Slashdot Mirror


Targeted Worm Hits Kazaa's Network

sh0rtie writes: "Kaspersky Labs and the BBC are reporting that the Fasttrack network that Kazaa uses has been hit by its first targeted worm virus dubbed 'Benjamin.' Is this a clever RIAA creation or that of a mischievous virus writer? I guess we will never know, but the result is that it seems to be bringing unsuspecting users machines to a crawl with full hard drives and clogging up the Fasttrack network with massive amounts of traffic bringing more headaches for ISPs and sysadmins worldwide."

300 comments

  1. any surprise? by eyegor · · Score: 0, Insightful

    Yet another reason not to use them. geez....

    --

    Don't anthropomorphize computers, they don't like it.
    1. Re:any surprise? by DrugCheese · · Score: 1

      Really, who wants to use such an advertisement ridden program anyway. Now it's infested with something more lethal. woohoo

      --
      *DrugCheese rants*
    2. Re:any surprise? by Anonymous Coward · · Score: 0

      I wonder if anything like this had ever hit Napster in the past? I don't remember such a thing. I think this is all due to the crappy code the fasttrack people created -- a lot of it spyware and other crap that is supposed to give them too-much control over your system.

      _
      WINDOWS USERS CLICK HERE!

    3. Re:any surprise? by loply · · Score: 1

      Yeah, who would want to use such a program?

      Well, from what I can gather... two million, two hundred & twenty six thousand, five hundred and thirty six regular citizens of Earth, who want to access over a million gigabytes of pirate software, mp3s and porn. Duhh. Wake up.

    4. Re:any surprise? by DrugCheese · · Score: 1

      two million, two hundred & twenty six thousand, five hundred and thirty seven complete morons

      kinda low from my recent headcount of sheeple out there

      --
      *DrugCheese rants*
    5. Re:any surprise? by peddrenth · · Score: 1

      So this virus doesn't affect you if you use KazzaLite, right? And you also use less bandwidth. ?And you use less processor time, so everything else runs faster?

      Looks like Kazza's going to get a whole lot less popular as the malware-enabled version goes..

    6. Re:any surprise? by Lazyhound · · Score: 1

      Actually, it affects KazaaLite users, too. Remember, the only difference is that the spyware has been removed. Any security loopholes present in one are bound to be present in the other...

    7. Re:any surprise? by xtremex · · Score: 2

      I have a Kazaa clone that uses the Kazaa network w/o using the crappy Kazaa Software.Unfortunately, it's for windows only :(
      Go to http://cguru.cjb.net. It's called MyKazaa

      --
      If you're not a Liberal in your 20's, then you have no heart.If you're still a Liberal in your 30's you have no brain.
  2. "Clever RIAA creation"??? by Wakko+Warner · · Score: 3, Funny

    Look at the kind of music these fellows put out. Now tell me anything they create is "clever".

    - A.P.

    --
    "Remember when the U.S. had a drug problem, and then we declared a War On Drugs, and now you can't buy drugs anymore?"
    1. Re:"Clever RIAA creation"??? by peterwayner · · Score: 1

      There are plenty of songs that infect my brain like a virus and I can't get rid of them. They may sound stupid if you think of them, but maybe they prey on the unconscious. In fact, that's probably why they give their music to radio stations.

    2. Re:"Clever RIAA creation"??? by Danse · · Score: 1

      Look at how much money they make. Now tell me how anything they create could be anything but clever.

      --
      It's not enough to bash in heads, you've got to bash in minds. - Captain Hammer
    3. Re:"Clever RIAA creation"??? by Anonymous Coward · · Score: 0

      >> In fact, that's probably why they give their music to radio stations.

      In fact, you are wrong.

      It's the distributors whom give the radio stations the music, not the R.I.A.A..

      In fact, those radio stations have to pay a royality on every song they play.

      So radio stations are hardly getting free music!

    4. Re:"Clever RIAA creation"??? by Wakko+Warner · · Score: 2

      When you own the means of production, distribution, and broadcast, does anything you create need to be clever?

      - A.P.

      --
      "Remember when the U.S. had a drug problem, and then we declared a War On Drugs, and now you can't buy drugs anymore?"
    5. Re:"Clever RIAA creation"??? by Danse · · Score: 1

      Ok then, the industry must be pretty clever to have secured such seemingly unassailable power for themselves, so yeah, I guess their creations don't actually have to be clever.

      --
      It's not enough to bash in heads, you've got to bash in minds. - Captain Hammer
    6. Re:"Clever RIAA creation"??? by MattCohn.com · · Score: 0

      Most radio stations pay for a couple of blanket licences that cover all the music they play. So if they were going to pay the same amount ANYWAY... getting music IS free music.

  3. of all days.... by jeffy124 · · Score: 5, Interesting

    the day the secret Kazaa/Brilliant network came to life is the day that this worm gets let loose.

    --
    The One Rule Of Chess You'll Ever Need: Don't play someone who carries a kit in their bookbag.
    1. Re:of all days.... by randomErr · · Score: 1

      It's not a virus, its an undocumented feature.

