

    For my own stuff, I'm a fan of Eudora.

    --j

  43. Re:Sheesh... by Joe+Decker · · Score: 4
    ...it's somewhat ironic that the Slashdot editors don't know the difference between a "Virus" and a "Trojan".

    Seems like folks using a "Trojan" should be safe from getting a "Virus". :-)

    --j

  44. Re:What does your post have to do with the OS? by RelliK · · Score: 2

    Not available in Windows 2000. Care to give more details? BTW, I hate it when moderators decide to give points without checking the facts first.
    ___

    --
    ___
    If you think big enough, you'll never have to do it.
  45. Re:solution: don't use outlook by crisco · · Score: 2
    I believe it's a win32 executable.

    the two I received had the extension .pif but digging around with a hex editor just about convinced me they were a standard executable. I'm not sure how windows handles .pif files though, there are definately some different things going on there.

    Chris Cothrun
    Curator of Chaos

    --

    Bleh!

  46. File extension by crisco · · Score: 3
    The 2 copies I received had the extension .pif. Windows hid that extension from me, only displaying filename.doc. Pegasus Mail displays the entire filename.

    Windows also brought up a different right click context menu with the file.

    don't ask about accidently double clicking the thing...

    Chris Cothrun
    Curator of Chaos

    --

    Bleh!

    1. Re:File extension by dodobh · · Score: 2

      I suggest going through the registry. there are some extensions with NeverShow next to them. Removew that, since show all extensions still ignores these extensions.

      --
      I can throw myself at the ground, and miss.
    2. Re:File extension by quintessent · · Score: 2
      Windows hid that extension from me.

      I was quite upset when Windows started doing that. When I get on a new setup, I am quick to go to the folder options and have it display all extensions. But like I said, a careful user can always tell what type of attachment it is.

    3. Re:File extension by Jucius+Maximus · · Score: 1
      "Pegasus Mail displays the entire filename. "

      Hurray for pegasus mail! Another reason why this client is excellent is that when you get HTML mail, it ASKS you whether you want it rendered or not. I always tell it to show the plaintext. This protects you from viruses, tracking bugs, cookies, spam confirmation scripts... the works!

  47. Re:unfortunately, by johnnyb · · Score: 2

    However, this brings up an interesting point that Robert Cringely wrote - if we all standardize to any given system, a single exploit could wipe everything out.

    Many people really want all computers to be the same. However, it appears that variety may save us from the "one true exploit". If we didn't all run the same freaking programs, problems like this would have a much milder effect.

  48. Re:Unthinkable - Thinkable by Francis · · Score: 1

    Haha! :) Ain't that the truth. Remember that Good Times email virus that was all the rage?

    You'd laugh at whoever "warned" you about it, because it was unthinkable that an email would transmit a virus to your terminal.

    But now, thanks to Microsoft Innovation(TM) it really is possible for your email to wipe out your machine. :)



    --
    #include <malloc.h>
    --

    --
    #include <malloc.h>
    free(your.mind);
  49. Re:The Microsoft Patch by Francis · · Score: 1

    No, what's really dumb is forwarding executable attachments to yourself. WHY WOULD YOU DO THAT?

    Suppose maybe you want to email yourself an executable (from home to work), or you want your friend to send you an executable file.

    Or suppose you know the executable is good. (You specifically requested it from someone) You can't even mail it to an account which you don't access through outlook to retrieve it.

    Of course you can rename the file, but this is an irritating in itself, especially if you forget. Round-trip time between home and work (or whatever) can be a day if it's not convenient to go home at lunch...

    --
    #include <malloc.h>

    --

    --
    #include <malloc.h>
    free(your.mind);
  50. The Microsoft Patch by Francis · · Score: 2

    Agreed - it's not that bad. You'd have to deliberately run a binary executable to get infected. Which also means Netscape + all others on windoze can be afflicated.

    But, technically, you can't *get* this virus on M$ Outlook, if you're reasonably up to date on patches. Outlook "protects" users from viruses by simply disallowing you to look at *.exe attachments. You can't even forward them to yourself through Outlook. Dumbest solution I've ever heard of.

    --
    #include <malloc.h>

    --

    --
    #include <malloc.h>
    free(your.mind);
    1. Re:The Microsoft Patch by Aphelion · · Score: 2

      This trojan also hides its extension, in the form of a DOC file.

      The actual name of the received file, for example, is [b]resume.doc.pif[/b], but in Windows Explorer, even with "show filename extensions" turned on, it shows up only as [b]resume.doc[/b].

    2. Re:The Microsoft Patch by Ronin441 · · Score: 1
      you can't *get* this virus on M$ Outlook, if you're reasonably up to date on patches. Outlook "protects" users from viruses by simply disallowing you to look at *.exe attachments.
      That won't necessarily cover it; the one copy of this virus I received had a .doc.lnk double extension; so that stupid users would think it was a Word doc, and Windows Explorer would think it was a shortcut. (And that's what it showed it as: size: 200K; type: shortcut.) The virus also adds other doubled extensions to file's names, including .com and who knows what else.
    3. Re:The Microsoft Patch by Fred+Ferrigno · · Score: 3

      If you think that's bad, take a look at this virus/trojan that was floating around IRC a while back. The thing is indistinguishable from a text file at first glance, even if you're bright enough to check the extension. When it executes, it even opens a contained note in Notepad so you don't think anything is wrong.

      --

    4. Re:The Microsoft Patch by tswinzig · · Score: 2

      But, technically, you can't *get* this virus on M$ Outlook, if you're reasonably up to date on patches. Outlook "protects" users from viruses by simply disallowing you to look at *.exe attachments.

      Actually, it disallows most executable attachments.

      You can't even forward them to yourself through Outlook. Dumbest solution I've ever heard of.

      No, what's really dumb is forwarding executable attachments to yourself. WHY WOULD YOU DO THAT?

      People like to invent ways to prove that this protection method is dumb, but I actually use Outlook with this security update installed (not that I would ever open an executable attachment anyway). The very few times I've actually received an executable that I want, e.g. a beta test I was expecting, I just ask the company to re-send it .zipped or renamed.

      --

      "And like that ... he's gone."
    5. Re:The Microsoft Patch by Jucius+Maximus · · Score: 1
      "Agreed - it's not that bad. You'd have to deliberately run a binary executable to get infected. Which also means Netscape + all others on windoze can be afflicated."

      Sure, but if a Windoze user is smart enough to download, configure and use another e-mail client instead of the default Outlook, they're probably smart enough to recognise when something questionable is coming into the inbox.

    6. Re:The Microsoft Patch by uigrad_2000 · · Score: 3
      When it executes, it even opens a contained note in Notepad so you don't think anything is wrong.

      Hmm, it would make me suspicious. I'm used to all text files being opened in gvim.

      --
      Free unix account: freeshell.org
  51. Re:Im sticking with Outlook by ZxCv · · Score: 1

    What security is their with a single-user operating system? Clearly there is some, but not even close to that required on a multi-user system. I guarantee these type of viruses affect the Win9x line of OSs much more than the NT/2k line. Win NT/2k have (essentially) all of the same security safeguards in place as any UNIX that would prevent a virus like this from damaging the system, provided the system is being used safely and correctly (like any UNIX system must be).

    --

    Perl - $Just @when->$you ${thought} s/yn/tax/ &couldn\'t %get $worse;
  52. Im sticking with Outlook by ZxCv · · Score: 3

    I've been using Outlook for far too long and get far too much functionality out of it to switch to another app because macro viruses for it are spreading. I've got the ultimate in Outlook macro virus protection-- it's called a BRAIN.

    First off, the only way to make macro capabilities even worth a damned was to include functionality that could also possibly be used for - *gasp* - viruses! Oh no! Shit man, big deal. Why is it that I can look at the attachments on my emails and plainly see an attachment that ends with .vbs, yet somehow others cannot? These viruses are the tamest you could ask for-- don't run the damned script file and you won't be infected! Oh wow! True genius, I know!

    I certainly understand that these viruses are capable of creating better disguised files (such as spreadsheets with autorun macros), but every Office app has an option to NOT autorun macros. IIRC, this is the default option (at least on Office 2000-- havent touched XP). And beyond that, that virus started off at some point as a script file. It took some jackass who wasn't paying attention to get it going.

    As well, the only reason this is even an issue is because of the number of people that use Outlook. Say someone wrote a "macro virus" for some Linux GUI mail client which supported scripting of some kind (Python, for arguments sake). It could disguise itself into other files, send random files to random people and generally spread itself just like these Outlook ones do. The only reason we'd never see news about something like that is because there arent the numbers of people using such clients that are using Outlook clients and as such, I imagine there aren't very many virus kiddies out there looking to target the Linux geeks of the world.

    Now, don't get me wrong. I'm no GO MICROSOFT! guy or anything, but at the same time I realize that when it comes to them, many people on this site don't even give a second thought before finding them guilty of murder...

    --

    Perl - $Just @when->$you ${thought} s/yn/tax/ &couldn\'t %get $worse;
    1. Re:Im sticking with Outlook by Mongoose · · Score: 1

      I use evolution, and it allows attachments to be run ( with some tweaking ) as well as opened for viewing...

      I doubt I'll ever have that problem, because javascript and etc has no real power on my machine.
      If you use outlook that's your problem.

    2. Re:Im sticking with Outlook by ElderKorean · · Score: 1

      The simple solution that we have is that you can install a virus scanner. The one that I have had installed here checks for downloads of new virus signatures each day, and as workstations connect in the morning they get the latest updates.
      Works on each desktop, and also on Exchange too.

      I also remind the staff here to not blindly execute programs that they weren't expecting.

      Yes some people here received the virus in their inboxes, but the thing never got the chance to run.

      Ian.

    3. Re:Im sticking with Outlook by binford2k · · Score: 1
      Say someone wrote a "macro virus" for some Linux GUI mail client which supported scripting of some kind (Python, for arguments sake).
      Add to that "That has no security mechanism" and your analogy would be accurate. The thing is tho, name one. Name one sigle Linux mail client that supports scripting without security!
    4. Re:Im sticking with Outlook by Asic+Eng · · Score: 2
      Why is it that I can look at the attachments on my emails and plainly see an attachment that ends with .vbs, yet somehow others cannot?

      That is because some people have "hide extensions" enabled - that's the default setting. :)

      I agree with you about the origins of the problem: monoculture of mail clients and scripting. However most engineers when adding scripting to an email tool would give security a thought. Why not implement a sandbox? Why not write sensible warning messages which *only* apply to executables?

      You could put the effort in to implement scripting in a mail client while maintaining security. Just compare Sun's approach when they introduced java. They realized when you execute code coming from the web you need a security system - and it had one right from start.

      Sure, just having such a system is not enough, it's implementation might be flawed, there could be holes which can be exploited. However Microsoft put no effort in at all. I think it's fair to put the blame on them, too. Outlook is sub-standard engineering, MS should take responsibility for the damage they cause to customers.

    5. Re:Im sticking with Outlook by night_flyer · · Score: 1
      except this isnt javascript, its either a .com file or a .pif file... which operate just like an .exe so if you automatically open the attachment & are using windows then you are screwed

      _______________________

      --


      Thanks to file sharing, I purchase more CDs
      Thanks to the RIAA, I buy them used...
  53. Re:CLUE Taken!!! by LinuxGeek · · Score: 1

    Cool, then I can participate!

    If we don't need Outlook, then I can run this virus/trojan/worm/stink-bomb under wine with no MS code installed. Everyone complaining about being left out can rejoice and join-in. :)

    --

    Kindness is the language which the deaf can hear and the blind can see. - Mark Twain
  54. These virus writers have no imagination... by kcbrown · · Score: 4

    Why can't these virus writers do something cool? Like install the SETI@home client on every infected machine? Or install something to DOS the RIAA/MPAA/Bad-guy-of-the-week (how about having the DOS daemon check Slashdot to determine who the current bad guy is)?

    I'm sure that someone can come up with even more interesting things than this...


    --

    --
    Use 'slashdot stuff' in the subject line in any email you send me if you want to get past the spam filter.
    1. Re:These virus writers have no imagination... by ajm · · Score: 2

      More social engineering is needed. The most effective sort of virus would be one that made people distrust the information the computer gave them. What about proxying connections to cnn to another site that looks the same and announcing Bush's assasination? Good for some stock trades I'd guess.

    2. Re:These virus writers have no imagination... by SmittyTheBold · · Score: 1

      Mwa ha ha! With these ideas, I shall create the super-virus! It will carry out all of these nefarious schemes, and then the world will be MINE!

      --
      ± 29 dB
    3. Re:These virus writers have no imagination... by Maniac_Dervish · · Score: 1

      what a fantastic hit list for any lurking virus authors... thanks so much.

      fortunately, half the people on slashdot are clueless morons, and it seems highly unlikely that many of them will be able to write any sort of working executable code :)

      --
      -----
    4. Re:These virus writers have no imagination... by Goblin · · Score: 2

      Well, there is a virus which installs the SETI client on infected machine. Its name is Hadra.

    5. Re:These virus writers have no imagination... by 1010011010 · · Score: 2

      It'll be interesting when viruses that delete or corrupt the WPA database start showing up...

      - - - - -

      --
      Napster-to-go says "Fill and refill your compatible MP3 player", which is a lie. It's not MP3. It's WMA with DRM.
    6. Re:These virus writers have no imagination... by quonsar · · Score: 1

      ...randomly changes three numbers in every fifth file. Or perhaps it finds your Word documents and randomly removes the words "do not" from a few places. Or maybe it flips a few bits in your swap file, or munges your C++ compiler...

      why would any hacker bother producing a virus whose features were already integrated into the OS?

    7. Re:These virus writers have no imagination... by BlueUnderwear · · Score: 2
      > Or perhaps it finds your Word documents and randomly removes the words "do not" from a few places. Or maybe it flips a few bits in your swap file, or munges your C++ compiler

      That reminds me of a prank we played back in high-school: a small program that would randomly change a semicolon into a colon in Turbo Pascal's editor. On the low-quality screens of that time, both signs were hard to distinguish, and moreover, as they are on the same key, people first thought about silly typoes before thinking that it may have been due to malicious code.

      The program itself was well hidden too: it was a TSR being started from autoexec.bat, namded <shift-space>. The shift-space just looks like a normal space, but was legal as a character in filenames, so you could invoke a program like this, and somebody checking autoexec.bat wouldn't notice anything fishy...

      As this was an external program, re-installing Turbo-Pascal wouldn't help. Eventually, the teachers completely re-installed the OS (which wiped the tampered-with autoexec.bat) to restore normal operation.

      --
      Say no to software patents.
    8. Re:These virus writers have no imagination... by NReitzel · · Score: 2

      Maybe somebody should build a vbs virus that distributes deCSS. Just for grins.

      --

      Don't take life too seriously; it isn't permanent.

    9. Re:These virus writers have no imagination... by Greyfox · · Score: 2
      While I was working on PostScript drivers back at the Printing Systems Company, I thought up a really cool printer virus that would propigate from network printer to network printer and quietly replace every instance of the word "strategic" to hit the printer with the word "satanic" in the output. Imagine that at a presentation.

      Fortunately the job kept me busy and I never quite did figure out how to open a network socket in PostScript. As an academic problem it was quite a nifty idea.

      --

      I'm trying to teach myself to set people on fire with my mind... Is it hot in here?

    10. Re:These virus writers have no imagination... by CaptainAvatar · · Score: 4

      Well ... now that you mention this idea, how do you know they aren't doing this already? Sounds like it could be causing half the win and macos problems I have to troubleshoot every week!
      --

      --
      The real Captain Avatar is a fictional character, so I suppose he doesn't mind if I impersonate him.
    11. Re:These virus writers have no imagination... by panum · · Score: 2
      Time to wake up, this is old news indeed.This bug attacks dBase files and corrupts them. dBase was quite a popular database in late 80's, IIRC.

      The nasty thing is that the bug is able to hide in memory and reverse the damage to the .dbf file when dBase loads it. Therefore file corruption is not noticed at once. Unsuspecting user will make proper backups of the damaged file. After a while the file is wasted, and the corrupted backups are good for nothing.

      -P
      --
      I hate people who quote .sigs
    12. Re:These virus writers have no imagination... by OverCode@work · · Score: 1

      Virus writers are a rare breed these days, imho. Maybe the first few Outlook virii were cute hacks, but nowadays they're repetitive and boring, and hardly an exhibition of skill. I had a little bit of respect for the guy who wrote Neuroquila (a DOS virus written in assembly which infected a bunch of computers I was trying to upgrade back in '97 or so)... That took some talent to write. But these script trojans just aren't of the same caliber. In my mind, the people who write these are just script kiddies, and vandals at that.

      (Not to excuse Microsoft for failing to secure their product; I consider that criminal negligence at this point. But we all know how likely that is to change.)

      These virii do show that a company can get away with maintaining a defective commercial product for an indefinite period of time, as long as they have a sufficient marketing department and pander to weak-kneed sysadmins who are too concerned about their job security to do anything but cover up the problem.

      -John

    13. Re:These virus writers have no imagination... by LoudMusic · · Score: 1

      AMEN TO THAT BROTHER! I've come to the point of format and reinstall several times to fix problems that are undocumented and I couldn't figure out what was happening.

      ~LoudMusic

      --
      No sig for you. YOU GET NO SIG!
    14. Re:These virus writers have no imagination... by Jucius+Maximus · · Score: 1
      "You don't want virus writers with imagination. You *really* don't. A truly imaginative virus writer would likely devote all sorts of creative energy toward thinking up nasty things to do to your computer."

      Oh my goodness you're right! If this happenned, sooner or later, someone would write a virus to add 127.0.0.1 www.whitehouse.com to all windowze hosts files! But wait a sec... doesn't that mean we'd all get *faster* downloads since all the windows users wouldn't be the leeching files? [g] This might not be so bad after all...

    15. Re:These virus writers have no imagination... by fallen1 · · Score: 1
      If you are quite happy with the current crop of dull, stolid, entirely *un*imaginative virus writers , why in the hell did you just give them a shopping list of ideas to choose from?? ;-p

      --

      Dream as if you'll live forever.
      Live as if you'll die tomorrow.
      ~Anonymous~

    16. Re:These virus writers have no imagination... by dasunt · · Score: 2

      There is already a trojan out there that installs the dnetc client to your machine, and spreads via poorly-protected windows shares. I disinfected a machine last week with that virus.

      Now the virus I would write, if I ever decided to be 1337, would be one that simply removes one card from microsoft solitaire... :)

    17. Re:These virus writers have no imagination... by jsse · · Score: 1

      No no, I see what he meant. He want them creating virus for good purpose, like sealing security holes, or altering DNS entry in order to redirect virus-induced DOS attack against whitehouse.gov to microsoft.com.

    18. Re:These virus writers have no imagination... by baptiste · · Score: 2

      Well, that's what Max Vision did and got thrown in jail for 18 months - course he was stupid enough to fix the exploits on the computers and then installed his own little back door - kinda like making change in the offering plate and taking out more than you put in :)

    19. Re:These virus writers have no imagination... by chuqui · · Score: 1

      > Why can't these virus writers do something cool?

      Please, god, no. You have the virtual equivalent of a group of people who think it's fun to kick in your back door, trash your house and defecate on your kitchen table -- and you want them to paint the liviing room while they're there now?

      What's scary is how many people don't even notice the smell or the draft... sigh.