      --
      You say things that offend me and I can deal with it. Can you?
    2. Re:of all days.... by Anonymous Coward · · Score: 0

      let's see. the guy didnt call the secret network a virus (it also happens to be documented in the user agreement). he didnt call the worm a virus (worm != virus by definition). what is he calling a virus?

  4. clever RIAA creation? by crovira · · Score: 0, Offtopic

    Bwahahahahahahaha.

    Those Luddites? I'm surprised they don't use a pen make by plucking a feather from a goose's ass.

    Oh that's rich. Thanks for laugh...

    --
    MSBPodcast.com The opinions expressed here are my own. If you don't like 'em... Think up your own stuff.
    1. Re:clever RIAA creation? by Anonymous Coward · · Score: 0
      You're right - they are Luddites! From the article:
      In addition to eating up free disk space Benjamin takes additional actions: under the name of the infected computer's owner it opens an anonymous web site from which it displays advertising banners. This way Benjamin's creator profits by the resulting increase in advertising displays.

      You'd think they would have learned how to use pop-ups before now...

  5. [deep sigh] by coronaride · · Score: 1

    seeing as how everyone and their grandmother's dog-sitter read the post about Kazaa's involuntary spyware and then promptly deleted Kazaa from their system, I really don't see how this story should effect anyone..right? hmmm..on second thought..is it the kazaa NETWORK?

    --
    Those who can, do. Those who can't, go into business for themselves.
    1. Re:[deep sigh] by Anonymous Coward · · Score: 0

      I still use Kazaa-Lite which is supposedly stripped of all the spyware (and according to Ad-Aware it is except for the dummy cydoor library). Why? Because I can't find shit on Gnutella compared to Kazaa! When I finally do find something, every link I try doesn't work. It's totally lame. Man do I miss Napster... the days of searching for something and finding 60 different hits on it in seconds. *sigh*. EVERYONE was on Napster. FUCK THE MPAA/RIAA!!!

    2. Re:[deep sigh] by Anonymous Coward · · Score: 0

      no kidding...i've got the kazaa lite running and gnucleus. So much more to be had on Kazaa, virii included apparently.

    3. Re:[deep sigh] by Anonymous Coward · · Score: 0

      a lot of people will still have this programme, the spyware wasn't reported THAT much.

  6. Warez Connection by _bobs.pizza_ · · Score: 2, Insightful

    how big of a surprise is this? The whole idea behind kazaa is that you can get music that you don't own. This reminds me a lot of the warez sites out there. How many of us trust them?

    You get what you pay for.

    1. Re:Warez Connection by Anonymous Coward · · Score: 0

      You get what you pay for.

      Yep, that's why I don't use Linux.

    2. Re:Warez Connection by Anonymous Coward · · Score: 0

      Now that, sir, is comedy gold.

    3. Re:Warez Connection by Anonymous Coward · · Score: 0

      I certainly don't "trust" them, but I've gotten tons of great software from them which I wouldn't have purchased, but was fun to try out. And games that are great to play for a few weeks but that I'd NEVER had paid money for.
      The warez scene has its purpose. You don't have to use those sites, and yes, buyer beware...viruses do pop up, but [knock on wood] I've never been INFECTED by one and have only found 3 EVER since 1990 in all those thousands of warez I've "evaluated."

    4. Re:Warez Connection by Anonymous Coward · · Score: 0

      I have had the same experience that you have had. And if I ever do get a bad virus, I make sure everything is backed up.

    5. Re:Warez Connection by VisMono · · Score: 1

      HOW DARE YOU!!! So true though. Very few things that are free compare well to those that are not. OS's are no exception.

      --
      'There is great chaos under heaven, and the situation is excellent.'
    6. Re:Warez Connection by shepd · · Score: 2

      I remember hearing about a leaked study from a long time ago done by a virus detection company.

      The results seemed to (at the time) finger purchased software and hardware as the prime infection point for many machines.

      Why?

      At the time, BBSes autochecked files for viruses, and most people ran their disks through CPAV/F-Prot before giving them to others (since people "smart" enough to copy a disk were, at the time, able to run simple virus detection software). However, at the same time, major brand name companies didn't bother as much.

      I can even remember a friend buying formatted floppies that came with a virus dropper on the disks...

      If 100 people download infected software from one illegitimate site before the infection is pointed out and cleaned, that's just 100 people. Imagine the destruction that happens when you go gold and don't find out until a few weeks later that your CDs (or computers, or floppies, whatever) include a virus.

      If anyone can find a link to that study, I'd really appreciate it. :-)

      Sometimes you get more than you pay for.

      Your PC is now stoned !!!

      --
      If you could be told what you can see or read, then it follows that you could be told what to say or think - BoC
    7. Re:Warez Connection by Anonymous Coward · · Score: 0
      You get what you pay for

      [Looks at latest Britney Spears CD.]

      [Looks at price tag on said CD.]

      Are you sure?

    8. Re:Warez Connection by Anonymous Coward · · Score: 0

      very true, I've been trying games out from the warez 'groups' and have only found one or two infected, and even those were package specific because the rest of them on the ftp/bot/site were ok. The only this that ever infected me was... stoned one of the many variants if you rember it's name you can understand how long ago it was.

    9. Re:Warez Connection by Anonymous Coward · · Score: 0

      yes, it was stoned...

  7. Stupid Virus Writer? by Saeculorum · · Score: 5, Insightful

    From the article...

    In addition to eating up free disk space Benjamin takes additional actions: under the name of the infected computer's owner it opens an anonymous web site from which it displays advertising banners. This way Benjamin's creator profits by the resulting increase in advertising displays.

    I might be wrong, but I'd think it'd be quite easy to find where the money from the advertising banners is going to. Quite simple to find the virus writer.

    Of course, the recipient of the advertising revenue may not be the virus writer, but it's a good place to start.

    Stupid people amuse me.

    1. Re:Stupid Virus Writer? by sheriff_p · · Score: 1

      Quite simple to find the virus writer. Because s/he must live in a country where Americans have jurisdiction.

      Right? Or maybe that won't help anything at all. And maybe it'll be almost impossible to bring charges against him/her because that would involve companies claiming damages. Companies that admit their employees were using software to steal music.

      Perhaps you didn't really think this through?

      As you said, somewhat ironically, 'stupid people amuse me.'

      --
      Score:-1, Funny
  8. Overhyped? by CmdrTaco+(editor) · · Score: 0, Troll
    ...under the name of the infected computer's owner it opens an anonymous web site from which it displays advertising banners. This way Benjamin's creator profits by the resulting increase in advertising displays.

    Wow! I think this is the first time I've seen a worm creator actually try to turn a profit. It doesn't really seem to be all that malicious, it also seems that this would be an easy way to catch the person repsonsible. Just find out where the checks are going and arrest him!

    1. Re:Overhyped? by pjkacmar · · Score: 0, Offtopic

      Just wait until Taco finds out that the anonymous web site is actually the Slashdot advertisement program.

    2. Re:Overhyped? by TheLibra · · Score: 5, Informative
      Just find out where the checks are going and arrest him!

      I'm afraid it's not that easy, CmdrTaco. Firstly, you are assuming that the money is going to someone associated with the virus writer. However, from what I understand, there are three types of people who write viruses:
      1. The Attention Getter: This person wants the hype, the name, and the infamy to achieve some sort of status in the cracker or skr1pt k1dd13 community. They don't do it for the money, they just want to be 1337.
      2. The Student: They do it for the study of viruses. They do it to learn. Sometimes it is legit, such as the programmers of anti-virus software, and sometimes it is a hacker (note the distinction I use here) who wishes to understand the why and how of a particular exploit. But we can rule out this type of writer because while they are sometimes in it for the money, they never want to actually cause harm, they want to learn, and their creations are rarely unleashed.
      3. The Causehead: These people write the virus because they feel it will advance their cause. Be it governmental, corporate, or Greenpeace, they have their reasons. They also do not do it for the money.
      4. But take a virus that makes money, such as Benjamin. Well, who says it has to go to the virus-writer. It could very well be a script that sets up the funds to go to any account, anywhere. If the writer was a cause-head, the money could very well be going to Save The Wales or some such to benefit that cause. Or even to a totally unsuspecting list of random accounts, to take away money from the corporations that have to pay for the advertising.


      5. But let us assume that the money is going to the author of Benjamin for a moment. There is also unfortunately the issue of money laundering, offshore accounts, vapor operations, and rerouting of transfers that can make finding out where the money goes all but impossible if someone is clever enough to do it.

        Assuming that someone is keeping the money for themselves, there are a variety of ways that it could be done. As referenced by Carl Sifakis...

        Method 1 Typical Drug Dealer Method

        • 1) Get a million dollars ( how you do this is you own business.)
        • 2) Fly to the Grand Cayman Islands and take your million with you.
        • 3) Some banks in that area sell legitimate off-the-shelf corporations. (These are shell corporations or holding companies. Some even come complete with a board of directors. Buy one of these corporations from the bank.
        • 4) Open an account in one of those banks under the corporation's name and deposit the remainder of your money.
        • 5) Enjoy the islands, get some sun and then go home.
        • 6) When you arrive at home, "borrow" $100,000 from the corporation in the islands by wire transfer. (As sneaky as this sounds, it is totally legal.)
        • 7) Open a restaurant with a bar.
        • 8) At the end of each month, take proceeds from whatever criminal thing you've got going on the side and deposit it in the bank as the take from the bar. It is a good idea to to over report how well you restaurant/bar is doing but not to get to greedy. The Internal Revenue Service takes a dim view of a pizza parlor that purports to do several hundred thousand dollars a month in revenue. If you don't get greedy you won't get investigated. They just don't have the manpower. It is also a good idea to plow some of the proceeds into the legitimate corporation too. If the company does well on its own it can expand and offer more laundering potential.
        • 9) Your criminal money is now clean as a whistle. Pay taxes on it.

        Method 2 The Loanback Method

        • 1) A New Jersey gambler has half a million dollars in profits salted away in a numbered Swiss bank account. He buys a string of car washes( another great way to over report potential sales) for $1 million financing it with 50,000 grand down and $450,000 with a legitimate first mortgage.
        • 2) He "borrows" the other half million from his Swiss bank.
        • 3) Since he is borrowing his own money and repaying it as if it too is a legitimate loan that means he has interest charges. This charade allows him to pay himself the interest and deduct that same interest from his taxes, thus bringing the money back into the country.
        • 4) Once he has paid of his loan to himself he may relend it to himself.