      --
      Chuq Von Rospach, Internet Gnome = When his IQ reaches 50, he should sell
    20. Re:These virus writers have no imagination... by anshil · · Score: 1

      I had one of these it was called 'ParityBoot Virus', and made a parity boot error once in a time during a boot but didn't destroy anything, even changing rams didn't help. I checked everything the whole hardward insideout, until after some days the error "spread" over to a friends computer, then I finally knew where to look :o)

      --

      --
      Karma 50, and all I got was this lousy T-Shirt.
    21. Re:These virus writers have no imagination... by _LFTL_ · · Score: 1

      http://www.symantec.com/avcenter/venc/data/w32.hyd @mm.html

      I also remember one team being disqualified for writing a virus to spread another of the distributing computing clients (didn't spread through outlook though), but I couldn't find it on Symantec.

    22. Re:These virus writers have no imagination... by mrm677 · · Score: 1

      I would guess that even the very best virus writers have just a tad bit of fear that he or she might get caught. If someone unleashed a virus like that, and got caught, he or she would see quite a bit of jail time.

    23. Re:These virus writers have no imagination... by p_trinli · · Score: 1

      I believe kcbrown's point was that virus writers could do something productive instead of just trashing computers.

      --
      Aaron J. Shaver
      http://aaronshaver.com/

    24. Re:These virus writers have no imagination... by wildlime · · Score: 1

      I seem to remember a worm a few days ago that DDOSed whitehouse.org... If only the target had been DNS based!!

  55. Re:It's the OS, stupid. by TZA14a · · Score: 1
    The outlook worms work just fine with default user privileges, so Unix doesn't really solve the problem any more than NT/Win2K do (under which you can also create bogus accounts in 30 seconds, BTW).

    Create them, maybe. But to run anything under such accounts is a lot more complicated than simply "su -c suspicious sandbox".

    Microsoft does still have some issues with true multi user concepts. One point I run into frequently is that you can't connect to the same remote host using two different user IDs for different shares or that it's pretty hard to make Windows forget authentication info you once supplied (I used to have some external developers who stopped by once a week, and I could access their W2k shares for months after they had once typed their password in my Explorer (yeah, my NT workstation really had 68 days of uptime, then! :))) And though the NT kernel can run processes as different users fine, there's not way for the common user to access that functionality.

    Unix on the other hand is so multi-user that it's sometimes remarkably difficult to do single user things.
    --

  56. Re:It's the culture, stupid. by Syberghost · · Score: 2

    Users want the ability to double-click on executable attachments in order to open them, and email software needs to honor that request to stay competitive.

    And if that was all Microsoft did here to cause a problem, you'd probably be right.

    But most users do not want the system to lie to them about a file's name, causing them to think it's NOT an executable file when it in fact is.

    Most users do NOT want their email to be able to destroy their entire system, and thus would be perfectly happy if said executables ran in a "jail" that couldn't affect the rest of the filesystem without a prompt. "This program is attempting to delete c:\windows\SOMEFILE.EXE, should I allow it to do that? (OK/CANCEL)".

    Most users do NOT want their email to be able to run scripts without them even having opened the message, much less clicked on something.

    Microsoft themselves have admitted that a number of things have been included because exactly one large customer wanted it, that affect how everything else on the system is designed. This is more than likely one of those things.

    -

  57. Be that as it may by FreeUser · · Score: 2

    The problem is people hate account security and won't use it. They don't like the bother of having to log out, closing everything they were doing, and log in as someone else just to install a new app. Heck, half the *linux* users I know log in as root all the time!

    Be that as it may (and you certainly know a different breed of GNU/Linux users than I ... even my mother doesn't mind logging into her GNU/Linux box), it is no excuse for building a system which even the most conscientious user cannot secure because the design (or lack thereof) simply makes it impossible.

    It is one thing for foolish users to undermine or gut existing security features. It is another to make the features non-existent, then blame the users with "well, it's what they would have done on their own anyway." People aren't generally as stupid as we like to think ... I've had numerous Windows users ask me how they can secure their system ("firewall" I tell them and, if they are serious, "switch to GNU/Linux or FreeBSD, because even a firewall can't effectively protect a system as ridden with exploits as Windows." You'd be surprised at how many of them fall over themselves to install and learn a new system.)

    --
    The Future of Human Evolution: Autonomy
  58. Unconscionable by FreeUser · · Score: 4

    I'm sure a lot of people here are going to go out and blame Microsoft for the Outlook-virus-of-the-week. But the fact is, Microsoft is just giving the user what they want.

    Good Lord.

    This reminds me, almost word for word, of statements typically made by rapists and child molesters. While the situation is vastly different (thankfully), the behavior of the guilty party, Microsoft, is appallingly similar: refuse responsibility for one's own actions and blame the victim.

    The cause of these (now almost cliched) viruses is, quite simply, the appallingly lax security in the Microsoft Operating System and mail utilities, a lack of which is unequaled anywhere else in the computing world. Whether by design, negligence, or simple incompetence the fact remains: if you run any version of Windows, IIS, or Outlook, you are vulnerable to this sort of thing regardless of how savvy or cautious a user you are, and there is little or nothing you can do to protect yourself. Indeed, by the time you know of the exploit (assuming you are savvy enough to keep up on such things, which IMHO is asking far more of the user than simply learning a few basic commands a la GNU/Linux or DOS, much less a few GUI variations from with Windows paradigm a la Mac, KDE, or Gnome) chances are the malicious crackers have been exploiting it for weeks or even months.

    Contrast this with the rest of the computing world, in which exploits are published and fixed as soon as they are found (and usually found by the product developers and/or testers before they are exploited), and in which the basic security paradigms allow one to secure the system in as paranoid a fashion as the situation requires, and the mind truly boggles at Microsoft's inability to at least match the quality of competing products such as Mac OS/X, the various *BSD flavors, and GNU/Linux.

    It is bad enough that Microsoft appears incapable of building a secure system. It is even worse that they knowingly market an insecure and unstable system as though it were secure and stable (were there still any kind of "truth in advertising" requirements they would certainly be paying hefty fines for falsly marketing their products). It is unconscionable that they refuse to accept responsibility for their own engineering, choosing instead to blame the victims of its failure: their customers.

    --
    The Future of Human Evolution: Autonomy
  59. The depressing thing about these worms... by dwlemon · · Score: 1

    Is that I've never recieved one.

    Nobody has me in their contact list :(

  60. Re:How long? by dwlemon · · Score: 1

    They can't do anything *too* malicious without calling enough attention to it that the spreading slows down.

    There has to be a balance.

    Sure, Melissa could have wreaked much much much more havoc than it did and got away with it, but that's hindsight for you.

    Nowadays people are slightly more clueful and I don't think a HD reformatting worm would propegate very far.

  61. Re:It's the culture, stupid. by Lumpy · · Score: 2

    Actually no, it's not.

    you just set up your email server to automatically destroy any attachment that is not an accepted attachment.

    and if your users whine, tell them to work at another place you arent going to allow it.

    Simple, to the point. and Voila... No more problems...

    In fact I have my servers set to reject all html email. bouncing the message back to sender stating the fact why it's not allowed.

    Works great, and as a gigantor corperation, we can get away with it.

    --
    Do not look at laser with remaining good eye.
  62. Re:How long? by SmittyTheBold · · Score: 1

    perhaps have the virus check a pre-determined URL every 12-36 hours. If it can't reach the site, or it detects you have modified the HTML to a pre-defined trigger, it drops the payload.

    Use free web space, and update it through myriad web-anonymizer sites.

    --
    ± 29 dB
  63. Re:Why continue using Outlook? by Zico · · Score: 1

    You can't receive an email attachment when using mutt? Sounds like a real piece of shit. Yeah, I'm sure that feature combined with that oh-so-attractive console interface is just wayyyy too much for anyone to handle.


    Cheers,

  64. Re:Why continue using Outlook? by Zico · · Score: 1

    I was just being coy. I know that Mutt (or any email client with more than 5 users) can handle attachments. The point is that this virus has nothing to do with Outlook -- the user only gets infected if they actually run the executable. Forget all the extra stuff like the built-in SMTP server or different languages; it's just an executable that needs to be run by the user before it can do any damage, and any email client that can receive attachments can make it available to an unsuspecting user.


    Cheers,

  65. Re:It's the culture, stupid. by Sloppy · · Score: 2

    No, the problem is with the applications. NT is multiuser (even though everyone logs in as administrator anyway, since NT doesn't have a "su" command and logging out/in whenever you want to install something is too much trouble). Having the apps run scripts as a sandboxed user wouldn't be very hard to do. But Microsoft just doesn't care enough about the problem to actually bother doing it. (And since their apps are closed, no other party can add this feature, so what Microsoft cares about actually matters.)


    ---
    --
    As copyright owner of this comment, I authorize everyone to defeat any technological measure which limits access to it.
  66. Re:How long? by Sloppy · · Score: 2

    It is hard to get into the heads of virus writers, so this is mostly just speculation, but...

    I suspect the reason we haven't seen any seriously malicious email viruses yet, is because the virus writers don't want the problem to get addressed. They are enjoying seeing their viruses spread. Right now, the industry tolerates the viruses and doesn't mind losing a few million dollars here, a few million dollars there, etc.

    If a truly malicious virus appears on the scene, and the loss figures go into the billions of dollars area, then the industry will stop tolerating the viruses and the software that executes them. Outlook/Word/Excell/IE will get fixed or be replaced, and that will be the end of the virus writers' fun.


    ---
    --
    As copyright owner of this comment, I authorize everyone to defeat any technological measure which limits access to it.
  67. Re:Not everyone escaped Code Red lightly by The_Sock · · Score: 1

    I'm no fan of Microsoft, but to be fair, Win2k Professional does not start IIS by default. Win2K server, advanced server, enterprise, (whatever other names they gave it so they can chrage more for the same product here) do. If you install *server*, you should really expect to start the services to run as a server. If he was using Win2K *server* as his desktop (which you never said he did), well, he deserves his bill. As always stupidity will eventually cost you.

    --
    For a good time call www.sawkie.com
  68. Damn.. by BilldaCat · · Score: 4

    I've been getting this for about a week or so I think.. 4 copies today.. I thought it was just more porn spam at first..

    Cheers to mutt .. :)

    --
    BilldaCat
  69. It's the OS, stupid. by warpeightbot · · Score: 4
    Think about what would happen if one of your colleagues sent you a random Linux binary through email and claimed it was a greeting card - would you run it? Well, the drooling masses will run any .exe that a "known" source sends to them, and that is the crux of the problem.
    Sure, I'd run it.

    $ su
    Password:
    # useradd fred123
    # passwd fred123
    Changing password for user fred123
    New UNIX password:
    Retype new UNIX password:
    passwd: all authentication tokens updated successfully
    # cp suspicious.exe /home/fred123
    # chown fred123.fred123 /home/fred123/*
    # chmod 700 /home/fred123/*
    # exit
    $ su - fred123
    Password:
    fred123$ ./suspicious.exe
    suspicious.exe: /etc/shadow: permission denied

    Aha!

    fred123$ exit
    $ su
    Password:
    # userdel -r fred123
    # exit

    The problem here isn't even gullible users. It's the fact that under Win9x, you're running as god all the time, and can seriously hurt yourself. Under Linux, I can create a temporary user in about 30 seconds, go crap all over the resulting sandbox, and I *might* release a forkbomb or fill up /home... if I was being lazy. If I was really worried about it, I could ulimit the bejeezus out of the new userid, and whatever little surprises lay in that exe wouldn't get past first base.

    And it's not just Linux, or other Unixes... VMS, NOS, NOS/VE, VM/CMS... IS there another OS out there that DOESN'T have proper ACL's and CPU/process limits? BeOS, MAYBE?

    Yes, there are a lot of clueless Windows users. There is still no excuse for deliberate insecurity on the part of the OS. As for Microsoft "giving the users what they want"... As Norm Schwartzkopf would say, bovine scatology. See previous comment.

    1. Re:It's the OS, stupid. by NeoMage · · Score: 2

      You are also forgetting something that a lot of tech savvy people forget... you -know- how to do this stuff.

      I support people everyday in using technology, both corporates and home users. A lot of people simply don't know how to do what you do to protect yourself. "Well they should learn", you say. Easy for you. Do you think my mother could learn it? She's flat out turning a computer on let alone creating a user "sandbox" to run attachments on her email.

      The glory of Windows (be it good or bad) is that it makes communicating on the Internet really easy for those that can't do what you can. Unfortunately, the age old trade off of ease-of-use for security is still present although becoming less and less.

      It's hard to please everyone all the time, and if a software company had to focus on every angle to the Nth degree all the time, then we'd never get software out the door. Sure Linux is well developed from a security standpoint, but it's no where as easy to use as Windows/Mac for the average consumer.

      If Windows had of been as security focused as Unix from day one, then I doubt it would be as rich in user interface and ease of use as it is today. Hopefully Windows 2000/XP will pick up some of the slack reputation that the Windows 9x line has earnt Microsoft in being inherently insecure, but only time will tell.

      Just remeber it's all very easy from where you stand, and not so easy for others, even the software companies.

    2. Re:It's the OS, stupid. by dodobh · · Score: 2

      First
      $strings suspicious.exe|more

      /etc/shadow

      Why does this need to access /etc/shadow?
      $cp suspicious.exe /chroot/user/tmp
      $su - chroot_user
      chroot_user@host]$ gdb suspicious.exe
      gdb>

      --
      I can throw myself at the ground, and miss.
    3. Re:It's the OS, stupid. by Belgarath52 · · Score: 1

      While I agree that Microsoft exaberates the problem through poor design, I think that the problem is really in that the general Windows user base is much less well educated in computer use than the Linux user base is. I strongly suspect that a worm/virus such as the one you describe in your example which first checked permissions, and then spat out a "This application must be run as user root" message would have similarly destructive effects upon the uneducated beginning Linux users out there, as a normal VBScript worm does under Windows, by asking you to open the attachment. People trust things that their friends send them, and don't think about it at all. If the worm/virus gave simple instructions on how to su, that'd likely be the end of that computer.

      If you or I were to get so suspicous a file under Win9X, we probably simply wouldn't open it. It's a pain to be restricted by the OS, but without being big brotherish (I know, it's coming), Microsoft can't protect people from themselves. The only way to do that would be to only allow windows (by default, anyway) to only run MS signed software. That'd be a Very Bad Thing for non-MS software companies and developers, but it'd stop stuff like this dead in it's tracks. Just make the signature-only feature hard enough to disable, and no one who knows how to disable it will be stupid enough to run trojans. Problem solved.

      That said, I don't think that it's worth the damage that this feature would do altogether. Therefor, this is something that we're going to have to deal with until people become better educated in computer usage, which will probably take a long time if it ever happens at all.

    4. Re:It's the OS, stupid. by maunleon · · Score: 1

      What you are saying is that there is no damage that can be done if you are not root?

      How about forking a backdoor trojan such as subseven? What if the payload contained an attack that would give you root? Or mailing out something sensitive? Heck, you don't need special permissions to ICMP flood an internet host under the command of a malicious user.

      Again, I resubmit that it's the user, not the OS. and because of posts like this, Linux would be a nice target, if only more than 10 people were using it on the desktop. It's all this 'my shit is better than thou's' attitude.

    5. Re:It's the OS, stupid. by tshak · · Score: 2

      Right, because the average user knows what su, chown, chmod are for.

      --

      There is no longer anything that can be done with computers that is nontrivial and clearly legal. -- Paul Phillips
    6. Re:It's the OS, stupid. by morcego · · Score: 2

      I hope you are not serious, or you are in for a nasty surprise.
      What is this binary exploit something on your machine ? Remember a worm that was attacking RH machine some time ago ?
      Never, ever, not even consider running something you are not VERY sure of in a production machine. If you want to test it, make sure you do so in a machine you can easily reinstall, and that is not connected to any network.

      ---

      --
      morcego
    7. Re:It's the OS, stupid. by OSgod · · Score: 2
      Yes, and this works well under NT/2000 as well.

      The unfortunate fact is that most users would not do this no matter what OS they are on. It requires thinking differently -- starting from a my system is secure perspective. Users in general start from the "my system is easy" perspective.

      So in general, on Linux, the end user would always log in as root. Would execute any binary executable the minute it was received as root. Would say that Linux (or any other OS) is insecure.

    8. Re:It's the OS, stupid. by Waffle+Iron · · Score: 2
      But if you can't even train people to not click on unknown attachments, you'll never train them to create a bogus account to run an attachment in. The outlook worms work just fine with default user privileges, so Unix doesn't really solve the problem any more than NT/Win2K do (under which you can also create bogus accounts in 30 seconds, BTW).

      The real root of this problem is that MS created an application (Outlook) that is an ideal breeding ground for social engineering attacks. In theory, a similar application could be created for Linux; we just don't expect that such an app would become popular on this platform. (But you never know ... they're porting .NET as we speak.)

  70. Re:How long? by Black+Parrot · · Score: 1

    > > Simple solution - the virus should scan Wired for its name every hour. When it finds a match, the fun begins.

    > Good idea... but who assigns virus names?

    This one would surely be called The Slashdot Virus, since all the probes would leave everyone thinking that Wired had been slashdotted.

    --

    --
    Sheesh, evil *and* a jerk. -- Jade
  71. Re:How long? by sunking · · Score: 2

    Simple solution - the virus should scan Wired for its name every hour. When it finds a match, the fun begins.

    -sam

  72. Re:Sheesh... by AeiwiMaster · · Score: 1

    You could mount the home directory with the noexec option this will prevent users from
    running programs from thier home dirctory.

    Knud

  73. Re:Unthinkable - Thinkable by AstroJetson · · Score: 1

    I still don't use HTML mail... I saw the Exchange servers usage grow when the upper management wanted to use HTML enabled mail because it looked pretty.
    I'm with you....I don't use HTML e-mail either. Mainly 'cause I'm just kind of old-school that way and think that e-mail should be text. But it's hard to make a case against HTML (to the PHBs) when you can get 45GB for $100 US. For that amount of money they'd rather have their pretty e-mail, with 7 differnt fonts in 4 colors.

    Thankfully, I work at a new company and their policy is - NO MS OUTLOOK PERIOD.
    Well, it's nice to see some enlightened people out there. It gives hope to the rest of us.

    --
    Admit nothing, deny everything and make counter-accusations.
  74. Re:Clear up some misinformation. by realkiwi · · Score: 1

    You can add German to that list

    --
    realkiwi
  75. Re:IMNSHO by realkiwi · · Score: 1

    stay away from the yellow kiwis please...

    --
    realkiwi
  76. Re:GET A DAMN CLUE PEOPLE!!! by Grimwiz · · Score: 1

    You missed the point,

    To be infected in the first place, you've got to receive the file by email. Obvously the sircam code won't be running on your machine before you got infected.

    I didn't see any definitive information on whether it requires user stupidity for them to double-click on the file or if it leverages an outlook vulnerability to cause the file to be run automatically.

    The discussion on SMTP was to point out that it can send itself out using its own resources and not depend on any email client.

    Tim Towers

    --
    -- Don't believe everything you read, hear or think
  77. Re:solution: don't use outlook by Grimwiz · · Score: 1

    If your email client allows attachments and you download and run it you will get infected.

    Even things like hushmail (encrypted).

    Unfortunately people can't be protected from determined stupidity.

    Tim

    --
    -- Don't believe everything you read, hear or think
  78. Re:Why continue using Outlook? by PovRayMan · · Score: 1

    You should not open anything remotely suspicious no matter what platform you are on!
    I mean... it's not like other platforms are immune to stupid users...


    Well, that's always true but in all honesty I've never really heard of a *NIX/MAC/QNX/BeOS virus or script that executes evil commands. I just wrote "Win32 platform" because it is by far the most susceptible OS to viruses.

    But if other systems are known to have attempts of attacks, I'd be interested in read about it.

    ----------

  79. Re:Why continue using Outlook? by PovRayMan · · Score: 2

    For me I just use...

    mozilla.exe -mail

    It's basically the old school Netscape Communicator email client with a dash of red lizard hehe.

    I don't believe it has the email attachment flaws Outlook is prone to, but anyone who decides to see the attachments included deserve what they get. It should be common sense to not open anything remotely suspicious if you're on a Win32 platform.

    Anyways, I like using Mozilla's mail client. Reminds me of the days when Netscape was decent.

    ----------

  80. Re:How long? by Restil · · Score: 2

    Reformating really isn't the worst thing that could happen. It'll hurt anyone who doesn't keep backups, but they're likely to get hit by a random non-virus windows bug anyways. Something that is really nasty would SLOWLY corrupt documents, so they get backed up and it will be months before the damage is realized and simply restoring the previous night's backup won't work, because you never know what's dangerous and what isn't and how far back it goes and what other payload is sitting around waiting.

    -Restil

    --
    Play with my webcams and lights here
  81. Re:This thing has it's own SMTP server... by odaiwai · · Score: 1

    150Mb? What the hell is in there? Does incoming mail get some kind of virtual reality tour of the Universe?

    dave

  82. Re:procmail filter, anyone? by odaiwai · · Score: 1

    :0:
    * ^To: *
    /dev/null
    # this script ensures no further virus attacks.

    dave "HTH, HAND."

  83. News five days old... by EvilMagnus · · Score: 2
    Norton released patches for Sircam on the 18th, and even AICN reported on this virus before slashdot. ;-)

    That said, I popped in to work this weekend to upgrade my servers AV protections (liveupdate refuses to work on my email servers. grr.) and, sure enough, I've been averaging one infected document every two hours. So it's possible we'll see a whole host of fun come Monday, 9am, when all those folks who got infected emails over the weekend open them up...

    --
    -EvilMagnus
  84. Re:Why continue using Outlook? by Kidder · · Score: 1

    I run Outlook and Outlook Express and I've never had a problem with the "viruses". I attribute this to the fact that I do not open attachments and am generally wise in the way of the internet. As the virus issue is a non-issue for me and I really, really like the way OE works (and Outlook, to a smaller degree), I have no intention of switching to anything else.

    Except maybe pine.

  85. Re:Sheesh... by mpe · · Score: 2

    Joe emails a rogue application to Jane, Jane runs the code which then emails itself (and an arbitrary document) to people in Jane's address book. Sounds like something that could be implemented on any OS, doesn't it?

    The last point is untrue. Since in order for this to work you need mail software which treats emails as executable code. Something which is rather specific to Windows apps (and Windows itself.)

  86. Re:This isn't really an Outlook worm by unapersson · · Score: 1

    Not strictly true, as it relies on two Outlook behaviours: 1) hiding the file extension and 2) automatic execution of attachment that you click on.

    I had three copies of it yesterday, all with attachments called something like:

    filename.doc.com

    If I'd be using Windows & Outlook I would have seen:

    filename.doc

  87. Re:How long? by csbruce · · Score: 2

    This is correct. So far, Outlook viruses have been mostly just an irritation. Nothing of any substance will be done by Microsoft or users in general until the shit really hits the fan. If half the PCs on Earth were suddenly wiped out, Microsoft would actually take some heat. Virus writers need to grow some balls!

  88. Re:documents by NettRom · · Score: 2
    but from all the stuff I received over the weekend, I noticed it's just the name of the document it uses...

    You're either incorrect or a lucky recipient. The largest infected e-mail I've received so far had an attachment of 17.5MB.

    Oh, I forgot, that's the average size of a Windows-binary.

  89. Re:What does your post have to do with the OS? by catfood · · Score: 1
    The scripting issue is, I suspect, where it really wins. If a user can start something with 'saferun some_app' instead of just 'some_app', it's much less of a hassle, and it's that much more likely that a user won't do something stupid.

    saferun doesn't quite solve all problems though.

    The malicious code could do something even more clever, like not dropping or revealing its payload unless it can figure out that the current user has some realistic-looking number of files in its home directory. For example.

    The saferun idea is useful but not totally foolproof.

  90. Re:Sheesh... by Malcontent · · Score: 2

    Umm yea but if I got this virus in linux it would not effect me at all right?

    --

    War is necrophilia.

  91. Re:Sheesh... by Malcontent · · Score: 2

    "If it were a Linux binary it would"

    No it would not really. I know of no linux email readers which let you execute an attachment by clicking on it. Also There is no such thing as a "standard address book" in linux so the virus would not be able to spread itself so easily. BTW the same applies for eudora. If doubleclicked on a .VBS file with eudora The virus could not propagate.

    The point is that windows and outlook have a myraid of security holes which are very easy to exploit by any body who can hack out a few lines of VB. Other systems don't.

    --

    War is necrophilia.

  92. Re:How long? by Mr.+McGibby · · Score: 1

    This of course would make it so easy to find you, that my blind grandmother could do it while baking cookies.

    --
    Mad Software: Rantings on Developing So
  93. Re:What does your post have to do with the OS? by Dr.+Smeegee · · Score: 2

    But all that rebooting gives me time to leaf through my certifications.

  94. Not that new by gizmo_mathboy · · Score: 2

    This is relatively old news. There is a previous Wired article from Friday discussing this virus. I would say the only thing new is that all of the anti-virus house have come to an agreement about its name, what it does, and how it does it.

    1. Re:Not that new by baptiste · · Score: 2
      This is relatively old news.

      Perhaps, but it is spreading faster and faster which makes it news. I'm starting to see more of these damn emails than SPAM! Which is scary! Mostly from folks I don't even know but probably sent email to at some point (I own a small business) Of course I had to laugh when I sent a detailed email reply to one user saying he'd been infected and sending him to sarc.com for more details. He replied back yelling at me for trying to infect his computer with an obvious virus email and suspect URL (it wasn't HTML format - just plain text) Makes it clear why some folks get infected. *cough*idiots*cough*

  95. Re:How long? by cyberdonny · · Score: 1

    Errhm, you might as well make the magic word "the", or let the second phase start immediately. Indeed, considering how many viruses are out there, it would be hard to avoid triggering the new virus by talk about other virii...

  96. Re:documents by cyberdonny · · Score: 2
    > anyway, one stupid thing is that all the reports call it "privacy" sensitive because it sends out personal documents from your drive... but from all the stuff I received over the weekend, I noticed it's just the name of the document it uses... the actual content is the virus itself; an executable disguised as a document...

    I dunno about this virus, but the Magistr virus only mails out full documents with a certain (low) probability. I.e. most of this virus' mails will just use the title of the document, or small extracts as the mail subject, but every now and then, a full .doc attachment would be sent out. Probability of this happening is very low, but not zero.

    The interesting thing about this is that it gives "cover" to disgruntled employees who wish to deliberately leak confidential stuff to suppliers or to competitors: as the virus exists, and its modus operandi is "well known", those people now have an easy excuse ready if they're caught. Quite a cunning move of the virus writer actually!

  97. Re:How long? by cyberdonny · · Score: 2
    > all one would have to do would be put some unique, memorable name or catchphrase somewhere within their infection/payload scheme.

    ... and hope that the anti-virus community names the thing before they reverse-engineer it sufficiently enough to find out what triggers the active phase... Man, would they look stoopid if they named it the "catch me now" virus, and as soon as news about it hit the major outlets, its very name would trigger armageddon...

  98. Re:How long? by cyberdonny · · Score: 4
    > They can't do anything *too* malicious without calling enough attention to it that the spreading slows down.

    Actually, there is a simple cure to this, and it has even been used by Code Red: operate in two phases:

    • A spreading phase, where you don't do anything malicious, except infect other machines. Best if done as low-key as possible: only attempt to infect those people that use Outlook (analize headers of recently received mails), attach yourself to documents that the user sends, rather than making up documents of your own, etc.
    • An active phase, where the fun really starts: DOS the withehouse, mail out confidential .doc files, thrash the BIOS and hard disk, etc.
    The difficult part of course is timing. If the active phase starts too early, you may not have enough of an "installed base" to really wreak havoc. And if it starts too late, a cure may already exist by then.
  99. Re:How long? by cyberdonny · · Score: 5
    > Simple solution - the virus should scan Wired for its name every hour. When it finds a match, the fun begins.

    Good idea... but who assigns virus names? It was my understanding that the names under which a virus is known is usually not chosen by the author, but by the anti-virus community once it is "discovered". Thus, it would be rather hard to scan for its name, as it will not be known at the time of writing...

  100. Re:An observation... by dr+bacardi · · Score: 1

    Wow!

    That means I can pull the pencils out of my power supplies now.

    Thanks!

  101. MacOS by chrysalis · · Score: 2

    Are Macintosh running Outlook also vulnerable to these shits ?

    -- Pure FTP server - Upgrade your FTP server to something simple and secure.

    --
    {{.sig}}
  102. Re:How long? by Leonel · · Score: 1

    Make the word "virus". Yeah, but once they discover he forbidden word, it will be really funny see they having to avoid mentioning it in the news :
    This new v1rus is set to spread once the word "v1rus" is out.

  103. Re:Sheesh... by Dwonis · · Score: 2

    ( ... ) is a subshell. The gunzip does nothing. if the ".gz" file isn't actually gzipped, it will be executed by the "source" command.
    ------

  104. Almost. by jcr · · Score: 2

    Not using outlook isn't quite enough to solve this problem. The long-term solution, is not to use anything from a company that's so bloody incompetent that they'll not only put a Turing-complete interpreter into all kinds of apps that don't need one (like mail clients, word processor apps, etc,) but having done so, they give the interpreter access to EVERYTHING.

    The long and short of it is, that microsquish still fails to understand even the rudiments of multi-user systems, let alone networked systems that require serious security. MicroSquish apps and OS's are unsecure and unsecureable, and it's about fucking time that people started to get fired for buying this kind of shit.

    -jcr

    --
    The only title of honor that a tyrant can grant is "Enemy of the State."
    1. Re:Almost. by imipak · · Score: 2
      The long and short of it is, that microsquish still fails to understand even the rudiments of multi-user systems, let alone networked systems that require serious security. MicroSquish apps and OS's are unsecure and unsecureable, and it's about fucking time that people started to get fired for buying this kind of shit.

      Sir, you are mistaken! (Well, actually, you're trolling like a penisbird, but wtf, I'm on holiday this week :D ) Some of Microsoft's software is broken in some respects - certainly, Outlook's security model is one of the best (worst?) examples. But it's not all insecure, and it /definitely/ isn't unsecurable to the typical level of security required for day-to-day corporate desktop use (and even departmental file & print.)

      But have you taken a look at Bugtraq recently? In my mail right now I happen to have 1084 mails since the 18th of May. And I'm sorry to tell you that (a) the vast majority concern Linux, BSD, or commercial Unixen; (b) many are remote root vulnerabilities; (c) for every conscientious sysadmin who checks every post, every day, and immediately applies (or starts regression testing to apply) relevant patches, there are *hundreds* of admins who don't even read Bugtraq, or distro security alerts, let alone apply the damn patches.

      Some of these holes have been absolutely horrendous; the ftp globbing issue that turned out to be a bug in the C library and affected many different ftp daemons. The current ssh vulnerabilities. The BIND fiasco. xinetd. Mutt. fingerd. yppasswd. Sendmail. Tripwire, FFS!! And so on, and on.
      --
      "I'm not downloaded, I'm just loaded and down"

  105. Exchange Calendar is BROKEN. by jcr · · Score: 2

    >I have Outlook running for my work email, even though it is the viral target of choice, becuase having it run is required for the Exchange Calendar system to work

    Let's see... A mail-based calendaring system requires a particular client to work?

    Back in 1986, I wrote a mail-based calendaring system (using NeXTSTEP as the GUI), which worked just fine with generic text-based mail clients if you didn't have NeXTMail to show you the spiffy 'RSVP' envelope icons.

    If your company puts up with apps that force you to use particular other apps to get generic functionality (like, say, MicroSquish Exchange), then it has a serious management problem.

    -jcr

    --
    The only title of honor that a tyrant can grant is "Enemy of the State."
    1. Re:Exchange Calendar is BROKEN. by imipak · · Score: 2
      If your company puts up with apps that force you to use particular other apps to get generic functionality (like, say, MicroSquish Exchange), then it has a serious management problem.
      Only if other companies behave differently. If (as is indeed the case in the real world) 99.9% of companies have IT Directors or VPs who are convinced that Microsoft Groupware is the bees knees (wow, look! you can email appointments back and forth, book time slots, see attendee's schedule to see if there's a better time..!) then they are all equally handicapped. You see much the same thing with Big Bang systems like Oracle Financials or SAP; and on a wider basis, with management fads like TQM, flattening the pyramid, customer focus, 360 degree reviews and all the rest of the buzzword bullshit. They're the most sheeplike, gullible people imaginable. No wonder companies like Marconi lose 90% of their value in 24 hours when it turns out their expensive Solutions are less use than a bunch of spreadsheets.
      --
      "I'm not downloaded, I'm just loaded and down"
  106. Sendmail Filter? by akiy · · Score: 1

    Does anyone have any pointers toward a sendmail filter to keep the Sircam virus from spreading? I've installed a recipe in my .procmailrc for my own account, but it would be nice if I could screen the virus out for the other users on my system...

    --

    --
    http://www.aikiweb.com - AikiWeb Aikido Information

  107. Re:Why continue using Outlook? by norton_I · · Score: 2

    Yeah, or you could put ANSI codes in zip file headers to bind 'e' to format c:. (if they had ansi.sys loaded)

    It isn't like MS invented this type of security hole, you would just think that after this many years, things would have gotten better, not worse. It used to be that when a problem like this was discovered, the author would do something about it: strip ANSI codes, etc. Instead, MS, dealing with an audience about 100 times less computer literate on average than the people above, insits on using user education, rather than the "right" solution of making a language and sandbox that lets people have dancing babies but not damage their system.

    I don't mean to knock user education: I am all for it. But in this case, even if possible, user education can't solve this problem. There is *no* way for a user to determine if a file is safe to open, without actually doing so.

  108. Re:Why continue using Outlook? by The+Musician · · Score: 1
    This isn't a problem with Outlook, it's a problem with idiot users clicking on every damn thing they're emailed.
    Furthermore, Outlook actually helps out the "idiot" users. I have all patches and security enhancements setup for my Outlook client, and when I got copies of this trojan in my email, Outlook would not let me open the executable attachment. The problem is users doing silly things, and Outlook can be configured to be safe. An argument can be made about default configuration, but that's another matter. This isn't a stody about a hole in MS software; it's a problem with users and with badly maintained software.
  109. Re:Once again I miss out on everything by rtaylor · · Score: 1

    All this thing requires is that you can run a windows executable. Receive it in mutt, save to harddrive and run from wine and you should get the same results.

    --
    Rod Taylor
  110. Re:It's the culture, stupid. by Tsian · · Score: 1

    It should be mentioned that Outlook XP will complete block .BAT and other 'dangerous' extensions, While this is annoying, it does protect the user. In other words, if people had Outlook XP the virus wouldn't be spreading (not that I'm plugging XP here).
    ------------------------------------

  111. Re:Why continue using Outlook? by dimator · · Score: 2

    I really don't know how one company's "good" name can dissuade those with decision making power (read: IT departments) to not choose a more secure solution for their firms/comapnies/clients. I mean, it's kind of important.

    Maybe this is the software equivalent of "it's not what you know, it's who you know."

    (Btw, you really can't compare Communicator's mail program to Outlook in terms of features and functionality, unless you meant Outlook Express.)


    ---

    --
    python -c "x='python -c %sx=%s; print x%%(chr(34),repr(x),chr(34))%s'; print x%(chr(34),repr(x),chr(34))"
  112. Re:solution: don't use outlook by Jace+of+Fuse! · · Score: 1

    Biggest step to preventing this --

    Don't execute the attachment!

    Even with the preview pane turned on, a user still has to click an EXE attachment.

    Most users with any sense turn off the preview pane to keep java and html type messages from automatically downloading images (more than likely web-bugs), but more importantly, to keep your system from always showing at least one e-mail if your Outlook window is opened.

    The only thing worse than security threats from the outside is security threats from the inside.

    Naturally - I don't even open e-mail with attachments from people I don't know. And attachements from people I do know are only looked into if they are data files of some kind. (Real common sense stuff here, people.)

    And most importantly - I show all file extensions. I think hiding the file extension, EVEN on known file types is something Microsoft should never, ever, ever, EVER even allow, but the OS ships with this "feature" on by default.

    It's bad enough that the OS relies on filename extensions, but to turn around and hide them and dummy users as to the true names of their files just makes things worse.

    The damange one can do with shortcuts alone is scary ... but at least Outlook will show you that a file is a .PIF -- too bad most users haven't got a clue what one is.

    One link to DELTREE.EXE /Y C:\WHATEVER\*.* >C:\WHATEVER\OWN3D.TXT is all it takes... and after clicking the pretty little (cleverly named and disguised) icon and not getting any results they won't even know they've just wiped something off of their system. *sigh*

    "Everything you know is wrong. (And stupid.)"

    --

    "Everything you know is wrong. (And stupid.)"

    Moderation Totals: Wrong=2, Stupid=3, Total=5.
  113. Re:How long? by BlueUnderwear · · Score: 2
    > Simple solution - the virus should scan Wired for its name every hour. When it finds a match, the fun begins

    Or, even better: every now and then, download the signature updates from McAffee, Norton, Symantec, Kaspersky, whatever, and as soon as its own signature appears, let the fun begin ;-)

    --
    Say no to software patents.
  114. This isn't really an Outlook worm by mabinogi · · Score: 1

    From reading the articles, it doesnt look like you can really blame outlook for this one..

    The file is a .exe...NOT vbs, so naturaly it can do whatever it wants....it does the SMTP stuff itself, and just happens to look at the Outlook address book to get it's list of email addresses. (as well as going through the temporary internet files directory)

    There's no real reason why it couldn't have been written to look at the netscape address book too.....except that it probably wasn't worth the effort...


    --
    Advanced users are users too!
  115. Re:Why continue using Outlook? by jesser · · Score: 1

    um i only get it for *.vbs *.exe and
    so on..

    never ahd it for *.rts *.txt and so on


    Maybe I'm using an old version, but Windows Update hasn't offered a "critical update" to make the dialog come up less often.

    --
    The shareholder is always right.
  116. Re:Why continue using Outlook? by jesser · · Score: 4

    This isn't a problem with Outlook, it's a problem with idiot users clicking on every damn thing they're emailed.

    Outlook Express, at least, has a horrible user interface for attachments. First, *any* attachment with *any* extension will trigger the dialog, which means users will ignore the dialog after seeing it several times. Second, it conveys the possible threat from the file type only by displaying the extension, and many users haven't memorized what extensions are safe and which aren't. Third, it only asks that you "be certain that [the] file is from a trustworthy source", which doesn't help much if the "trustworthy source" is infected by the same attachment.

    --
    The shareholder is always right.
  117. Re:What does your post have to do with the OS? by syates21 · · Score: 1

    Find an executable file somewhere in the explorer interface of your Windows 2000 machine (e.g. on the desktop).

    Shift-Right Click on the file and select "Run As..."

    You can then type in the username and password of the account you want to use to run the executable.

    It's handy for doing things like running something that needs to be an admin, without logging out and back in.

    It could also be used for the purposes discussed here, but you would need still need to worry about locking the account down somewhat.