        Method 3 The Money Broker Shuffle Problem

        Mr A is Columbian drug lord. He has a million dollars sitting in New York badly in need of deodorization. Mr B is a legitimate Columbian businessman who wants to buy a million dollars worth of U.S. computers but his government wants 21 cents for every dollar he buys with his pesos.

        Solution: They hire a money broker who for a nominal fee will solve the problem.

        • 1) The million dollars is smurfed or smuggled overland to an account in a Mexican bank. ("smurfing" is process of wire transfer of money in tiny chunks less than 10,000 dollars. This is effort intensive but necessary. Billions of dollars are wire tranfered everyday but only transactions larger than 10 grand are documented by banking institutions. Transactions smaller than this are fully covered under banking insurance. Thus larger transactions are carefully tracked in case something goes wrong. Law enforment also does not possess the manpower to check all these transactions and never will. This is an every damn minute,24 hour a day phenomenon.)
        • 2) The broker writes a check for U.S. 1 million at a correspondent bank in New York City and gives it to XYZ computers.
        • 3) XYZ computers ships Mr B. his machines from its Panamanian free zone warehouse
        • 4) Mr B gives the money broker a million dollars worth of pesos.
        • 5) Pesos become sqeaky clean pocket change of Mr A. Annual loss of revenue to Columbian government: 6-8 billion dollars.

        Method 4 The Omnibus Account Method

        Swiss banks (and others I'm sure) maintain what is known as "omnibus accounts" at American brokerage houses. This make it easy for mafiosi to purchase American blue chip stock anonymously. Naturally, if they make a profit they pay no capital gains taxes on it because there are no records in the U.S. tying them to the stock purchases and the Swiss banks are bound by their laws not to reveal the names of their investors. This enables them not only to make money but to manipulate the market by buying large blocks of stock through the banks and then exercising their proxies, enabling them to determine who will be on the board of directors and who will be C.E.O.


        In Short, if this person has half a brain, then just "seeing where the checks are going" will not reveal the culprit.

        The Libra Eagles may soar, but a weasel never gets sucked into a jet engine.
    3. Re:Overhyped? by Anonymous Coward · · Score: 0

      i hope you know that isnt the real taco...

    4. Re:Overhyped? by wdr1 · · Score: 2

      I'm afraid it's not that easy, CmdrTaco.

      FWIW, the person you responded too wasn't CmdrTaco.

      Give him points for being clever though.

      -Bill

      --
      SlashSig Karma: Excellent (mostly affected by moderatio
    5. Re:Overhyped? by Pig+Hogger · · Score: 2
      ...
      1) A New Jersey gambler has half a million dollars
      ...
      He buys a string of car washes...
      That's how the IRS caught a launderer: he washed something like 450 cars during a 3 day blizzard...

      Dry-cleaners are a good money laundering method (no pun intended!!!). Some years ago, around here, someone started a chain of $1 dry-cleaners. Within weeks he was firebombed into oblivion.

    6. Re:Overhyped? by Slashamatic · · Score: 1

      You forgot OTC derivatives. Very good way of laundering lots of money!

    7. Re:Overhyped? by Anonymous Coward · · Score: 0

      I thought that swiss banks aren't as anonymous anymore. Or maybe it's just me. Can't their government sometimes disclose things? I did hear that Luxumborg (did I spell the right....who cares anyway...its Luxumborg!) is pretty private though. Although, I could be wrong. Just thought I would in my own 2 cents.

    8. Re:Overhyped? by Anonymous Coward · · Score: 0
      Here's a lotery ticket method.


      After you get a winning ticket, spend nine months setting up your own religion. As soon as you get all the paperwork done, and get the religion officially recognized, the church recieves an anonymous donation of a 50 million dollar ticket. Which the church instantly cashes, and instantly pays you, as a signing bonus for being the first priest of your church.

      Why go through all of this trouble? Seperation of church and state. Priests are the only people in the nation that pay zero income tax. No state, federal, OR local tax on money gained while performing the duties of the church.

      End result? You pocket 50 million after taxes instead of 20. And when you are investigated by the fed? Sorry, but when they notice and revoke the tax exempt status of the "church", you have already been paid your money. The fed can revoke the tax exempt status, but can not do it retroactively.

      Gotta love organized crime^H^H^H^H^Hreligion, eh?

    9. Re:Overhyped? by Clemence · · Score: 1

      Right, it's that easy to go undetected. As you leave the country with th $1m cash, you will be required to fill out a declaration form stating you are taking that much currency out of the country - caught. If you don't, that much currency is difficult to conceal and as likely as not will be detected - caught again. When you wire the $100,000, the receiving bank in the U.S. will file a Suspicious Activity Report (SAR - required under U.S. banking law), and your transfer will be flagged in the Financial Crimes Enforcement Network (FinCEN) databases at the Department of Treasury - caught. From there, the feds will find every piece of open-source (and closed source) data available about you . . .

      As if a shell corporation in the Caymans will make everyone look the other way. And paying taxes on it - good lord, what better way to tell the feds "look at me, question my income" You still haven't established a cover for the original income.

      And so on and so on and so on. The feds never catch the smart ones.