  118. Re:Why continue using Outlook? by szcx · · Score: 2
    I've Been using Netscape Communicator's E-mail program for years, without a problem.
    All it takes is for the trojan author to support Netscape's address book format and hey-presto, Netscape is affected. Someone ports the trojan to a Linux email client and now Linux is affected. This isn't a problem with Outlook, it's a problem with idiot users clicking on every damn thing they're emailed.

  119. Re:Sheesh... by szcx · · Score: 2

    If it were a Linux binary it would. And what if it is a CLR binary? If you want a reason to fear Mono/.NET, there it is.

  120. Re:Why continue using Outlook? by szcx · · Score: 2
    WRONG! The trojan in this article not a scripting exploit. It's a user exploit pure and simple. It relies on a user knowingly executing it.

    I just got a user who sweared never opening any attachment has his computer infected with this.
    Users always swear they "didn't do anything!" when they fuck something up. 99.9% of the time it's not true. Yes, HTML mail is evil. Yes, scripting exploits are evil. But this case is neither. So put down the bold tag and exclamation marks, there's no need to get worked up.
  121. Re:Why continue using Outlook? by szcx · · Score: 3
    No, they don't. They rely on the user executing the code. Have someone DCC the attachment or FTP it from somewhere. You have to run it, not the client. That's why it's a trojan, fool.

    This sort of trojan can theoretically be ported to any platform that has an email client and an address book.

  122. Re:Sheesh... by szcx · · Score: 4
    Incorrect. This trojan is executed by the user not the email client. It arrives as a file attachment, just like any other attachment. It comes down to the user having sense enough not to choose to double-click everything they see.

    It is exactly the same as if the user downloaded the trojan from an FTP site or through Gnutella, it's strictly an application. It doesn't rely on being received via email, all it needs is for the user to choose to execute it. Now if that application (trojan) happens to be a Linux executable, it's going to run when the user tells it to run. It's going to go ahead and read whatever address book it can find and spam everyone with a copy of itself.

    It's naive to think this problem only affects Windows users. It's only a matter of time before someone creates a Mac or Linux port.

  123. Sheesh... by szcx · · Score: 5
    You know, for all the bitching Slashdot does about the media confusing "Hacker" with "Cracker", it's somewhat ironic that the Slashdot editors don't know the difference between a "Virus" and a "Trojan".

    Of course, then the headline would have to be "Idiot Users Still Exist, Nobody Surprised" -- doesn't really have the same aire of panic though, does it?

    Joe emails a rogue application to Jane, Jane runs the code which then emails itself (and an arbitrary document) to people in Jane's address book. Sounds like something that could be implemented on any OS, doesn't it? You can't patch user stupidity.

    Anyhoo, let the Microsoft bashing begin! Everyone get your pitchforks and flaming torches, but leave your dictionaries at home.

    1. Re:Sheesh... by YKnot · · Score: 1

      Attach your favorite malware bash script and tell them to "extract hot porn from the archive. Just copy the attachment to your homedirectory and type 'gunzip (source ~/hotporn.gz)'." I doubt that anyone dumb enough to doubleclick on mailattachments won't fall for that.

    2. Re:Sheesh... by YKnot · · Score: 1

      make that
      gunzip <(source ~/hotporn.gz)

    3. Re:Sheesh... by YKnot · · Score: 1

      Even the dumbest users know what rm does, but gunzip'ping a file which ends in .gz might sound reasonable. To a "user" the line reads like "extract something for me, the source is this archive. Dunno what the () are for, but they won't hurt. The only program run is gunzip, and that doesn't execute foreign code, right?" ;)

    4. Re:Sheesh... by purplemonkeydan · · Score: 2
      Indeed. If/when Linux is mainstream, and newbies are using it, the potential is there for script viruses to be invoked.

      Most Linux systems have Perl. All it would take is a Perl script that scans your Mozilla or Netscape prefs file for info, parse the address book, and bam! It replicates.

      The average luser will click on anything, regardless of whether its .vbs or .pl.

    5. Re:Sheesh... by chuqui · · Score: 2

      I'm a little surprised we haven't seen java viruss start to propogate -- since they can be transmitted the same way as windows-specific ones, but could be programmed to be more platform independent.

      --
      Chuq Von Rospach, Internet Gnome = When his IQ reaches 50, he should sell
    6. Re:Sheesh... by archen · · Score: 1

      well Microsoft (in their concern for security) are one step ahead of you, since they're not going to include the JVM anymore. Ahh.. I feel safer already.

      Hey, what does this Active X thing do?

  124. Recycle bin by inf0c0m · · Score: 1

    what about those of us who have the recycle bin disabled? aka we have the automattically delete files? does it still exist then?

    1. Re:Recycle bin by sasha328 · · Score: 2

      Yes it does. The "austomatically delete" items option only works during the action of putting/moving files into the "recycle bin". This is the same process as manually copying the file (in a dos prompt) to the "recycle bin" folder location; the gui would not know about it.

  125. Re:Why continue using Outlook? by Jens · · Score: 3
    "Most human beings on the face of the earth are not technically minded and DO NOT WANT to understand the details of how the tools they use work."

    Right. They only have to understand how to use them, and that includes understanding possible consequences of using them incorrectly.

    Morale: "Messer, Schere, Gabel, Licht, ist für kleine Kinder nicht." Don't give someone who does not know how to use it, a tool that could become hazardous.

    Just as an example: Today's internet is swamped by users who want to send e-mail "cuz its c00l" but probably don't know what an attachment is. They don't need to know - as long as their email client does not support attachments.. As soon as they get the possibility to send attachments, they must learn

    • how to send and receive them (of course)
    • how not to trust them
    • why not to send 20MB files to unsuspecting modem users (what's a modem?)
    • why not to send binary files (what are those?) to Usenet newsgroups (what are those?)
    • etc.

    You don't give a 15-year old a 200mph racing car just because "everyone has one". Similarly, you don't give someone without training a gun. (Yes, I know it's different in the US. Does that make me wrong?)

    Use the tool that do the job. And make sure the user is educated. Simple tool: simple education. Powerful, complex tool - detailed education. Simple as that.

    (Yes, I know I'm dreaming. Please reply to slashdot at jensbenecke dot de if you are interested in serious discussion. I might miss you here.)

  126. Re:solution: don't use outlook by Greyfox · · Score: 2
    You mean like this one?

    Yes, it's old news and yes it's been fixed but I think it illustrates quite well that you can never blindly trust your apps to be secure, not matter what platform you're on.

    --

    I'm trying to teach myself to set people on fire with my mind... Is it hot in here?

  127. Re:Once again I miss out on everything by pompomtom · · Score: 1

    [blockquote]I have to run Lotus Notes at work (pity me! :-)) [/blockquote[br][br]I, too, use Notes at work, and I'd prefer the virii...

    Buckets,

    pompomtom

    --

    Buckets,

    pompomtom

    "There's an exception to every rule. Except for some rules"
  128. Re:Why continue using Outlook? by steelhawk · · Score: 1

    It should be common sense to not open anything remotely suspicious if you're on a Win32 platform.

    You should not open anything remotely suspicious no matter what platform you are on!
    I mean... it's not like other platforms are immune to stupid users...

    --

    --
    Ner lbh sebz gur HFN? Gura lbh'ir whfg ivbyngrq gur QZPN!
  129. New Internet Law on the drawing board by Kwikymart · · Score: 1

    You now need an IQ greater than that of a pebble to use email.

    thank you


    --

    Buying a Dell computer is equivalent to dropping the soap in a prison shower.
  130. Microsoft *DID* make a patch. by Christopher+Biggs · · Score: 1

    Microsoft released a patch ages ago to turn off executable attachments et. al.

    Nobody installed it. The kind of people who went looking for it already knew better than to run attached executables. The kind of people who are victims of these trojans hated the patch because, those people WANT to be able to click on attachments and have them run. Living without the latest animated christmas card is intolerable to them.

    (Or rather, they are unable to perform any more complicated procedure, so it's single-click or nothing for that user base.)

    --
    -- veni vidi nuclei deceri --- I came, I saw, I dumped core.
    1. Re:Microsoft *DID* make a patch. by NoOneInParticular · · Score: 1
      Yes, and some smart ass company has taken this as a cue that this is bad. Reading Bruce Schneier's latest Crypto-Gram newsletter, for all of you people that are restrained by Outlook's new and improved security, there's good news;

      Outlook Redemption is a developer tool specifically designed to let Outlook applications evade the Outlook security patches and built-in features of Outlook 2000 that warn users when applications send mail on their behalf, read their address book, and so forth. This can't possibly be a good idea.

      Outlook Redemption link

      On the other hand, the "security patch" is a really terrible idea, too; it won't let you receive bunches of different types of attachments, rather than letting the user choose. And there's no way to uninstall the security patch, once installed. That's what inspired this tool, I'll bet.

      Thank Bruce for this info and let's wait and see if this thing becomes popular. Let the games begin!

  131. Re:solution: don't use outlook by rosewood · · Score: 1

    Actually - Try Outlook XP if you must outlook and are stupid enough to become infected. If anything (sadly including palm syncs) trys to access Outlook - it gives you a delayed pop up asking if it is all good.

  132. i don't think it's an "outlook" virus by jon_c · · Score: 1

    Hell, i wouldn't even call it a virus. more like a worm. I don't belive it uses VBA or VBScript, from what i can tell it's just an executable.

    the interesting text from the ZDnet artical:

    it will append the file name with either .exe, .bat, .tif., .com, or .link. If it uses .link or .bat, the virus will essentially "neuter" itself, Trilling says, ceasing to operate.


    .exe, .bat, .tif etc.. can all be executables, but in difference contexts. if you rename a .bat to .exe it won't run, so for this to work it would need to change the structure of the file each time; this would make it a polymorphic worm.

    I would also like to note that the exact same type of worm could work on any operating system, the only reason it targets windows is because of the large user base of people who don't know better.

    btw, i got this one in my yahoo account. it was marked at "bulk/junk" mail my yahoo's filters, and yahoo's virus scanner flagged it.

    -Jon

    --
    this is my sig.
    1. Re:i don't think it's an "outlook" virus by Gordonjcp · · Score: 2
      .exe, .bat, *.tif* etc.. can all be executables

      Surely that should be .pif?

    2. Re:i don't think it's an "outlook" virus by archen · · Score: 1

      yeah, I got the pif one this morning. Now I'm no genius, but when was the last time you saw a .pif file that was over 3 megs? (I'm a M$DOS batchfile junkie, so I mess with them all the time). Anyone know how to remove the virus from the attachment so you can see what random file you got? I got a *.zip.pif, and I'd like to see what it is since my mailbox just got stuffed with this damn thing.

      then again maybe everyone will run away in fear from all those ".tif" files on their computer. Egads! My scanner makes viruses!

  133. Re:Why continue using Outlook? by jon_c · · Score: 1

    I don't think this worm uses any features of outlook, it's simply an executable attachment that does BadThings(tm).

    you could probably use whatever email client you want, as long as it's under windows it'll probably work.

    -Jon

    --
    this is my sig.
  134. *MOD UP* by jon_c · · Score: 1

    first thoughtfull post i've seen, thank you.

    -Jon

    --
    this is my sig.
  135. procmail filter, anyone? by Jeppe+Salvesen · · Score: 1

    after all, procmail is the basic unix tool of the trade in mail-worm-stopping. so - whoever wants a quick +5 informative should just come up with a nice procmail filter for the rest of us to benefit from..

    --

    Stop the brainwash

  136. haha by Jeppe+Salvesen · · Score: 1

    i'll remember that one if i ever get to be BOFH anywhere..

    --

    Stop the brainwash

  137. Re:What does your post have to do with the OS? by twitter · · Score: 2

    This marked as flamebait is an abuse of moderation! Parent is reasonable, non offensive and should be reviewed.

    --

    Friends don't help friends install M$ junk.

  138. Re:shutupshutup! by twitter · · Score: 2
    Don't worry, if the support mechanisms were in place to do this MS might have done it. It's not really there, as problems like this demonstrate, and they won't put it in either. It would cost about a billion $ to fix Windows, AKA the quick and dirty operating system (QDOS), and MS would rather spend that kind of money on Adverting the public.

    Too bad they are like that.

    --

    Friends don't help friends install M$ junk.

  139. I like em big and stupid. by twitter · · Score: 2
    Works great, and as a gigantor corperation, we can get away with it.

    So what do you do with the Boss's Word attachments? How do you keep him and his secretary from running comet cursor or some other more malicious trojaned piece of fluff off the web? Have you disabled Java in Netscape and MSIE?

    If you are so big, you might make a real difference and run a real OS! Good luck if you don't.

    --

    Friends don't help friends install M$ junk.

  140. What does your post have to do with the OS? by Carnage4Life · · Score: 4

    OK, so you've shown that if a friend emails you a suspicious .exe, you create a phony account with no permissions then run it from that account. This is also possible in Win2K and Windows XP. So what's your point?

    All you've shown is that you are an extremely paranoid person and not that your OS of choice is some fantastically secure manifestation of operating system design. Most Linux users I know would not go through all that trouble if mailed a perl script or executable (or heck, compiling some obsfucated source from someones .sig).

    And it's not just Linux, or other Unixes... VMS, NOS, NOS/VE, VM/CMS... IS there another OS out there that DOESN'T have proper ACL's and CPU/process limits?

    Windows' ACL support has been more mature than Linux's for a long time. Because you don't know about it doesn't mean it doesn't exist.

    --

    1. Re:What does your post have to do with the OS? by mr3038 · · Score: 1
      I don't want an email client to have the authority to create user accounts on my system!

      Of course it shouldn't be outlook itself that creates that user account. It's the installer software that installs the outlook.

      I don't know about your OS but I must have root access to install system wide software. For example apache installation script usually creates user account for it to run under but it doesn't have root access when actually running...
      _________________________

      --
      _________________________
      Spelling and grammar mistakes left as an exercise for the reader.
    2. Re:What does your post have to do with the OS? by Erasmus+Darwin · · Score: 2
      The malicious code could do something even more clever, like not dropping or revealing its payload unless it can figure out that the current user has some realistic-looking number of files in its home directory.

      Assuming that I always saferun the executable, I'm still safe. Imagine combining saferun with a CVS-like system such that the files that the executable works with get copied to the jail, the executable does what it does, then the changes get imported back into my home directory. The worst the executable can do is destroy the work that I've done during that session of using the executable (which isn't too different from the program crashing from a bug).

      But you're certainly right in that saferun isn't foolproof. However, when it comes to computer security, the realistic goal is to minimize risk, within a given usability-versus-security tradeoff. I would feel comfortable using saferun to run arbitrary code from semitrusted sources. If I were truly paranoid, I'd only trust personally audited source.

    3. Re:What does your post have to do with the OS? by Erasmus+Darwin · · Score: 3
      OK, so you've shown that if a friend emails you a suspicious .exe, you create a phony account with no permissions then run it from that account. This is also possible in Win2K and Windows XP.

      Can you do the following in Win2K/XP? (This is only half rhetorical -- I freely admit that I'm less than fully versed on Windows-based security. I suspect that at least some of these are doable in Windows.)

      • Run the program in a chroot jail
      • Run the program with ulimited resources
      • Set up a script to quickly and easily do the previous two items (and run it as a throwaway user account, as previously mentioned).

      The scripting issue is, I suspect, where it really wins. If a user can start something with 'saferun some_app' instead of just 'some_app', it's much less of a hassle, and it's that much more likely that a user won't do something stupid. It also limits damage to programs that're capable of breaking out of chrooted jails, when running as a user-level process. It's at least theoretically possible, but in the process, we've managed to cut out a lot of potential exploits.

    4. Re:What does your post have to do with the OS? by poot_rootbeer · · Score: 1


      I don't want an email client to have the authority to create user accounts on my system! That's absurd.

      Watch as a new Outlook virus gets unleashed that exploits Outlook's abilities and creates 100's of dummy accounts per second on every Winbox...

    5. Re:What does your post have to do with the OS? by Jucius+Maximus · · Score: 1
      "OK, so you've shown that if a friend emails you a suspicious .exe, you create a phony account with no permissions then run it from that account. This is also possible in Win2K and Windows XP. So what's your point?"

      Most Windowze users won't know how to do this.

      And even if they did, it would be too much trouble to save the attachment, close WinAmp, Excel, ICQ, mIRC, MSIE and log into a fresh account, execute the dubious attachment, and then get back to work.

    6. Re:What does your post have to do with the OS? by idej_retsam · · Score: 1
      To run an executable with no permissions I simply unattach the file and right click on it and chose runas->guest. Simple No?

      Actually, sir, you must hold the shift key when right-clicking to access the Runas function (assuming you have the service for this started.)

      Also, why would you be running it as Guest? Any admin worth his salt disables the Guest account within five minutes of a new install.

  141. Re:How long? by SimCash · · Score: 1
    Simple solution - the virus should scan Wired for its name every hour. When it finds a match, the fun begins.

    Good idea... but who assigns virus names?

    Better yet - scan /. for the phrase "Linux sux", then post some flamebait when you are ready to go to phase 2.

  142. spreads using the address book? by superpeach · · Score: 1

    I dont believe that the virus spreads by getting addresses from the address book, I have recieved 3 emails with random attachments to far and they are all from addresses I have never seen before and can't think of any reason why I would be in their address book.
    A friend of mine has also gotten one of these emails, and has no idea who the (apparent) sender is. Is this the same virus that I am thinking of? the one with the "Hi, I would like your opinion on this" kind of main text (I cant remember what it really is, but it's the same every time)

    1. Re:spreads using the address book? by codepunk · · Score: 1

      I think that is the one that we are talking about, and the same one I dissasembled in a hex editor and found it was written in delphi.

      --


      Got Code?
    2. Re:spreads using the address book? by morcego · · Score: 1

      Ever posted to a mailing list ?
      I kind of remember a version of Outlook (Express?) that automagicaly recorded every sender of every e-mail it touched on its address book.


      ---

      --
      morcego
  143. Re:spreads using the address book? - oops by superpeach · · Score: 1

    Oh, ok. It gets addresses from that Temporary internet files place too, which I guess has cached webpages in it. That would explain the random mails (even though I put .[AT]. instead of @ on any web-accessible stuff..)
    I should have read the wired article too before posting :)

  144. Re:It's the culture, stupid. by AsbestosRush · · Score: 1

    and email software needs to honor that request to stay competitive.

    Umm... There are only a small number of companies that charge for an email client, and MicroSoft isn't one of them. Where does comepetition come into this picture? The email client is usually used *because* other programmes that many people like (as the afore mentioned Calendar) to use with it. The competition is in the suite of products, not the individual parts.

    --
    EveryDNS. Use it. It works.
    AC's need not reply
  145. Re:solution: don't use outlook by -brazil- · · Score: 2
    Now it would be harder to do, but imagine a worm written in C that would spread as source code and then recompile on various client computers, thereby appearing to be different viruses on different platforms...

    Your imagination lags far behind reality. This is exactly how the first really widely spread virus, the Internet Worm spread in 1988.