  9. I fail to see the "worm" here... by Bollie · · Score: 3, Funny

    but the result is that it seems to be bringing unsuspecting users machines to a crawl with full hard drives and clogging up the Fasttrack network with massive amounts of traffic

    What? Doesn't that happen every time a new cammed version of Spider-Man or AOTC's is released?

  10. Hide the spice! by Limburgher · · Score: 3, Funny

    The worm is coming! It can smell the spice on your hard drive! Delete it, or it'll smash through it and destroy you!

    --

    You are not the customer.

    1. Re:Hide the spice! by Anonymous Coward · · Score: 0
      It can smell the spice on your hard drive!


      There's someone sharing *shudder* Spice Girls videos on KaZaA? Hmmm. Let's see. Windows. Spyware. Total lack of common sense or musical taste. Okay, I can see the pattern.
    2. Re:Hide the spice! by Kphrak · · Score: 1

      +1 DUNE!

      Mod the parent up...this is a clever Dune reference. You know, the novel...or the movie, for those who didn't see the novel.

      No kudos to the people who were stupid and thought the dude was talking about the Spice girls.

      --

      There's no sig like this sig anywhere near this sig, so this must be the sig.
    3. Re:Hide the spice! by Anonymous Coward · · Score: 0

      I didn't see the novel, but I read the movie. Does that count?

    4. Re:Hide the spice! by liquidsin · · Score: 2

      Some of us just enjoyed the video games...

      The Dune game that was like warcraft (erect buildings, build army, kill foes) was the first pc game I ever bought, I think...

      --
      do not read this line twice.
    5. Re:Hide the spice! by Anonymous Coward · · Score: 0

      > The worm is coming! It can smell the spice on your hard drive! Delete it, or it'll smash through it and destroy you!

      Wrong worm; this one's attracted to the smell of fecal networks.

    6. Re:Hide the spice! by Zathruss · · Score: 0

      Or novels(s).. The damn thing went on forever.

    7. Re:Hide the spice! by Anonymous Coward · · Score: 0

      That was a rocking game...I legally own all Dune 2 and dune 2000, I can'T find ANY copy of dune 1.

  11. Death Nell by Nanite · · Score: 0

    Goodbye Kazaa. If the spyware scheme didn't kill you, infecting all of users with viruses isn't going to help. I don't think you could PAY someone to use Kazaa after all of this crap.

    Nanite

    --
    God is real unless declared integer.
  12. The Brilliant Worm is by Haiku+4+U · · Score: 0, Troll

    what you get. Why use Kaaza?? It's a pile of shit!

  13. Next Time A Warhol Worm? by cybrpnk2 · · Score: 5, Interesting

    Some very scary research has been aimed at discovering just how fast a worm could infect the entire Internet. This is the so-called Warhol worm, so named because instead of getting 15 minutes of fame, it would only take 15 minutes to infect the entire internet. If some nut combines a Warhol worm with a Kazza worm, we are in deep trouble.

  14. Re:Fuck the RIAA by Cheesy+Fool · · Score: 0

    But yet you still buy windows games.

    --

    Hail to the king, baby!
  15. Oh, by the way, STEPHEN JAY GOULD DIED by Artifice_Eternity · · Score: 0, Offtopic

    This is not a troll, and it's not offtopic, if Slashdot is truly about "News for Nerds, Stuff that Matters":

    The greatest evolutionary theorist since Charles Darwin died of cancer at his Manhattan home today... here's the New York Times obituary.

    I submitted this story and it was rejected. Apparently Nintendo price cuts and the latest Star Wars box office figures are big news today, but not this.

    I suggest that when Slashdot editors reject stories, they put their names on them, so we the submitters can start to figure out who ignores this kind of hugely important news in favor of trivia. Anonymous users are labeled as "cowards"... seems to me the same applies to anonymous editors.

    Of course I fully expect this story WILL appear on the front page later tonight, or tomorrow, or better yet, in two or three days, after another 50 people have submitted it, and Taco or Timothy or somebody finally recogizes its significance.

    1. Re:Oh, by the way, STEPHEN JAY GOULD DIED by rkent · · Score: 1

      I submitted this story and it was rejected. Apparently Nintendo price cuts and the latest Star Wars box office figures are big news today, but not this.

      Boo hoo for you, did you consider that maybe 13 other people submitted it before you, it's maybe 200 submissions down on the queue, and it might get posted later? Sorry your story got rejected and you don't get any karma, but please. Enough with the ragging on people because they talk about other stuff besides your pet topic.

    2. Re:Oh, by the way, STEPHEN JAY GOULD DIED by tgibbs · · Score: 1

      A great loss, not merely for his contributions to evolutionary theory (and whether you agree with him or not, he has undeniably raised crucial issues that have stimulated progress in the field), but for his contributions to scientific history, and showing that serious scientific writing does not need to be dull or stilted.

      I agree, this deserves its own topic. But this thread is sort of about evolution, isn't it?

    3. Re:Oh, by the way, STEPHEN JAY GOULD DIED by nomadic · · Score: 2

      Boo hoo for you, did you consider that maybe 13 other people submitted it before you, it's maybe 200 submissions down on the queue, and it might get posted later? Sorry your story got rejected and you don't get any karma, but please. Enough with the ragging on people because they talk about other stuff besides your pet topic.