    --

    The illegal we do immediately. The unconstitutional takes a little longer.
    --Henry Kissinger

  146. Re:An observation... by jred · · Score: 1

    I have noticed the same thing. The only time I get viruses at my home address is when I need to go update my grandmother's virus protection & clean her machine. But lately she's either learned how to do it herself (very possible) or learned not to blindly click on attachements (yah, right).

    jred
    www.cautioninc.com

    --

    jred
    I'm not a mechanic but I play one in my garage...
  147. Re:Yet again, we see by zerocool^ · · Score: 1

    makes me glad to have my .sig
    good 'ol fashion virus, right here
    user stupidity required to operate properly =)

    ~z

    --
    sig?
  148. Re:solution: don't use outlook by biohazard99 · · Score: 1
    This thing thinks it is cute, it sent one copy as a .com file (dos executable), the next time, it sent itself as .bat(DOS batch) file, so I got foo.doc.com and foo.doc.bat, hotmail scanners didn't catch it, but I hopped over to sarc as soon as I saw this bird, it was a little suspicious, why would the emergency management commission in my hometown be asking me for input on a saturday morning about a list of board members.

    Perhaps we need to make a Tuberculosis colony on the net for the people stupid enough to use outlook, partition them away from the rest of us.

    As for your mysterious .pif, it is a dos loader file, a kind of batch/link file, DOOM was the last game that I can remember making one on install. It basically calls command.com $CONTENTS_OF_PIF_FILE

  149. What would be really nice... by brianboru · · Score: 1


    Instead of random files from an infected computer, why can't somebody write a virus that would send me a job offer!

    Heck - all of these years forced to work with Outlook in corporate America ought to be worth something. ;)

    PS - anybody needing an out-of-work CTI Systems Engineer, please let me know!
    (I also do sprinklers...)

    1. Re:What would be really nice... by k2r · · Score: 1

      Thats not exactly what you asked for but:

      I got emailed somebody's resume from downunder. Maybe that is a fahionable way to apply for a job?
      "Hey, I'm as stupid as 80% of all users, give me the job!"

      k2r
      will they ever learn?

  150. An observation... by brianboru · · Score: 5


    One thing I've noticed is that it's always my work address that seems to get the viruses. In the 10+ years that I've had personal email addresses, I think I've only had maybe 2 even delivered to any account. (This includes free Outlook-enabled web accounts).

    There's only a couple conclusions I could draw from this:

    1) I am a supreme personal system administrator and do not let any common mundane virus issue affect the harmony of my smoothly oiled machine. (you do you oil computers, right?)
    2a) All of my personal friends are apparently not as stupid as they look (this one is hard to believe).
    2b) All of my work collegues are definately more stupid than they look (ok this one isn't so hard to believe). heh
    3) There is some kind of shield made up of impervious virus-fighting smurfs that protect my personal computer 24 hours a day.
    4) Karma (no not that kind)

    or most probable:

    5) Someone has been reading and deleting my personal email for years.

    1. Re:An observation... by enneff · · Score: 1

      Me too. I've never, ever recieved a mail-worm-trojan-virus-whatever in my 10 years of internet use.

      Weird.


    2. Re:An observation... by Da+Web+Guru · · Score: 1

      I don't get viruses at my work email address, nor do I get them at any of my other email addresses. Apparently no-one deems me worthy enough to (or at least attempt to) infect me with a virus. Does this mean that nobody likes me?

      --

      --guru

    3. Re:An observation... by Regolith · · Score: 1
      5) Someone has been reading and deleting my personal email for years.
      Sounds like Carnivore to me...

      -----
      --

      Bow before my sig, for it is good.
  151. Re:It's the culture, stupid. by softsign · · Score: 2
    I wish someone would actually use Outlook before disabusing it so much.

    I use Outlook, every once in a while I hop on over to Windows Update and get the latest security patches. It's painless.

    Guess what? I haven't been hit by SirCam or Code Red. I've gotten more than a few SirCam messages from people I don't even know (including one that was mailed to me by a stranger through my Slashdot sneakemail account).

    An up-to-date and properly configured Outlook will not arbitrarily execute EXE/COM/BAT binaries. It won't even open HTML attachments without permission. Mine won't even let me see the attachment I was getting from SirCam victims. I had to ssh to my mail server, use Mutt to save the attachment and run "strings" on it to see what it was.

    Not to mention, the really poor English in those SirCam messages is a dead giveaway.

    --

  152. Re:solution: don't use outlook by autechre · · Score: 5

    "It relies on the user executing the attachment, it doesn't execute itself."

    Unless, of course, it's something like Javascript code, or an unruly image tag. Exploits of this nature have been discussed on BUGTRAQ (more recently as an example of how poor PHP programming can cause security problems [duh!], so don't think I'm picking on Outlook here). Any mailer that displays even plain HTML as soon as you view the message can be attacked, and ones that do Javascript are INSANE.


    Sotto la panca, la capra crepa

    --
    WMBC freeform/independent online radio.
  153. Re:This thing has it's own SMTP server... by SuiteSisterMary · · Score: 2

    Microsoft is a big ole' relational database. It will use all available RAM. When other programs request RAM, outlook will relinquish some. This is normal behaviour, it is by design, and my usual response is 'if you don't want your programs using that RAM, why is it in your box?'

    --
    Vintage computer games and RPG books available. Email me if you're interested.
  154. Re:Praises to Pine.. Outlook? Would MS make a patc by SuiteSisterMary · · Score: 2

    However, our intrepid IT support person was also COMFORTABLE IN THE KNOWLEGE THAT THEY WERE RUNNING A FUCKING VIRUS SCANNER ON THE MAIL SERVER, thus removing any and all possibility of users receiving nastyness through their email, or accidently propegating it should it come in through another vector.

    --
    Vintage computer games and RPG books available. Email me if you're interested.
  155. Re:This thing has it's own SMTP server... by SuiteSisterMary · · Score: 2

    Holy CRAP I'm incoherent this morning. Microsoft EXCHANGE is a big ole' relational database (as opposed to being an OLE relational database) which will use all available RAM. When other programs want some, EXCHANGE will relinquish some.

    --
    Vintage computer games and RPG books available. Email me if you're interested.
  156. Re:This thing has it's own SMTP server... by SuiteSisterMary · · Score: 2

    The other thing to remember is that Exchange is NOT an email server. Exchange is a corporate groupware server. If you're not running a whack of people on an intranet who want to use Outlook for shared calanders, contacts, etc etc, you really don't want to use exchange.

    --
    Vintage computer games and RPG books available. Email me if you're interested.
  157. Re:It's the culture, stupid. by neoThoth · · Score: 1

    I agree with you, users really want these features with their email client. They are generally not going to be happy with a plain ASCII world. Not to mention the fact I use Outlook on one of my installations and it has the ability to TURN OFF all the features that allow these exploits (minus that one which over flowed the buffer just by receiving the message.. that was impressive). The sad fact is the market departments get to dictate that all this stuff (cool flashy not so secure and always prone to a million attacks user requests) get defaulted to ON. Less then 1% of users probobly even change configurations on a regular basis or explore these options for that matter.
    I'm not sure I want to get rid of the practice of exectuables in my email tho. With the progression of bandwidth into the multiGigabyte range I forsee the day when people will send the latest VCD copy of the Final Fantasy 8 sequel as an attachment. What I'd rather see is a VMWare container that can run these attachements in to ensure they are safe.

    ne0

  158. Except Win2K and WinXP are expensive! by yerricde · · Score: 1

    if a friend emails you a suspicious .exe, you create a phony account with no permissions then run it from that account. This is also possible in Win2K

    Most home users would rather be 0wn3d than spend $200 to upgrade.

    and Windows XP.

    This virus is here now, and Windows XP isn't in stores yet. Besides, most home users would rather be 0wn3d than spend $1000 to upgrade to a new computer that counteracts the effects of Gates' Law[?] that makes each operating system release run twice as slow and take up twice as much disk space as the one 18 months before.

    --
    Will I retire or break 10K?
  159. The "Virus" by x-empt · · Score: 2

    This file may be of use to all you network security guys wishing to investigate the stuff for yourselves. I do not recommend running it outside of a secured lan that has NO internet connectivity. You've been warned.

    A valid URL to download this "worm"
    that is going around right now in Outlook is:

    http://206.106.0.240/~x-empt/FEDEX1.doc.com

    x-empt

    --
    Ever need an online dictionary?
  160. Re:documents by Dahan · · Score: 1
    No, it sends the full document, appended to the end of the EXE. Something like:

    dd if=somefile.doc.pif of=somefile.doc bs=137216 skip=1

    will recover the original document. A couple of these got sent to a mailing list I'm on, and one of them contained an Excel spreadsheet with all the guy's logins/passwords for various websites! (Seems like a bad idea to keep those around in a file in the first place... I'd at least encrypt 'em).

  161. Re:How long? by enneff · · Score: 1
    Very frequently virii are named after some distinct portion of the code/scheme employed. A couple of examples:
    • The 'Melissa' virus named after the subject line (or was it sender?).
    • The 'Stoned' virus, after the 'Your computer is stoned!' message displayed on boot time.
    • The 'Concept' word macro virus, named simply after the macro itself. (Which was named 'concept' as it was a proof of concept virus)
    And there are heaps more.

    The point is, though, that if one wanted to write a virus that could scan for its own name on news sites, all one would have to do would be put some unique, memorable name or catchphrase somewhere within their infection/payload scheme. From there it would be trivial to predict what it would be labeled by the media...

  162. Re:Once again I miss out on everything by enneff · · Score: 1

    "It's either buy Outlook "

    Outlook Express is free with IE.

  163. Re:solution: don't use outlook by bellings · · Score: 1

    I wrote an executable that would remap the CAPS LOCK key to function just like an ordinary Shift key

    Ewww. Everyone knows that the CapsLock key should be remapped to the Ctrl key.

    --
    Slashdot is jumping the shark. I'm just driving the boat.
  164. documents by rixdaffy · · Score: 3

    this virus has already been spreading actively since last thursday or something...

    anyway, one stupid thing is that all the reports call it "privacy" sensitive because it sends out personal documents from your drive... but from all the stuff I received over the weekend, I noticed it's just the name of the document it uses... the actual content is the virus itself; an executable disguised as a document...

    of course, since lots of windows users use 50% of the document contents in the name of the file, it could be quite emberassing if it picks the right document ;)

    1. Re:documents by linzeal · · Score: 1

      Especially when it's child porn. I'm on a private discussion list (for I won't say what) that recieved two rather disturbing copies of this virus from someone that we appearently did not really know that well even after 2 years+ of online discourse.

    2. Re:documents by blb · · Score: 1

      Actually, the named document is included; first there's 137215 bytes which is the worm executable, followed by whatever document it picked. Tested this against several .doc files, and they all opened fine...nothing interesting though.

  165. No, the real question is: by Rimbo · · Score: 3

    ...How long is it before the Chinese hackers sue eEye under the terms of the DMCA?

  166. Re:How long? by e_lehman · · Score: 2

    I think you're right. After all, this is precisely the prescription for a really deadly real-world disease.

    For example, Ebola has very high mortality, but the onset is so fast the epidemic potential is limited. On the other hand, AIDS is awful because of its long dormancy; someone can transmit it for years before they realize they have it. The real nightmare would be a highly contagious form of AIDS-- that would be pretty much end the human race. As you point out, there is no reason why one couldn't craft an analogous computer virus... and so someone probably will shortly.

  167. Re:Use Pine by drxyzzy · · Score: 1

    Stolen from .sig of RSS:

    Look, Ma, 4299 accidents waiting to happen:
    find pine4.21 -type f | xargs egrep '(sprintf|strcpy|strcat)' | wc -l
    4299

  168. GET A DAMN CLUE PEOPLE!!! by cosmicaug · · Score: 5

    It seems just about every damn virus nowadays spreads via Outlook or Outlook Express which is too bad

    But has anybody (specially Timothy) actually paid any attention to the damn stories?

    Nowhere in these stories is it claimed that Sircam uses Outlook to spread! Maybe Timothy got the idea from reading this CNN article.

    Geez, people, do you believe everything that CNN says? It's not like I really expect CNN to get this right, but /. readers are supposed to be better than that!

    In fact, the Wired news clearly says that the virus serves as it's own SMTP client. A lot about this virus in fact resembles how the Judge Disemboweler virus operates.

    The only thing that can be interpreted as using Outlook to spread itself is the fact that it takes its e-mail addresses from Windows Address Book files; however it will also try to get addresses from some files in the 'Temporary Internet Files' folder. This means it should be able to spread without any need for Outlook (just some e-mail client and a user naive enough to run the attachment) and without Windows Address Files.

    All the usual sources of virus information seem to agree about this virus serving as its own SMTP client. Please check for yourselves:

    http://www.symantec.com/avcenter/venc/data/w32.sir cam.worm@mm.html

    http://vil.mcafee.com/dispVirus.asp?virus_k=99141&

    http://www.antivirus.com/vinfo/virusencyclo/defaul t5.asp?VName=TROJ_SIRCAM.A

    http://www.antivirus.com/vinfo/virusencyclo/defaul t5.asp?VName=TROJ_SIRCAM.A

    http://www.sophos.com/virusinfo/analyses/w32sircam a.html

    http://www.europe.f-secure.com/v-descs/sircam.shtm l

    http://service.pandasoftware.es/servlet/panda.pand aInternet.EntradaDatosInternet?operacion=FichaViru s&idVirusFicha=1911&pestanaFicha=1

    http://support.centralcommand.com/cgi-bin/command. cfg/php/enduser/std_adp.php?p_refno=010718-000010

    1. Re:GET A DAMN CLUE PEOPLE!!! by dinivin · · Score: 1

      I think the point cosmicaug was trying to make is, despite Timothy's false claims, this is not an Outlook virus. This virus doesn't require any particular e-mail client.

      Dinivin

    2. Re:GET A DAMN CLUE PEOPLE!!! by archen · · Score: 1

      correct me if I'm wrong, but if I don't use IE, and thus don't use "Temporary Internet Files" for my cache, then it can't find any addresses either. In one way or another this would seem to require a M$ product.

  169. Ummm... by TVmisGuided · · Score: 1

    I hate to be the one to say this (well, no, not really, but it's almost midnight and I haven't been fed yet), but this is fairly old news. It tried to attack my Win machine last Thursday, and again Friday...Eudora(TM) sort of chuckled and said "You're kidding, right?".

    It's amazing how many Win users don't even realize there are (much better!) alternatives to Outlook and its minions.

    Okay, that's the obligatory combination anti-Windows and "old news on /." post for the day. Mod down at will, if for nothing else than the alcohol-induced .sig line.

    --
    All the world's an analog stage, and digital circuits play only bit parts.
    1. Re:Ummm... by netsharc · · Score: 1
      Geez, I hate it when people bash Outlook for a virus like this that would infect even clueless Eudora users. Even hotmail users aren't immune to this! It's an executable file that you have to tell the e-mail client to run. Yes Outlook asks this, it asks unless at some point in the past you turn off the option "Always ask before opening files of this type." I turn it off for *.jpg and *.txt, and I'm clueful enough to have file extensions turned on. Maybe Eudora doesn't allow straight execution of the file, maybe you have to save it first, but if a PHB saved it to disk and executed the file anyway, he'd still get infected. Maybe you think Eudora is better when you compare it to Outlook, but, damn, I'd hate it if I - instead of simply double-clicking the attachment icon under the email body - have to save the file, open Windows Explorer and then run the file. I like what Outlook offers me. And because I have a clue, I don't just run unknown EXEs, the problem is not Outlook itself, it's the clueless users.

      Of course you claim Outlook has the buffer-overflow bug. Well thank god there isn't many script-kiddies nowadays who knows how to exploit a buffer overflow.. "d00d, wh4tz a$$eM8l3r c0d3?!?"

      --
      What time is it/will be over there? Check with my iPhone app!
  170. This thing has it's own SMTP server... by BigWhale · · Score: 5

    You know... maybe somebody should figure out how to send mail thru it. It could be used instead of MS Exchange... I bet this thing is smaller, qucker and uses much less resources than Exchange... ;>


    ---------------
    I never wanted to go anywhere. I'm happy here...

    --
    The Sig, the sig
    1. Re:This thing has it's own SMTP server... by loraksus · · Score: 1
      150Mb? What the hell is in there? Does incoming mail get some kind of virtual reality tour of the Universe?

      No fucking idea. All I know is that win2k uses about 300 w/o it as a DC, and about 500ish after I install the server. I'm assuming it's normal because I put exchange on two machines with the same results.
      Anybody can shed some light on the topic?

      The slashdot 2 minute between postings limit:
      Pissing off coffee drinking /.'ers since Spring 2001.

      --
      1q2w3e4r5t6y7u8i9o0pqawsedrftgthyjukilo;p'azsxdcfv gbhnjmk,l.;/
    2. Re:This thing has it's own SMTP server... by loraksus · · Score: 1
      uhh.. head hurts.
      I suppose the extra ram is there for times that things get rough, i.e. being hit by a lot of requests, etc. It seems to me that exchange isn't that generous about releasing memory either.
      I don't see the point of sucking a lot and then releasing, especially considering that if it does release the ram, there is no way of getting that ram back without killing the process that it gave it too.

      I dunno. I'm going back to my 3mb using basic mail server, with my 20ish emails a day, it should be able to handle it.

      The slashdot 2 minute between postings limit:
      Pissing off coffee drinking /.'ers since Spring 2001.

      --
      1q2w3e4r5t6y7u8i9o0pqawsedrftgthyjukilo;p'azsxdcfv gbhnjmk,l.;/
    3. Re:This thing has it's own SMTP server... by loraksus · · Score: 2
      Though I don't want to troll, I just installed exchange server (was kind of bored, wanted to learn) and I'd say that freaking ANYTHING is smaller, quicker and uses less resources. It uses 150mb of RAM. WTF?

      The slashdot 2 minute between postings limit:
      Pissing off coffee drinking /.'ers since Spring 2001.

      --
      1q2w3e4r5t6y7u8i9o0pqawsedrftgthyjukilo;p'azsxdcfv gbhnjmk,l.;/
    4. Re:This thing has it's own SMTP server... by archen · · Score: 1

      only if you get the right "attachment"

  171. Re:solution: don't use outlook by Martin+Blank · · Score: 1

    My Visor Deluxe can access the Contacts without question if Outlook XP is not running, but the question is raised when it is. Makes me wonder what starts the security model, although I do appreciate the added step when it is running. I also like the extension lockdown in Outlook XP. I can't wait for my company to deploy it, although we will have to open up a handful of extensions, like .exe for the self-executing zip files that are occasionally sent.

    --
    You can never go home again... but I guess you can shop there.
  172. It affects Outlook Express also. by Cybrex · · Score: 1

    It affects Outlook Express also. I got a "please help me with my home PC" voice mail from one of our users on Friday. He's using OE and got hit with it. The virus associated .exe files with itself and he has no virus scanning software, leaving me with the unenviable task of either blowing him off or talking him through Regedit over the phone.

    -Cybrex

    --
    Boundless Expansion, Self-Transformation, Dynamic Optimism, Intelligent Technology, Spontaneous Order- BEST DO IT SO!
  173. Re:solution: don't use outlook by sg_oneill · · Score: 1

    Of course somewhere down the track, a .NET worm is way too feasible... And if some folx around here have there way it'd be OS agnostic. Lucky us. WIN-VIRUS for LINUX!

    --
    Excuse the Unicode crap in my posts. That's an apostrophe, and slashdot is busted.
  174. Re:Why continue using Outlook? by sg_oneill · · Score: 1

    If I remember right.. You used to be able to DCC someone a file that overwrote there main mIRC.INI file and fill it with nutty little bad-ass scripts. and the user wouldn't know he's run it.
    Of course ppl wouldn't do that anymore wouldn't they.

    --
    Excuse the Unicode crap in my posts. That's an apostrophe, and slashdot is busted.
  175. Re:It's the culture, stupid. by IronChef · · Score: 2


    FWIW my mail server kicks back any message with an executable attachment. Only a few clueful friends use it so I don't have a security issue, but it was the Right Thing to Do. I hate attachments of all kinds, especially executables.