      I doubt the original poster cares about karma; he's complaining about the fact that the editors just have no apparent ability to pick stories anymore. Gould was a brilliant scientist whose passing should be major news. Instead we get an endless succession of stories about file sharing and wireless networks. Interspersed, ironically, with self-congratulatory stories about how brilliant, well-rounded, and scientifically literate geeks in general are.

    4. Re:Oh, by the way, STEPHEN JAY GOULD DIED by MoneyT · · Score: 2

      If the original poster actualy cared about his Karma, do you honestly think he would have posted under his account instead of anonymously?

      --
      T Money
      World Domination with a plastic spoon since 1984
    5. Re:Oh, by the way, STEPHEN JAY GOULD DIED by DouglasA · · Score: 2
      Gould was a brilliant scientist whose passing should be major news.

      Yes, it is major news. That's why it's on the front page of CNN, Boston.com, etc. I do not need Slashdot to cover stories that I'll hear about anyway. I come to Slashdot to get more interesting, off-the-beaten-path stories, or sometimes interesting commentary on hugely important news (not just the passing of someone famous).

      Making the Slashdot front page does not mean that the Kazaa worm is more important that SJG. It's called perspective.

    6. Re:Oh, by the way, STEPHEN JAY GOULD DIED by Anonymous Coward · · Score: 0

      Every fucking one of these stories is FPN on the net somewhere. There is not one single story that is a slashdot original! not one! No one needs slashdot for anything except bitching about meaninless drivel. News? HA!

    7. Re:Oh, by the way, STEPHEN JAY GOULD DIED by Anonymous Coward · · Score: 0

      Sadly, the type of INFORMED DISCUSSION and REASONABLE DISCOURSE you're desiring is only available via our SLASHDOT2 service. Sadly, SLASHDOT2 is only available via our INTERNET2 service.

    8. Re:Oh, by the way, STEPHEN JAY GOULD DIED by Anonymous Coward · · Score: 0

      And now it has its own topic

    9. Re:Oh, by the way, STEPHEN JAY GOULD DIED by ahde · · Score: 2

      1) Only political statements make the front page of any major mainstream publication. News, Ads, and everything else takes a back seat.

      2) Do you think when the Pope dies that it will make the front page on Slashdot? There are a whole heap more catholics than evolutionists in the world. Probably even on Slashdot.

      3) The Kazaa worm affects alot of people, and actually is relevant to the FUTURE. To top it all off, it's even "tech" or "computer" news, which is what slashdot is mostly about.

      4) Obituaries don't belong on the front page. See #1.

    10. Re:Oh, by the way, STEPHEN JAY GOULD DIED by Anonymous Coward · · Score: 0

      Catholics *are* evolutionists.
      http://www.newadvent.org/docs/jp02 tc.htm
      http://www.2think.org/pope.shtml

      Or at least, the catholic church isn't officially
      against evolution.

  16. How is it activated? by Shagg · · Score: 4, Insightful

    The way I understand the article, it replicates itself in someone's share directory and waits for other Kaaza users to download it. How is it executed on the remote user's computer then? Do they have to specifically run the virus program, or is there a security hole in the Kaaza client somewhere that automatically executes the virus?

    I'm assuming users that download this file must specifically execute it. If this is true, then IMHO any person who downloads an unknown .exe from a P2P network and runs it without at least scanning it, deservers what they get.

    --
    Unix is user friendly, it's just selective about who its friends are.
    1. Re:How is it activated? by eddy · · Score: 1

      I don't see how it can deserve the designation worm if it takes user intervention to spread, both a) to download it and then b) to execute it, which is the impression I got from the Kaspersky bulletin.

      Wouldn't simply trojan be a better fit?

      Indeed, the bulletin calls it a "worm". Let's continue doing that so as to not confuse matters even more than they already are regarding the designation of all these malware.

      --
      Belief is the currency of delusion.
    2. Re:How is it activated? by rkent · · Score: 0, Troll

      I'm assuming users that download this file must specifically execute it. If this is true, then IMHO any person who downloads an unknown .exe from a P2P network and runs it without at least scanning it, deservers what they get.

      Oh come on, cut some slack. You know as well as everyone that non-exe files are associated with an app based on extension, and double clicking (for example) an mp3 file opens it in WinAmp. So if this thing gets downloaded and aliased as "Simpsons Theme.mp3", you should be able to forgive people for double-clicking on it.

    3. Re:How is it activated? by kilroy_hau · · Score: 1

      Agreed until the last phrase. If you use a P2P network to copy an exe you cannot know what are you gonna get.

      But scanning a NEW worm is next to useless if you don't have the latest antivirus, which is updated after this worm has been released and infected several machines.

      --


      Kilroy was here!
    4. Re:How is it activated? by Time_Ngler · · Score: 1

      If it's aliased from exe to mp3, I don't think it would run. It would try to open it as an mp3 file then.

    5. Re:How is it activated? by bonzoesc · · Score: 3, Funny
      The Kazzzasaazaz installer connects to the FastTrack network to download the actual filesharing program (the functionality in the installer + search + spyware and ads and robot monkeys that confuse your clock cycles for bananas and eat them while throwing monkey poop all over your hard drive). Since the client itself also has built in functionality to display stuff, it would be entirely possible to exploit a buffer overflow bug or something like that that slipped through the probably non-existend QC or some such.