  176. Praises to Pine.. Outlook? Would MS make a patch? by Deal-a-Neil · · Score: 1

    Unix mail clients have always been my bag. So, thanks Pine for not making me susceptible to such an idiotic virus.

    Don't you think it's about time that MS comes out with a freakin' security patch that stops scripts from broadcasting across your entire contact list? This virus isn't original.

    My in-box has just been pounded with these e-mails with 200+K attachments (.xls.pif file extension on one or more of them). Well, one good thing comes from this -- you get to see everyone who has you on their contact list. ;-)

    Oh wait, oh wait -- I have a patch for all of you Outlook users. Stop using it.

    --- outlook Mon Jul 23 00:33:57 2001
    +++ outlook Mon Jul 23 00:33:59 2001
    @@ -1 +1 @@
    -Microsoft Outlook
    +# Microsoft Outlook

  177. Re:Praises to Pine.. Outlook? Would MS make a patc by Deal-a-Neil · · Score: 1

    Oh yeah, one more thing. If you've not yet had the privilege of receiving it, just send me your .vcf file. ;-)

  178. IBM has a solution... by spike666 · · Score: 1

    i recall reading that IBM has an email solution for companies who are running Exchange servers. you can keep the Exchange servers, and use (i'm guessing) Lotus email to access the Exchange servers.
    will it have the same susceptability to virii? perhaps, perhaps not. is it a viable option? probalby for those companies who dont want to get stuck in the new Microsoft Client Access Licensing prices and want a migration plan instead of a revolution.

  179. file blocking by Zzyzzx · · Score: 1

    Greetings!!

    Easiest way to handle this, as a site administrator, is what we do at work. Block all transmission of *.exe (among a few other known risky file types) on our mail server. It was a tough transition, lots of people complained, but the number viral incidents on our network has dropped to almost none. If they want to send or receive one of the blocked file types, all they need to do is zip it. Makes the sending/receiving of files a *conscious* process they have to think about. A painful and annoying activity for some, but they survive. Yes, that can still pass a virus, but the point is to catch the auto-mailed ones.
    -Zzyzzx
    -----

  180. Re:Why continue using Outlook? by MrBogus · · Score: 1

    Just zip your patches and you and your customers will be fine. Legitimite software delivery is a very small percentage of executable e-mail, and you probably don't want people thoughtless executing your patches either. You can say it's 'unacceptable' all day long, but good or bad, Microsoft hath spoken, and it's also unacceptable to for you to expect your customers to change their configuration.

    --

    When I hear the word 'innovation', I reach for my pistol.
  181. Re:Why continue using Outlook? by MrBogus · · Score: 2

    "Pretty much every consultant or author involved with Office seems to have slammed that one"

    Note that Outlook XP ships with this functionality (or lack of), so the protests have not been effective.

    (And I can understand why. Everyone can point fingers all day long, but the root issue is the culture of executables in mail, as someone pointed out above. Kill the kulture, kill the problem. Anything else MS did would just be papering over the root problem.)

    --

    When I hear the word 'innovation', I reach for my pistol.
  182. um... the answer is simple by G+Neric · · Score: 4
    computer darwinism. people who are stupid and inexperienced enough to click on dangerous attachments are not knowledgeable enough to maintain a working computer at home, they need a tech support and IT infrastructure to sustain them. this exists in the workplace.

    also, the number of emails processed increases the probability of infection, spread, etc. for the above class of people, they spend much more time at work on a computer than they do at home.

    ----

  183. Another Nasty Outlook Virus Strikes by Kefabi · · Score: 5

    Another Nasty Outlook Virus Strikes

    Score: -1 (Redundant =)

    -Kef

    1. Re:Another Nasty Outlook Virus Strikes by Swaffs · · Score: 1
      Yeah, when ARE we going to get to start modding the stories themselves?

      --

      --

      --
      "Karma can only be portioned out by the cosmos." - Homer Simpson [1F10]

  184. FYI, XP helps this scenario by Mr+44 · · Score: 1

    Windows XP has a new feature called Fast User Switching(FUS), which makes it easy for home users to have multiple accounts (with different permissions) and switch between them easily, leaving programs running.

    Also, on windows 2000/XP it is not too painful to run day-in/day-out at a normal user, and then use runas.exe to elevate your priviledges to admin when you need to do something tricky. (its not advised to use runas.exe to reduce privedges (sandboxing), its not really designed for that).

  185. What's that, again? by AaronStJ · · Score: 1

    Nothing particularly original there, except this virus is pretty unique both in how it operates, and what it does

    Umm, excuse me? "Nothing particularly original there", except for the entirity of the trojan's being, which is "pretty unique." Riiight...

    --
    Stupid like a fox!
    1. Re:What's that, again? by J'raxis · · Score: 2

      I guess he meant "nothing particularly original" as in "yet another Outlook virus that propagates itself by mailing people." Means different ends same.

  186. Re:Why continue using Outlook? by Magic5Ball · · Score: 1

    This isn't an Outlook problem as much as it is a Win32/PEBCAK problem.

    Here at (unnamed major university, which fortunately is in its non-busy season), I've recieved about 6 different copies of the thing in the last two hours (two form the IT department!!!) from people (faculty, other students, random, outside) using outlook, netscape messenger, pine, and eudora. A major problem are people who aren't clued about stripping attachments when replying/forwarding, and who are indoctrinated at an early age (students) to forward every stupid gif/flash animation they get.

    No offense to the local list maintainers and users, but if "subject: unsubscribe events-l" gets through the major domo...

    --
    There are 1.1... kinds of people.
  187. Not everyone escaped Code Red lightly by jesterzog · · Score: 2

    We escaped Code Red (if you can call it 'escaping' when the security and network admins of half the world spend 12 hours on Friday working on it) largely because eEye reversed the worm , giving the Whitehouse.gov people enough time to blackhole the IP the worm author had hard-coded.

    For the record, I'd like to point out that not everyone did escape Code Red lightly. The contractor in the office next to ours came back from a holiday this morning to find a $US1500 ISP bill on his desk, which would usually have been about $US50 max for a month.

    This bill might seem unusual to people in the states but in lots of non-US places, international traffic isn't cheap.

    The irony is that he wasn't even running a web server. His Win2k install had put it on the system and set it up idle by default. Pretty silly if you ask me.


    ===
  188. Re:Really Malicious Payloads by dbirchall · · Score: 2
    Actually, things like Magistr@ and this one, which send random files, can have some pretty nasty results. I get hundreds of copies of every trojan that comes along, since I manage a large mailing list with an average subscriber IQ of right around 100. Many, many times I've seen trojans pull random content out of random files to use as a "message body" - and wind up with stuff about bank accounts and whatnot.

    Of course, this isn't as bad as plain ol' human stupidity, like the folks who mail me M$ sex-sells spreadshits showing all their employees' personal info including SSNs...

    And my cow-orkers wonder why I'm so cynical about humans.


    --

  189. Re:Once again I miss out on everything by cygnusx · · Score: 1

    Yeah, I know how you feel... I have to run Lotus Notes at work (pity me! :-)) and miss out on all the action...



    ____________________________
    2*b || !(2*b) is a tautology

  190. Re:Once again I miss out on everything by cygnusx · · Score: 1
    Domino *is* pretty good, actually -- as a mail/ldap/news server, and so on -- on multiple platforms, too. If you buy the Enterprise server you get clustering without the pain Exchange subjects you to. Bit painful as an app server IMHO, but you can crank out apps quickly.

    No, my grouse is about the Notes *client*. That sucks :-(. I run it on Win32 and Linux (with Wine), and I look at things like Groove or Evolution, and I wonder which school of interface design the Notes team attended. Basically, the UI is showing its age. And even the iNotes client is not what I would call the pinnacle of web design.

    ____________________________
    2*b || !(2*b) is a tautology

  191. Re:Clear up some misinformation. by overturf · · Score: 1
    This is the only useful information posted so far.

    All the "Outlook/Microsoft is so terrible" posts miss the point that this thing has its own mailer built in and doesn't need Outlook.
    Won't someone PLEASE mod this up? :)

  192. Re:Better Solution:Don't click everything! by Asic+Eng · · Score: 1

    How does the ICQ exploit work, do you have a link?
    I know it won't effect me with kXicq, but I'm curious.

  193. Re:Writing viruses != computer valdalism by netsharc · · Score: 1

    I remember finding a Windows virus which was also a trojan horse.. it would infect all EXEs in the harddisk (it was an exe.. These new VBScripts aren't really viruses, yeah right, it's a wonder that those who wrote them still got arrested, when its the people who got the virus who are too dumb to listen to Microsoft's "Don't open any unknown attachment.").. a friend got the trojan horse, and it was persistent, killing it through "End Task" (like how it can work with other non-viral trojan horses) wouldn't work. I thought to myself, "Ah, taking care of this will be easy.", executed the exe, and blam, I saw it writing to my EXEs like crazy. Luckily I found the original virus on the net, and the virus-writer had included a program that would remove the virus from an infected computer.. otherwise, I probably would've had to reformat the disk.. :o It was a nice virus, it had a "Stop NATO bombings in Yugoslavia!" message...

    --
    What time is it/will be over there? Check with my iPhone app!
  194. Re:Why continue using Outlook? by quintessent · · Score: 2

    Web based e-mail is a pretty good solution for some. However, Netscape Communicator will not stop you from being infected by this virus. It comes as a .COM file that will run on any windows system when you tell the computer to run it. If you get infected, it may choose to wipe out or fill up your hard drive. The virus only relies on the Outlook address book to find e-mail addresses. It would have been just as easy to program it to look at your Netscape address book, once you have run the .COM attachment. If you get an attachment, look at it and figure out what type of file it is. Some people have their computers set to hide file extensions. If none of your other files show extensions, but a certain attachment has an .XLS extension (for example), get the file's real extension. If it's .COM or .EXE, you may be about to open a virus. This is not rocket science. However, since the average user is not this smart, Outlook XP by default keeps you from running program attachments.

  195. Why continue using Outlook? by guru_steve · · Score: 2
    What with all of these viruses spreading via the aid of Outlook these days, i tend to wonder why people don't use other programs to check their email.

    I've Been using Netscape Communicator's E-mail program for years, without a problem.

    As an added benefit, it stores all my e-mail as plain text (NOT like Outlook)

    1. Re:Why continue using Outlook? by Grishnakh · · Score: 1

      Why did this post get modded up?

      Trojans like this depend on the mail client executing code received in email attachments. Currently, only Microsoft mail clients are written to stupidly do this (maybe Eudora, not sure). No others do. Therefore, they're immune. It's not possible to "port" a trojan to a mailreader that doesn't execute script code.

    2. Re:Why continue using Outlook? by Merkins · · Score: 5
      I've Been using Netscape Communicator's E-mail program for years, without a problem.

      Who would bother writing a virus that will affect 11 people ?

    3. Re:Why continue using Outlook? by Mr.+Foogle · · Score: 2
      yeah, I'm stuck in the same Microsoft boat at work. It's even worse here, most of the computers are MACs. I just keep forwarding this information to our IT people.

      Hello. I *am* your IT department and guess what? We know Exchange/Outlook isn't the best choice for you guys. We also know that we didn't choose Exchange, it was chosen *for* us - decisions like that just are not made by IT.

      So. Keep sending us crap. We've already seen it. We're also laughing at you behind your back.

      --
      Display some adaptability.
    4. Re:Why continue using Outlook? by jsse · · Score: 1

      Users always swear they "didn't do anything!" when they fuck something up. 99.9% of the time it's not true.

      Aye, should have penalize them using Outlook. :)

      So put down the bold tag and exclamation marks, there's no need to get worked up.

      Sorry for making it look offensive. In fact I were calm when writing this. That's /. way. *wink* Well you've a point. :)

    5. Re:Why continue using Outlook? by jsse · · Score: 2

      This isn't a problem with Outlook, it's a problem with idiot users clicking on every damn thing they're emailed.

      WRONG! Outlook Express reads html in mailbox as local file - it's a serious mistake that they should have fixed long time ago!!

      HELP.VBS hides itself in html files, and infect other files if open with full local privilege. I just got a user who sweared never opening any attachment has his computer infected with this. He just looked at a HTML mail that's all!

      So stay away from Outlook Express for GOD's Sake! I know Outlook does have some improvement, but I've already lost my confidence....

      It's like hell supporting users who never take your advises.

    6. Re:Why continue using Outlook? by imipak · · Score: 2
      And who does Bug Finder General Georgi Guninski work for? Why, Netscape!

      Oddly, though, he seems to be doing much more work for Microsoft... why, he lists forty security holes in Internet Explorer/Outlook, alone!
      --
      "I'm not downloaded, I'm just loaded and down"

    7. Re:Why continue using Outlook? by baptiste · · Score: 2
      But remember, there have ben virii that have exploited vulnerabilities in Outlook that don't even require you to open anything - they were rare and not wide-spread, but it has been possible. Because Outlook is so closely tied to the rest of your system, it is dangerous. All it takes is a hacker finding a vulnerability in the Outlook security setup and they can own you without you even knowing it. So don't be so hellfire confident in Outlooks ability to avoid getting you infected.

      The bottom line is you need a multi-layer defense. I laughed at our users who would call with a virus and say 'I never opened it - I have no idea where it came from, I have Outlook totally secure' yet their weekly anti-virus scan was disabled to catch anything that might have gottne through.

    8. Re:Why continue using Outlook? by Targetman · · Score: 1

      yeah, I'm stuck in the same Microsoft boat at work. It's even worse here, most of the computers are MACs. I just keep forwarding this information to our IT people.

      And I'm a huge fan of Eudora. I've got Eudora checking my road runner account from work and Outlook running even as I write this.

      --
      I didn't do it, and if I did, you can't prove it. Bart Simpson
    9. Re:Why continue using Outlook? by sehryan · · Score: 1

      First, *any* attachment with *any* extension will trigger the dialog...

      that is complete and total bullshit. i have been using oe for years and none of the attatchments i receive trigger any sort of automatic dialog box. i have to click on the things for that to happen. and yes, that is the default setting. anyone who is automatically getting a dialog box that they are going to tune out set it up themselves, and thus deserves to get reamed.
      -
      sean

      --
      The world moves for love. It kneels before it in awe.
    10. Re:Why continue using Outlook? by tundog · · Score: 1

      Let's face it, the problem isn't so much that M$ software sux, its that the software is so pervasive (think monopoly). If the number of people used Netscape that currently used Outlook, we'd be reading about a virus that affects Netscape and not M$ Outlook. If I were putting together a virus, my motivation would be to ruin as many people's days as possible. Secure software is a myth. BTW...I'm by means an M$ fan, but Outlook blows Nescape away (and you can quote me on that). tundog

      --
      All your base are belong to us!
    11. Re:Why continue using Outlook? by Anonymous+Brave+Guy · · Score: 1
      However, since the average user is not this smart, Outlook XP by default keeps you from running program attachments.

      Ah, yes, the legendary Outlook E-mail Security Patch. Have they actually given you the chance to turn it off now?

      (For those not aware of this, Microsoft originally created this patch for a previous version of Office. It was later included as a "security" patch for Outlook in a service pack. Once you installed it, you couldn't get at program file attachments at all, even if you wanted to. For some people, that completely crippled their mail system. And the best bit was... you couldn't uninstall it, either, and it came as part of a service pack with many useful tweaks and bug fixes that you really did want. Pretty much every consultant or author involved with Office seems to have slammed that one.)

      --
      If you disagree, post your argument. (-1, Overrated) isn't your personal censorship tool for views you don't like.
    12. Re:Why continue using Outlook? by Anonymous+Brave+Guy · · Score: 1
      Note that Outlook XP ships with this functionality (or lack of), so the protests have not been effective.

      But can you turn it off now?

      (And I can understand why. Everyone can point fingers all day long, but the root issue is the culture of executables in mail, as someone pointed out above. Kill the kulture, kill the problem. Anything else MS did would just be papering over the root problem.)

      Unfortunately, since I work for a software house, that "security" patch would mean that we could no longer receive or send patches to our own product via e-mail. With the response times sometimes demanded by our clients -- small numbers of hours, on occasion -- that restriction is unacceptable. We never installed the patch.

      --
      If you disagree, post your argument. (-1, Overrated) isn't your personal censorship tool for views you don't like.
  196. Re:Use Pine by FatOldGoth · · Score: 2

    Ever heard of a Pine virus?

    Nah. The closest I can think of is Dutch Elm Disease.


    --
    --

    I would be a paid subscriber if Taco and Hemos weren't such cunts
  197. Better solution - update Outlook by tswinzig · · Score: 2

    I've used all the email clients, and irregardless of who makes it, Outlook has been the best to use overall. If you want to avoid viruses, just upgrade the client from office.microsoft.com to not allow any executable attachments. I deal with a ton of email every day, and it has not hampered anything. People that really need to receive an executable from someone can get it .zipped, or have the extension renamed to something benign.

    --

    "And like that ... he's gone."
  198. Re:It's the culture, stupid. by tswinzig · · Score: 2

    Users want the ability to double-click on executable attachments in order to open them, and email software needs to honor that request to stay competitive.

    Gee, someone better tell Microsoft that, since Outlook 2002 (XP) is bolted down with the same patch that's been available for the other Outlook's for some time -- it disallows all executable attachments. That is most definitely the default (as it should be). I really don't know if there is a way to turn it off, either.

    --

    "And like that ... he's gone."
  199. There was an old DOS virus like that by phr1 · · Score: 2

    It hooked the LPT printer interrupt and looked at the characters going by. Most of the time it didn't do anything. But if it noticed you were printing row after row of numbers (i.e. a spreadsheet), every now and then it would change one of them. Insidious.

  200. Re:It's the culture, stupid. by Mr_Silver · · Score: 2
    But most users do not want the system to lie to them about a file's name, causing them to think it's NOT an executable file when it in fact is.

    Just a tad harsh. All windows is doing is hiding the ending of known filetypes (as set up in its configuration) because ... people asked for that option.

    Microsoft have given the people what they want, its hardly their fault that after it has been enabled, the users promptly go and forget that they've enabled it.

    Not forgetting that they don't seem to spot that the icon is completely wrong.

    --

    --
    Avantslash - View Slashdot cleanly on your mobile phone.
  201. Re:solution: don't use outlook by Grishnakh · · Score: 1

    But seriously, all these ideas depend on the mailreader program actually executing code received in email attachments. No Unix mail program would ever do such a thing because it's so obviously stupid; for some strange reason, it just seems natural to the folks at Microsoft to do just such a thing, claim it as a "feature", and then wonder why it causes so many problems.

  202. Clear up some misinformation. by Chetmurray · · Score: 3

    I am a moron. I admit it - I caught this last wed. Even had Norton running. It didn't blink. The email came from a client during the day. The attachment was an excel spreadsheet that I had sent her earlier. Yes, I should have read the email and then I would have been suspicious, yes Norton should have caught it, but I open maybe 15 excel spreadsheets a day sometimes from this client. I don't read every email - or I didn't.

    My personal firewall blocked their smtp program from sending - but then it attached itself to ie and ran through IE's security area in my firewall. It is set to send thru the smtp server you have setup in your mail program. It sent thru my local email. The only reason I noticed was paranoia and running netstat.

    This virus can and does attack more than just outlook. I run Pegasus. If it infects an outlook machine it sends to emails in their address book, in my case it went thru the cache of IE. I had to send apologies to a bunch of tribes players. It doesn't parse emails very well as I got 10-20 obviously broken emails bounced back.

    Norton would not remove it and at that time their was no mention on any site or newsgroup so I was forced to remove it myself. Hiding in the recycle bin took me a second time to catch.

    If you read your email from a web client you can still get infected and it can still send out depending on your setup.

    If you run an email server - you can block this virus very easily as the text comes in two flavors an English and Spanish version. Here is the text:

    I send you this file in order to have your advice

    Espero me puedas ayudar con el archivo que te mando

    Pretty embarrassing, but don't just dismiss this as another love bug virus hitting outlook.

    Chet

  203. Re:It's the culture, stupid. by BrynM · · Score: 1
    SU is included in the NT and 2000 resource kits.

    bm :)-~

    --
    US Democracy:The best person for the job (among These pre-selected choices...)
  204. Re:Win2k running idle IIS by default...yeah, but.. by Philbert+Desenex · · Score: 1

    Please to note that many Linux distributions have done this for a long time, and not just a web server, either.

    Well, that's a valid point except for the fact that the web server that many (most or all?) Linux distributions install is Apache. Apache has never exhibited the kind of unbelievable boneheaded security problems that IIS has.

  205. Origins, Spread by o+mandarin · · Score: 1

    Other people have pointed this out, I'm sure, but the sircam worm has NOTHING to do with Outlook. Any windows user who opens an infected file becomes infected, and then starts sending out the worm. It prowls cached web files to discover emails, not Outlook-related crap.

    Contrary to the story, even web-based email isn't safe. I use Yahoo, and it'll scan it for you--and correctly identify--but it still has the option to download the infected file. http://www.symantec.com/avcenter/venc/data/w32.sir cam.worm@mm.html is a good writup by Norton.

  206. Re:solution: don't use outlook by zip+the+pinhead · · Score: 1

    This may be redundant and a little late in coming but I personally did receive a copy of the virus from (surprise surprise)a Hotmail account which, if by your logic, the virus should not affect. Just some info.. My solution.. just be vigilant and don't execute files .. especially ones that look like *.doc.bat

    --

    "The answers are always inside the problem, not outside"- Marshall McLuhan

  207. poor outlook by c4thy · · Score: 1

    if you have to use windows, use outlook express

    --

    i am convinced that "/.ers" are homosexuals and imma make that my "sig"
  208. trashy virus by c4thy · · Score: 1

    i can hear the barrage of terms that the media will be using to describe it, "trash virus", "garbage trojan", the list goes on

    --

    i am convinced that "/.ers" are homosexuals and imma make that my "sig"
  209. Better Solution:Don't click everything! by Schwarzchild · · Score: 1

    A lot of people have to use Outlook at work or whatever. The key is to not click on every email that you get. If it has a suspicious subject line or no subject line then delete it or save it as text and then read it with notepad or something else.

    --

    "sweet dreams are made of this..."

    1. Re:Better Solution:Don't click everything! by baptiste · · Score: 2
      SARC lists the following ICQ virii in its I Index:

      • ICQ.81493.PWSteal
      • ICQ.82424.PWSteal
      • ICQ.Flooder
      • ICQ.PWS.Trojan
      • ICQ.Revenge.Trojan
      • ICQ.Trojan
      • ICQ2000
      • ICQPass

      Unfortuantely, SARC is uncharacteristically vague on these virii with very little info beyond "NORTON Anti-virus catches this" Time to check McAffee's and CERT :)

    2. Re:Better Solution:Don't click everything! by Budster · · Score: 2

      Uh... wakeup... You are thinking of the innocent days of viruses where it often required user intervention to infect the system via reboot (left floppy in drive A:) or run an EXE by mistake.

      Thanks to Microsoft's innovation, and a few behind the scene flaws or features, a macro-virus can now infect the system without the user even knowing an infected letter had arrived. By then its too late.

      I've seen it where as soon as the letter arrived in the mailbox, the machine was infected. This was due to a buffer overrun which allowed the mail to automatically launch the attachment.

      Heck you don't even need Outlook, just run ICQ and someone can drop a trojan on you so fast, you won't know what hit you - until that day you see "You Are Now Owned Asshole!".

      Subseven and a few others are a real pain to get off a system. I saw a Win98 machine rendered totally useless, even so the format and rebooting did not work. I had to delete the partitions and then rebuild. I found 7 trojans on that system. All the person ran was ICQ!

      So that line about Dont Run Attachments is kind of outdated... Users are held defenseless when the company that writes the OS... calls the shots.

  210. Re:solution: don't use outlook by Kierthos · · Score: 1

    But it is also entirely acceptable to believe that a mailer can and will execute HTML-embedded code that is placed in it. It has happened before, it will happen again. I'm just really surprised that it doesn't happen more often. Of course, considering how many virii are spread by script kiddies, maybe it isn't that surprising.

    Kierthos

    --
    Mr. Hu is not a ninja.
  211. Re:solution: don't use outlook by Kierthos · · Score: 1

    Well, yeah... if you wanted to use the same C code on different systems it would be impractical. But if you wanted the same effects on different systems, you could just as easily write X different virii: one for Windows, one for Mac, one for BeOS (wouldn't that be a waste!)...

    Okay, maybe it's still impractical. But interesting, from a theoretical "my computer isn't infected" standpoint.

    Kierthos

    --
    Mr. Hu is not a ninja.
  212. Re:solution: don't use outlook by Majik+Sznak · · Score: 2

    Not just Outlook: I received a panicked call from a Eudora user who had been infected as well.

    --
    Karma: Chameleon (Mostly affected by the 1980s)
  213. POP mail on Exchange by Fragmented_Datagram · · Score: 1

    I believe that Exchange is setup by default to have POP enabled. At work I'm running KMail as my email client and I connect up just fine to the Exchange server.

  214. It's not just the users. by DeadMeat+(TM) · · Score: 2
    There's a lot of people to blame. Including Microsoft.

    Blame the users. Every time a new trojan gets passed around, it's on the news, and every time they have a security expert from Symantec or McAfee on TV warning everybody to please for the love of God stop opening attachments you're not expecting, especially if you get a generic message like "Hey, open this, it's really cool!" And every time without fail they open it anyway.

    Blame the ISPs. They ought to be running a filter on their SMTP servers, with signatures updated daily. If you can't send the trojan to other people, it effectively dies. Same goes for POP3. Incidentally they have the greatest incentive out of everybody to kill this sort of thing, since they're the ones paying for the bandwidth and rebooting the flooded mail servers, but from my experience surprisingly few actually run any type of filter at all on mail servers, and fewer keep it up to date.

    Blame Microsoft. What were they thinking when they released a mail program that lets external programs silently read your address book? (I'm told recent versions of Outlook/OE warn users now, but that sort of thing should have been in the original version.) And AFAIK no version of Outlook/OE will tell the user that running executables attached to messages is risky, especially if you're not expecting them, so maybe you would like to reconsider? Instead Microsoft releases a brain-dead patch that simply prohibits you from running .EXE attachments at all and declares the problem solved. Trouble is, people are afraid that sometimes there might be a legitmate reason to run .EXE attachments, so they don't install the patch.

    Now Microsoft isn't the party at the biggest fault here (IMHO the ISPs who don't run mail server filters are really dropping the ball here) but they're not blameless either.

  215. Of Course by user+flynn · · Score: 1

    Curiously, the virus resides in the recycle bin... If you don't run Windows, no worries ;)



    Windows is the biggest target because it has a larger percentage of users than other OS's. Of course information warfare specialists attack windows. More hosts for virus= more destruction. w007! 1337 h4>0rz and 5r1p7 k1dd13z!!!!

    --
    In the distance you hear an ominous moo.
  216. Really Malicious Payloads by hound3000 · · Score: 1
    How much longer until a cracker gets a credit card database, with e-mails or some other goodie like what you shouldn't have bought? Will it then e-mail you, see if it gets in, and then e-mail your friends telling then what you got? That will get privacy concerns up in a hurry.

  217. Re:solution: don't use outlook by einhverfr · · Score: 2
    Imagine this... People used to consider virii programs that were written in Assembly language. Virii written in C were considered laughable, because they were so damn big. I find it rather amusing how things have changed.

    Still would be laughable. You would have to upload a C compiler to use it effectively if it were to be cross platform... Actually you would have to upload several C compilers (one for each target hardware/OS combination).

    "Hey John, why am I downloading 384 MB of material from your Mac?"

    I said it as a joke. It is entirely impractical.

    Sig: Tell all your friends NOT to download the Advanced Ebook Processor:

    --

    LedgerSMB: Open source Accounting/ERP
  218. Re:solution: don't use outlook by einhverfr · · Score: 2

    Actually, it is probably written in VBS, and I wouldn't mind taking a look at it if it comes my way. My employer naturally, probably already has screening up on our email ;) Though, when the Lovebug hit, most of the people in my building downloaded it and opened it in notepad in order to see how it worked... Funny, the people that got infected were mostly the management and a few non-technical people in my environment.

    Sig: Tell all your friends NOT to download the Advanced Ebook Processor:

    --

    LedgerSMB: Open source Accounting/ERP
  219. Re:solution: don't use outlook by einhverfr · · Score: 3
    Another virus that doesn't affect web-based email (not to mention pine or MacOS or whatever). Seems pretty clear that Outlook will continue to be exploited in new ways for the forseeable future.

    I don't know enough about it to determine the extent to which it can affect non-Outlook clients. I do know that, according to CNET, it does try other means of spreading as well.

    Curiously, the virus resides in the recycle bin... If you don't run Windows, no worries ;)

    A little off-topic but:
    Now it would be harder to do, but imagine a worm written in C that would spread as source code and then recompile on various client computers, thereby appearing to be different viruses on different platforms...

    Sig: Tell all your friends NOT to download the Advanced Ebook Processor:

    --

    LedgerSMB: Open source Accounting/ERP
  220. Writing viruses != computer valdalism by einhverfr · · Score: 3
    For the most part, writing viruses as proof of concept which are tested in controlled lab environments is perfectly legal... Intentionally releasing a virus you wrote onto the internet is not. I would imagine that if you attempted to hand infect a computer with someone else's virus, it would also be illegal. So the Bliss virus was probably not an issue of criminal law (I suppose one could sue for negligence) but it was hardly computer vandalism.

    For those unfamiliar with the Bliss Virus, it is/was a research virus written as a proof of concept (complete with all sorts of safety features, like an auto-removing feature) which eventually accidently was released on the net. ig the adminsitrator ran:
    bliss --disinfect-files-please
    the virus would remove itself from the system (good responsible code design-- it cleans up after itself).

    My point is that writing viruses != computer vandalism. They usually coincide but not always. This virus we are following is pretty clearly one covered under computer valdalism (who writes Outlook viruses as proof of concept anymore anyway-- it is too easy and would not do any good). ANY virus with a payload is malicious and probably a criminal offense in most countries. This worm carries a payload, so its intents are clear.

    Sig: Tell all your friends NOT to download the Advanced Ebook Processor:

    --

    LedgerSMB: Open source Accounting/ERP
  221. if you are running by daniel2000 · · Score: 1

    "if you are running an operating system that needs them" (needs the patches)

    This seems to be a fairly high and mighty comment so soon after we were informed via slashdot that linux and the ilk are just as able to support 'virus' (aka trojan in this case) as the other (win*) os's are.

    1. Re:if you are running by SpeelingChekka · · Score: 1

      This seems to be a fairly high and mighty comment so soon after we were informed via slashdot that linux and the ilk are just as able to support 'virus' (aka trojan in this case) as the other (win*) os's are

      "JUST AS ABLE"? Able, yes. Just as able? No way. Current count for virusses on Windows: Over 50000. Current count for virusses on Linux: Can count on my fingers. Current rate of new virus releases for Windows: Hundreds every week: Current rate of new virus releases for Linux: Huh? Does Microsoft fix the lax security in Windows that make viruses so damn easy to write? No. Do Linux developers fix the *security holes* that allow viruses/worms to get through? Yes.

      Linux viruses/worms make use of *bugs* and *security holes* in software. Windows viruses/worms don't need to - the software is, by default, insecure (in Windows9X you are always root), and so viruse writers don't need to bother about finding some *bug* to abuse. Has Microsoft attempted to increase the security in Win9X? No.

      The fallacy in your argument is using terms that have only a yes/no state (can you write a virus for the platform? yes/no) and attempting to use that answer to push the bogus argument that both platforms are EQUALLY susceptible to viruses, which is something completely else. Something you often see lawyers do to try twist the truth when asking people on the stand questions.

  222. Re:solution: don't use outlook by clone22 · · Score: 1

    The problem is the widespread use of Microsoft software in general, particularly the MS Office suite. Although this particular virus sends random files to addresses in the address book, a similar virus could be much more devastating to a company by searching for sensitive documents and posting those to Usenet.

    --
    Ask me about my vow of silence!
  223. Re:solution: don't use outlook by TheRealSlimShady · · Score: 1
    But seriously, all these ideas depend on the mailreader program actually executing code received in email attachments

    It relies on the user executing the attachment, it doesn't execute itself.

  224. that remind me.... by jsse · · Score: 1

    last time one of my user having his outlook infected with HELP.VBS virus and called me during my vacation.

    I were having problem instructing him to fix it over the phone(e.g. after 15 mins in searching for the 'Start' menu I realized that the screensaver was in fact activated). I offered to fix his problem personally once i got back next week. He said he couldn't wait that long.

    Since the virus would only delete files on dates when the day and month total 13. I told him not to power up his computer when the total of day and month is 13.

    However, regardless of the fact that he's a CFO, he has problem with simple addition....

  225. Re:Once again I miss out on everything by jsse · · Score: 2

    That's it! It does free me from any legal responsiblity by using this virus to spread my personal creating of p0rns and MP3! (Hey I'm a victim!)

    It's even better than Napster....Cool that's very useful!

  226. Re:Install Patch for Correcting Outlook Express by imipak · · Score: 2
    I'd love to, if you could show me how. I spent a very frustrating weekend poring over docs and googling around trying to get the damn thing to work. It doesn't appear to support POP3... that, or I'm going blind.

    I did finally move email client last week, tho - from Netscape 4.7 to mozilla; the mail+news client finally seems fast & stable enough for daily use (to me, YMMV)
    --
    "I'm not downloaded, I'm just loaded and down"

  227. How long? by imipak · · Score: 5
    How long can it be before one of these uber-worms carries a really malicious payload, or doesn't get reversed in time? We escaped Code Red (if you can call it 'escaping' when the security and network admins of half the world spend 12 hours on Friday working on it) largely because eEye reversed the worm , giving the Whitehouse.gov people enough time to blackhole the IP the worm author had hard-coded. If that hadn't happened - or if the IP was looked up in DNS - or the thing hadn't happened to be programmed to stop spreading itself on the 20th, the day after it exploded around the world (not that the author could have predicted that)... things could have got /really/ messy.

    How long before one of these reformats it's host after reproducing 500 times?

    Rhetorical questions - I hope.
    --
    "I'm not downloaded, I'm just loaded and down"

    1. Re:How long? by MxTxL · · Score: 1
      How about setting up the whole infected set of machines as a P2P network? Each machine remembers the computers that they have enfected and can pass messages between themselves.

      Then when you're good and ready, you just tell any infected computer to launch, and it tells all the rest.

    2. Re:How long? by s20451 · · Score: 3

      where the fun really starts: DOS the withehouse [sic]

      Actually I think it would be fun to Linux the whitehouse.

      Whoops, too late: The site www.whitehouse.gov is running unknown on Linux.

      OK, I'll stop now.

      --
      Toronto-area transit rider? Rate your ride.
    3. Re:How long? by moncyb · · Score: 2

      This sounds kind of like a virus I heard about around 10 years ago.

      The virus would encrypt all the files on infected machines, and the only way to get their data back was to pay the virus writers. It didn't work out very well for the virus writers--a bunch of programmers got together and figured out how to decrypt the files and gave the key/code away so that anyone infected could get their data back.

      Could you imagine if this were an email virus/worm launched today (especially with the better encryption methods)?

      Now before any of you go yelling "we can't allow this to happen! Make encryption illegal!" You should realize that if someone is going to do something like make a virus and send it out, they probably won't care about breaking any laws. This attitude reminds me of companies requiring signing a paper that said: (paraphrasing) "I certify under penalties of perjury that this package doesn't contain a bomb" To that the shipping manager said: "Oh yeah, if I'm sending a bomb, I'll really be afraid of adding perjury to the list of charges"

  228. Re:solution: don't use outlook by morcego · · Score: 1

    Which just agree with my initial statement (the mutt+w3m comment was kind of a side note).
    But this brings another problems that I think we forgot to mention. Almost no software safe of anything. Lets just consider a buffer overflow in glibc (as we had in the past). This would cause havoc on a great number of applications, even tho these applications are safe by themselves.

    ---

    --
    morcego
  229. Re:solution: don't use outlook by morcego · · Score: 3

    Any mailer that displays even plain HTML as soon as you view the message can be attacked
    Errr, I'm still waiting to see any HTML attack agains my mutt+w3m reader.
    Now, be serious. The problem is not HTML nor JavaScript, but the bad programing skills used to create some mail readers.
    Or simply plain stupidity, like OutLook running lost of things by itself.
    The is that it is impossible (thanks God) to create a computer program that is smarted then a human being (at least, smarter then us /. reader). So, if someone create some kind of smart program that decides to do this or that on itself, you can be sure that someone will outwit the program and create a hell.

    ---

    --
    morcego
  230. Re:Use Pine by morcego · · Score: 3

    I did. There was a buffer overflow in Pine a year or two ago.
    ---

    --
    morcego
  231. Re:solution: don't use outlook by schof · · Score: 1

    Someone said: Another virus that doesn't affect web-based email (not to mention pine or MacOS or whatever). Seems pretty clear that Outlook will continue to be exploited in new ways for the forseeable future.

    And then someone else replied: I don't know enough about it to determine the extent to which it can affect non-Outlook clients. I do know that, according to CNET, it does try other means of spreading as well.

    Although many virii and worms do rely on Outlook's crappy design and implementation of security issues, this one does not. (There doesn't seem to be any agreement between virus experts (I'm not one) whether SirCam is a worm or a virus. To me, it looks like a hybrid.)

    SirCam harvests e-mail addresses through two methods:

    • It will search through temporary HTML files (from your Internet Explorer cache only) and use any e-mail addresses it finds.
    • It will harvest addresses from *.WAB (Windows Address Book) files on your HD. (I'm not clear on what program uses *.WAB files. I use Eudora for my e-mail on my Windows computer, and although there is a *.WAB file on my system, it is empty.)
    According to the Symantec web site, the virus "contains its own SMTP server which is used for the email routine." It's not dependent on Outlook at all.

    References:
    http://www.sarc.com/avcenter/venc/data/w32.sircam. worm@mm.html.

  232. Re:solution: don't use outlook by refactored · · Score: 2
    So you have never run GhostView on a postscript document have you? Or JavaScript in your browser?

    What about that fetchmail exploit that went by the other day?

    Are you "up to date" on your distributions security patches?

    Have you read http://project.honeynet.org/

    I think we linuxers are too complacent and will suffer one day...

  233. Re:Install Patch for Correcting Outlook Express by RustyTaco · · Score: 1
    apt-get install imap
    1. Setup the imap server in OE
    2. copy the messages to IMAP folders.
    3. Get a better mail reader

    - RustyTaco
  234. comp virus == true viruses? by anshil · · Score: 2

    I think comparing computer viruses with real life viruses reveals a lot similarities.