      But Kaszzzasdfddsafaszzza is for frat boys, sorostitutes, and pre-teen girls. Real men use FTP or DC++.

    6. Re:How is it activated? by BCoates · · Score: 1

      Yeah, looks like it's really a trojan, relies on the one-born-every-minute principle to spread.

      --
      Benjamin Coates

    7. Re:How is it activated? by Anonymous Coward · · Score: 0

      Cut slack to cheap grabass motherfuckers that refuse to pay for their music/software? You're on fucking crack.

    8. Re:How is it activated? by giberti · · Score: 1

      No but a word document with some vbs script in it might do the trick... I am sure they can get plenty of people to open a word document if titled correctly (like the simpsons example above) but you will have to forgive my lack of creativity right now.

      --

      AF-Design, web development.
    9. Re:How is it activated? by wik · · Score: 1

      You could even embed a virus inside an MP3! Winamp might even execute it in a vulnerable webbrowser for you:

      http://msgs.securepoint.com/cgi-bin/get/bugtraq0 20 4/284.html

      Remove the space that slashdot lovingly inserts in the URL.

      --
      / \
      \ / ASCII ribbon campaign for peace
      x
      / \
    10. Re:How is it activated? by amuro98 · · Score: 1

      That's the thing that confuses me as well...

      This really just sounds like a modified version of the same stupid Outlook Express virii/worms we hear about every other day. The only difference is that this one is a bit more tailored for its environment.

      How is this any different from someone sharing a virii labeled "Natalie Portman Nude.jpg.exe"?

      Considering Kazaa already lets you filter out files based on their extension, I don't see this being a problem unless you're stupid enough to believe that that copy of Photoshop you downloaded really is only 216bytes large (or even 5mb with padded junk.)

    11. Re:How is it activated? by phoenix123 · · Score: 0

      it is. read the article and you will find out for yourself.
      IT'S THAT STUPID CLICK-THE-ATTACHMENT-WHOSE-NAME-SOUNDS-INTERESTING SCHEME. NOTHING SPECIAL HERE -
      user has to click on bogus scr-file with bogus name and bogus file size.

      if one cannot distinguish any "good" file from a faked one with X
      no person here has tried to understand the virus' concept and did just comment bogus like "we don' need no filesharing we are all honest" or "music industry is to blame" and the like.
      i loaded my kazaa LiTE (only stupid people use the "real" spyware-infested original) and searched for *.scr (the extension of the virii files) and voilà X thousand hits.

      summary: the virus is NOT clever, user action IS necessary in EVERY case of infection. it closely resembles the outlook-attachment-virii-scheme, so it can only infect users that: a) ignores extension b) has its extensions still hidden in windows c) don't cares

      this virus relies on the fact that windows can RUN many more files than most people think. maybe some online-virus-scanners check exe, com, dll, doc, xls, boot-sectors, MBRs etc. files (mine (free for personal use) does include scr, btw) but of course PEOPLE do not suspect all other files to be malicious.
      windows can execute some even nastier things: LNK(!), PIF(LNK&PIF-extension is HIDDEN even when UNHIDE extension is selected. to show pif and lnk exts the use of REGEDIT can't be avoided), SCR, EXE, COM (d'oh!), HTA (html-executable/precompiled html(?)) and a lot more. but pif and lnk's are the best to hide your malicious code. even i tripped in an XYZ.jpg.pif - worm once. (shame on me) try to send someone you favorite fun-program (no virus, but looks like one maybe) and name it XYZ.jpg.pif and send it via outlook. (the victim must use outlook express prior to version 6 and the file must not exceed normal JPG file sizes or it will be too obvious.) soo and then the file arrives at the victim in his outlook, but outlook prior to version IE6 *hides* the PIF-extension of the file if you choose download/save attachment... - so everyone assumes "jpg is safe" and opens it directly. or is cautios and saves it on disk and opens it from there. but even then the .pif is hidden, the only thing the person can spot then is the "MS-DOS"-like symbol of the well known jpg-file...

      don't execute anything you download.
      have your always-on virus scanner scan all files if in doubt. yes that will cost performance. but reinstall is a lot more time and you guys probably won't notice any lag on that ATA-133 hd's anyway.

    12. Re:How is it activated? by Anonymous Coward · · Score: 0

      well, there is one occurence where i download a *.mpg files in kazaa. it is a porn cartoon. it is nice. anyway, *ehem*, at the middle of the video stream, it can trigger a internet explorer and directed it to their web site where i'm suppose to get FREE PASSWORD FOR THEIR PORN SITES.
      yes. it is scary. if it can trigger the IE, it can also trigger something else.

    13. Re:How is it activated? by hazyshadeofwinter · · Score: 1

      "Hot Sexxxxy Lezbo Pr0n Movie - SELF EXTRACTING.mpg.exe" I don't use Kazaa, but I see a *lot* of titles like that on gnutella, usually with filenames long enough the actual extension would be well hidden. And Windows/Mac users are usually pretty well conditioned to click on the file, rather than run a movie player and go file/open.