    For the real life viruses the human body as defender is the "operating system" it tries to keep itself clean from evil attackers. But it doesn't bother to spend energies on harmless intruders. There a dozends of harmless bacterias even one or two harmless viruses, some of these even help the human body. Especially I remember one virus that attacks and spreads only through "unwanted" bacterias. This virus is the human bodies friend, on we all have tousends if not millions of this one on our body.

    If an intruder seems to be harmfull your body starts to attack it, it's a common trick for viruses/bacteria to trojan themselfs into the human body, in the beginning they are nice and cute and after some time if they are strong enough they suddendly start to mean, salmonella is such a bakteria, or AIDS that lives quitly and hidden over 10 years or more. BTW, there some brand new cures in evalation building on this knowledge, "telling" the human body early that this introdur is evil.

    So each virus goes a small path between being tolerated, survive/spreading itself and how much attention it will receive. Also a virus doesn't gain anything if it's host dies, in history there were viruses which completly killed a whole population (I think there is some proof that it happened to some bird kinds), and at the end the virus dies himself.

    Okay what has it to do with computer viruses? Take in example the "parityboot" virus in our capital city (Vienna) this virus was spread every some years ago, why? Because it didn't destroy any data, yes the paritity boot errors were nasty if you didn't know the virus and that it was the cuase, but once you knew it you just had to ignore that message and everything was fine. People knew it. However to completly clean it from a companies net required to scan all discs, that times the main medium, which of course would cost quite an amount and time, so many simply chosed to live with that virus, it was even funny in some kind. Same as the old 'gimma a cookie' virus everybody found it so cute you was even happy if you got it.

    However the meaner a virus the harder it counter attacks. If in example I know I've a virus that bombs some IP address I'll think yes I'll clean it, as soon I've time, maybe tomorrow. If I know it might delete my data I want it removed from my harddisk NOW! If I know it sends confidential data to my competitors/costumers I would consider completly wiping all infected harddisks. A virus beeing that mean,ie by altering files it will have no spreading, people will put all afforts in killing it quickly.

    BTW: how many viruses for linux exist? ;o) And please don't come me with because nobody uses it. It's because all the programs run in an isolated sandbox by default, and have no possiblity to alter any sytem files.

    --

    --
    Karma 50, and all I got was this lousy T-Shirt.
  235. love your sig by imaginate · · Score: 1

    that is all.

  236. Re:solution: don't use outlook by tb3 · · Score: 2
    PIF stands for Program Information File (from the Microsoft Department of Redunancy). It's a Windows 3.X hold-over that basically describes how a DOS program is going to run under Windows (full-screen or windowed, how much extended/expanded RAM to allocate, etc).

    Thanks to the wonders of Microsoft backward-compatibility, the darn things get treated as execuatables in the Win32 environment.

    Even better, if you have a file with a double extension, such as .txt.pif, Outlook shows it as a .txt file, but the OS treats it as a .pif file. Microsoft makes things too easy for the virus creators, don't you think?

    --

    www.lucernesys.comHorizon: Calendar-based personal finance

  237. It's the software, stupid by SpeelingChekka · · Score: 1

    Users want the ability to double-click on executable attachments in order to open them, and email software needs to honor that request to stay competitive

    Opening documents via double-click from email is ONE THING. Getting your network infected from opening a WORD PROCESSOR DOCUMENT is ANOTHING THING. Opening and viewing an innocent, benign-looking MSWord document SHOULD NOT allow a user to become infected, and the problem with the "culture" you refer to is the culture that says that that is "normal" and "acceptable". It even happened to me with this Sircam virus - I had an up to date anti-virus guard program running, am clued up technically, and I thought "I'll be safe". I opened a Word document. Thats all I did. There were NO WARNINGS, NO MESSAGES, no indication whatsoever that a program had now installed itself on my PC and was spreading through the network. At the very least, MS Word should warn you before executing any content, but it doesn't. There is no excuse for that, and the fact that Microsoft continues to defend their actions is pathetic. That is the real problem here. I don't even use Outlook, I use Pegasus. I saved the Word document, opened it. Not even a warning that something had been EXECUTED. We're talking about a Word processor document, not an .EXE. If even clued up people make mistakes, I feel sorry for Joe User. What good is having a Word processor if you need to feel afraid to even open a document?

  238. Mostly correct, but incorrect by SpeelingChekka · · Score: 1

    You are correct. However, you imply that thats the ONLY way a user can get this virus. However, if you happen to have your C drive shared (as many people have for some strange reason), and someone else on the LAN becomes infected, you too will become infected, unknowingly, without even doing anything, as the virus will copy itself to your C:\Recycled directory and add an entry to c:\autoexec.bat to run itself. Thus, you don't have to do ANYTHING to become infected. The SirCam is thus a virus, a worm, and a trojan. (It will also run in the background, it copies itself over rundll32.exe in Windows, making it harder to spot, and rundll is very commonly run on Windows).

    Of course, its fine and well to say "only stupid people share their C: drives", but I have three other computers in my office which I've shared the C drives and mapped because I do network programming and it is very convenient that way. NOTE: The shares ARE password protected with a VERY cryptic password, yet this SirCam had no problem with that. Now use your imagination: picture the next version of this virus having Cain-style functionality integrated into it - not only would it be able to find open shares, but fetch passwords out your cache for other password-protected shares, and it might even do brute force cracks, sniff the network for password hashes, grab them off NT servers and crack the lame passwords of EVERYONE on your network, or set itself up to grab password hashes from password-protected shares that you have on your machine. It a matter of if, not when, that someone creates a virus that does this.

    This problem MAY be ported to Linux .. however, all of the security mechanisms that Linux uses make it a helluva lot harder for such a virus to spread on Linux. If you have a basic knowledge of how Unix/Linux work, you will understand that. One often hears that argument though from people who know nothing about Linux security and protection mechanisms, you'll often hear them say "so what someone will sooner or later do the same thing on Linux" .. when you try explain the layers of protection that have been built in, they just look at you funny, or say "so some clever virus writer will figure out a way around them". Maybe it'll happen, yes. But it may happen once a month or once a year on Linux, because of the protections. With Windows, new viruses like this are released EVERY DAY, and a new one that becomes as widespread as Sircam seems to be an almost weekly occurrence lately. With Windows, its a daily part of the package - people have come to accept viruses on Windows in the same way we all just expect to get a cold every Winter. With Linux, it'll be regarded as something strange, unusual. Thats the difference.

  239. Incorrect! (not informative!) by SpeelingChekka · · Score: 1

    You are incorrect, the virus WILL infect .zip, .exe, .xls and .doc files that are on the users hard disk and forward THOSE documents to others in the address book. This virus has already emailed me a zip file of the source code to someones commercial project!

  240. No by SpeelingChekka · · Score: 1

    You can be infected by this virus from doing something as simple and benign as opening a word processor document or spreadsheet - without even so much as a warning that the Word document is executing a program. Do some research before posting, you say "from reading the articles" but it looks like you only glanced through the articles yourself. It extracts .exe files to your harddisk, but can infect and be spread by .xls, .doc, .zip and .exe.

  241. Re:solution: don't use outlook by angry_android · · Score: 1
    Actually it affects both hotmail and yahoo mail. If you read norton's write up, it reads temporary internet files and grabs email address from there as well.
    Please mod his comment down it is false.
    From http://www.norton.com/avcenter/venc/data/w32.sirca m.worm@mm.html

    10. The worm contains its own SMTP server which is used for the email routine. It obtains email addresses through two different methods:
    • It searches the folder that is referred to by the registry key

      HKEY_CURRENT_USER\Software\Microsoft\
      Windows\CurrentVersion\Explorer\
      Shell Folders\Startup\Cache

      for sho*., get*., hot*., *.htm files, and copies email addresses from there into the file %Windows%\sc??.dll (where ? is a random letter and number).
    • It searches the entire drive for *.wab (all Windows Address Books) and copies addresses from there.
  242. Incidentally by MacGod · · Score: 2

    For whatever it's worth, the copy of the virus I got (I'm on a Mac so it did a whole lot of s**t-all), came as a 1.5MB .text file. Neither of the articles linked by this story list .text as one of the common extensions. Just one more thing to watch out for.

    --
    "Reality is merely an illusion, albeit a very persistent one " -Albert Einstein
  243. Re:solution: don't use outlook by flippety_gibbet · · Score: 4

    ...spread as source code and then recompile on various client computers, thereby appearing to be different viruses on different platforms...

    Is this how java got so damn popular?

    --
    <-- You are here.
  244. Unthinkable - Thinkable by flacco · · Score: 5
    To paraphrase an admin at our University during a mailing list discussion about Outlook:

    "Prior to MS Outlook, if you suggested to ANYONE that a mail client should be able to execute foreign code sent to you through e-mail, they'd have looked at you like you just grew an extra head."
    --
    pr0n - keeping monitor glass spotless since 1981.
    1. Re:Unthinkable - Thinkable by Budster · · Score: 1

      Funny, I remember uttering the same thing about web pages. Until Java was released... I thought... OH Fuk!!!! It will only be a matter of time before they find a backdoor and we are screwed.

      I still don't use HTML mail... I saw the Exchange servers usage grow when the upper management wanted to use HTML enabled mail because it looked pretty.

      Well.. On an old text-based system (Banyan's Beyond Mail) I was able to place 130 users on a 1GB drive (with maybe 150MB dedicated to mailboxes). When Exchange moved in, we had to bring in 20GB drives, and even that wasn't enough... 300 users on one server (we had to recycle the older/newer servers for NT) can sure take up space. Even user network drives swelled beyond capacity. Oh well.. but we had pretty mail! :)

      Thankfully, I work at a new company and their policy is - NO MS OUTLOOK PERIOD. I smiled. I like using Netscape IMAP mail with the Exchange server. The Exchange part still sux, but at least its not Outlook.

      I use Opera as the browser of choice, cuz Netscape just keeps crapping over itself when it comes to a page designed for MS's flavor of javascript. People who use FrontPage, need to get a life and learn how to write documents, not pages that attract someones interest for more than 5 seconds. If the page is a slow loader - I'm gone! :)

  245. SirCam info by Ballresin · · Score: 1

    Here's some interesting info on how SirCam works.
    ---

    --
    I got nothin'.
  246. Re:Praises to Pine.. Outlook? Would MS make a patc by TeraCo · · Score: 1
    An exec at my work was having a problem with powerpoint resizing the fonts on a certain page unexpectedly. Sure enough, I checked the Office2K web page and it was a known bug, fixed in SP2.

    I say to the exec, "Aha! This will surely fix your bug" and she said "Yes, please install it post haste, I can not live a second longer while my powerful fonts change so erraticly!". So I diligently installed the SP, which took over an hour of my life. [I even stayed late to do it, as she wanted to take her laptop overseas the next morning.]

    The next morning she rings me up at 6am saying "I can't open my mail, when I double click on it, it only gives me the option to save it, not to run it.". I did a bit of investigation, and it turns out that it also installed the latest patches for outlook, including this one.

    I explained it all to her, carefully pointing out that this was a benefit as it was more secure, and you also get the benefits of having your powerpoint fixed. [As many as many other bugs in O2K fixed.] She mulled it over for about 2 seconds and said "Remove it".

    And so our intrepid IT Support person removed the service pack, and [mentally at least] clubbed the executive around the head.

    --
    Not Meta-modding due to apathy.
  247. Re:Praises to Pine.. Outlook? Would MS make a patc by TeraCo · · Score: 1

    Yes, but the point was that the executive took CONVENIENCE over BUG FIXES to problems that she was having.

    --
    Not Meta-modding due to apathy.
  248. Use Pine by s20451 · · Score: 2

    Ever heard of a Pine virus? Exactly.

    --
    Toronto-area transit rider? Rate your ride.
  249. solution: don't use outlook by MajrMeximelt · · Score: 4
    Another virus that doesn't affect web-based email (not to mention pine or MacOS or whatever). Seems pretty clear that Outlook will continue to be exploited in new ways for the forseeable future.

    This will not be the last time we see a Slashdot headline of this nature (and I seem to recall that it's not the first either...)

  250. unfortunately, by EvilStein · · Score: 1

    You're right.. what gets me are those that are *not* on an Exchange server, but they want to use Outlook "because it's familiar to them" rather than at least using Outlook Express or..gah, anything else but Outlook.
    I've got a few lusers that I'm trying to wean away from their outlook dependancy, but it's not going so well so far *sigh*

    1. Re:unfortunately, by Unknown+Bovine+Group · · Score: 2
      Yeah there's no viruses for my VIC-20 either. Why? Nobody cares enough to write 'em.

      --
      m00.
  251. Yet again, we see by kypper · · Score: 2
    that Java is not the issue with Microsoft and viruses.

    I'll be good goddamned if I'll ever use Outlook again, simply because it is so easily picked and well susceptable to Vbasic script viruses etc.

    Screw 3...

  252. Re:Praises to Pine.. Outlook? Would MS make a patc by NorthStar4 · · Score: 1

    Actually, there is a patch for these sort of problems. Details are here, or just download it directly here.
    Basically, it will not allow the user to access (run, or save to disk) any executable file (.exe, .vbs) etc. Other files (like .zip) _must_ be saved to disk before being opened. This would pretty much stop this virus/trojan in its tracks.
    It's been out for over a year, but it seems admins aren't deploying it (for whatever reason).

  253. Install Patch for Correcting Outlook Express by christoofar · · Score: 2

    1. Click Start, Settings, Control Panel.
    2. Click Add/Remove Programs
    3. Select Outlook Express
    4. Click Remove or Uninstall (depending on OS version).

    5. Go get a copy of Pine compiled for Win32 and install it ASAUC (As soon as you can).

    {awaiting the flame-bait}

  254. IMNSHO by sinserve · · Score: 1

    The M$ OL is ...

    wait, i forgot what i was about to say. damnit, must be the guy from the "censorship" icon, he is looking
    at me, with his mouth shut, just like my father,
    when i was suffacting him to death.

    take him away please, and have a picture of a yellow kiwi or something.

  255. Re:Praises to Pine.. Outlook? Would MS make a patc by All+Dead+Homiez · · Score: 1
    Don't you think it's about time that MS comes out with a freakin' security patch that stops scripts from broadcasting across your entire contact list?

    That might treat the symptom (sometimes) but it doesn't treat the problem. Contact lists are easily accessible through COM objects, from a trusted process. Untrusted code (like scripts on web pages) are not allowed to access address books.

    The root problem is that people run attachments with the same privileges that their user account has. Therefore the attachment runs as a trusted process. As long as A) people still run executable attachments, and B) those attachments run with the same level of access that the user has, there is absolutely no way to prevent the attachments from impersonating the user and flooding the net with virus mail.

    As a side note - Eudora and Netscape Mail both allow users to run executable attachments. The reason that their address books are not targeted is not that it's impossible (it is definitely possible to write a program to read them; I have seen it done) - it is because Outlook is the most popular program out there and it's easy to code a virus that accesses Outlook contact lists. If M$ had not driven Netscape into the bit bucket in the 90's and everyone used Netscape Mail today, these virusus would work just the same for that client. (That's not to say that Outlook doesn't have plenty of other faults - it does.)

    -all dead homiez

  256. It's the culture, stupid. by All+Dead+Homiez · · Score: 4
    I'm sure a lot of people here are going to go out and blame Microsoft for the Outlook-virus-of-the-week. But the fact is, Microsoft is just giving the user what they want. Users want the ability to double-click on executable attachments in order to open them, and email software needs to honor that request to stay competitive.

    The underlying problem here is that people have come to accept executable attachments as the norm. Years of silly Flash greeting cards, "snowball fight" games, and Joe Cartoon crap sent across offices since the mid-1990's have hooked Windows users on native-binary attachments. The only way that this sort of activity can be stopped is by making it socially unacceptable (improper netiquette) for anyone to send executables through email. Think about what would happen if one of your colleagues sent you a random Linux binary through email and claimed it was a greeting card - would you run it? Well, the drooling masses will run any .exe that a "known" source sends to them, and that is the crux of the problem.

    Unfortunately, it is in content producers' best monetary interest not to change their distribution strategy to use a format that requires less trust (such as .swf or even .html). That would artificially limit the quality of their goods, and closes the door to including "value-added features" (like spyware) to their attachments. Therefore, the situation shows few signs of changing anytime soon, and users will simple work around any stopgap measures in their email software so that they can continue to play their "frog in the blender games" in perpetuity.

    -all dead homiez

  257. Re:solution: don't use outlook by Unknown+Bovine+Group · · Score: 2
    Yeah these articles are getting pretty weak. What's up with:
    Nothing particularly original there, except this virus is pretty unique both in how it operates, and what it does

    Hmm. It's unoriginal, yet totally new in how it operates and what it does.

    Does this strike anyone else as contradictory?

    -- Just your average guy, except with 2 heads and an eye stalk in my chest.

    --
    m00.
  258. so what? by Tuxinatorium · · Score: 1

    There's a major new M$ based virus every week. This hardly qualifies as news.

  259. Re:solution: don't use outlook by Budster · · Score: 1

    Actually,
    I'm surprised no one has included a list of 100 to 500 hotmail accounts in the virus. That way they can mail one to your friend and one to a Microsoft Hotmail account.

    The virus that keeps on giving!

    For once it would be nice for Microsoft to feel the brunt of these attacks.

    :)

  260. Re:solution: don't use outlook by aarakawa2003 · · Score: 1

    I don't know, why don't you try it, so you can get arrested and thrown in jail.

  261. Oh Crap! by Nathdot · · Score: 4

    I've just realised it doesn't matter what mailer I use. The fact that this virus/worm/whatever even exists means I'm gonna suffer!

    With all this media attention my Mom's gonna start sending every freaking bogus virus warning on the planet (She scares very easily; The poor dear!).

    I'd rather get the virus.

    :)

  262. Once again I miss out on everything by Nathdot · · Score: 5

    I wish I used Outlook...

    I completely missed out on that whole "Anna Kournikova" thing and now I can't even run this one...

    It's either buy Outlook or hope Lotus Notes releases a "Microsoft Virus Enabler" patch

    *sigh*

  263. Solution: Ban Stupidity! by redcliffe · · Score: 1

    I use Outlook on my Windows machines, and have received email virus quite often. I have never been affected by them though, because I just don't open anything suspicious.

  264. Re:solution: don't use outlook by Ridiculator · · Score: 1
    Don't be rediculous here.

    Ridiculous.

    I should know.

  265. Outlook Virus #23948842^99 (conservative estimate) by madman2002 · · Score: 1

    Ahem, Microsoft issued a warning today that their popular e-mail program Microsoft Outlook has once again been exploited by evil superhackers. At a press conference this morning Mr. Gates said this of Outlook Virus ##23948842^99: "I have never seen a virus as advanced as #23948842^99, those evil superhackers have struck again. The mind boggling intelligence it would take to exploit a product as secure as Microsoft Outlook has me believing that it is the work of advanced alien life-forms with a secret agenda. It is also believed that these aliens are also the cause of all other Microsoft security problems, the incredible size of the Windows OS, and the coming of the antiOS (Linux). Please help us stay strong against the aliens by supporting Microsoft in our hour of need, don't switch e-mail programs or your OS, thats what the aliens want." As always we will keep you informed of any further developments in the Outlook Virus #23948842^99 story. Really if your still using Outlook of your own free will you deserve a virus and a kick in the ass from anyone who receives the virus from you.

    --


    http://www.gamedev.net/reference/articles/article1 015.asp A spin on the old, if Microso
  266. Actualy, it is a virus. by AnthraX101 · · Score: 1

    It attaches itself to another file, reporduces iteself, and has a payload. That is therefore a virus ;) AnthraX101