      --
      Click here if you just like to click on shit.
    14. Re:How is it activated? by ardfarkle · · Score: 1

      Well, I have first hand experience with this worm/bot and can tell you it does some weird things, but it relatively benign and easy to remove.

      One of my clients got it on the 18th, and after trying to find out why their server was going crazy for several hours, they finally called me at about 3am on the 19th. It only took a few minutes to find since 'explorer.scr' sits at, or close to, the top of the task list sorted by CPU utilization. But the part that I found interesting was the distribution system. Not only is it your system that distributes it, but the person receiving the worm actually chose to do so from your computer. In addition, the ~2000 internal filenames allows the worm to appeal to a broad range of victims while allowing it to merely produce variable sized copies of itself with new names on the source drive. This is then forced to be shared by Kazaa.

      Although there have been those whose have suggested this might be an RIAA plot, it doesn't target audio files such as .mp3, although considering the way it processes filename strings, I'm surprised the author did not figure out how to do so. It would be a simple task to create a file with a apparent .mp3 extension that would execute like a .exe or .scr file. And no, this worm has nothing to do with the adware included with the full verses Lite version. The both are subject to this worm. My client was running Kazaa-Lite.

      Originally it was falsely unidentified as 'TROJ_FILLHDD.A' and 'GT Bot (Global Threat)' due to the 'explorer.scr' filename, but the operation was considerably different. It was brand new, and was not properly identified by virus scanners for this reason. My client who got it runs the Corporate version of Symantec's virus protection, but it just didn't know about it. To this date the new defs do not fully protect against this worm IMO (updated 25 min ago and tested on a closed system).

      One of their employees decided it would be a good idea to install Kazaa on one of the servers (yes, I have now tightened up the group policy so they can't do this again), and the rest is history. Needless to say, he's not in the good graces of his employer right now.

      Although this was originally designed to be a method of distributing advertisements (and a damned stupid one at that. Wow, you just gave me a worm and filled by drive with shit. Sure, I'll buy your product (porn or not)!), I think it may now do a bit more.

      I have found that it does not just contact 209.182.61.132 (xww.de), but also contacts 66.218.71.113:0 (w2.rc.scd.yahoo.com), each time it is loaded. It also contacts various other IP numbers (one specific IP# per run) that might be stored internally. Here are a few I have sniffed besides the two above:

      64.239.122.20 (ns1.macrohost.de [Dialtone Internet])
      63.209.70.227 (an unknown address at Level3.net)
      217.69.237.132 (an unknown address at PIXELHIT1-NET [Poland])

      Anyway, it doesn't do much/any damage unless it cause your system to crash from too little space left on the system drive, and it's easy to completely remove, but currently it needs to be manually removed. For one, Symantec Anti-Virus 2002 and the Corporate version will not remove the registry entries or stop the running process. If you have it, or know someone who does, take a look at:

      How it works:
      http://groups.google.com/groups?hl=en&lr=& frame=ri ght&rnum=11&thl=1066366998,1066307103,1066303080,1 066150858,1066138013,1066056211,1065940874,1065917 702,1065701808,1065699348,1065574296,1065568930&se ekm=38c0e426.0205170649.873ce8%40posting.google.co m#link20

      Removal:
      http://groups.google.com/groups?hl=en& lr=&frame=ri ght&rnum=31&thl=1022186493,1022097445,0&seekm=2868 c408.0205220308.674ac3f1%40posting.google.com#link 31

      John - ard@d30.info

  17. Clever RIAA Creation by BlueFall · · Score: 2, Insightful

    Is this a clever RIAA creation?

    What an incredibly irresponsible statement. Don't go pointing fingers until you have some evidence.

    1. Re:Clever RIAA Creation by Aexia · · Score: 4, Interesting

      Yes, quite irresponsible. After all, when has the RIAA ever done anything malicious to innocent computer users' systems?

    2. Re:Clever RIAA Creation by Thud457 · · Score: 0

      Yeah, but they're only Mac users. They deserve to be abused.

      (The whole point being is that Macs are what Hollywood thinks computers look like, so they go after the target they recognize. Leaving those of us with real computers clean and free.)

      --

      the preceding comment is my own and in no way reflects the opinion of the Joint Chiefs of Staff

    3. Re:Clever RIAA Creation by Anonymous Coward · · Score: 0

      What an incredibly irresponsible statement.

      Actually, that funny little squiggly-looking thing after the word "creation" is called a "question mark"-- and it has the power to make the group of words before it into a question, not a statement.

      Examples:
      Question: "Are you a dunce, for not being able to tell the difference between a question and a statement?"
      Statement: "You are a dunce, for not being able to tell the difference between a question and a statement."

    4. Re:Clever RIAA Creation by ocbwilg · · Score: 1

      What an incredibly irresponsible statement. Don't go pointing fingers until you have some evidence.

      It wasn't a statement, it was a question. Don't go pointing fingers until you know the difference.

    5. Re:Clever RIAA Creation by Mordanthanus · · Score: 1

      I wonder though, has anyone considered that the creator might be from MusicCity (Morpheus) or a supporter?? They did get screwed a few months ago...

      --
      User logging on... 300 baud... 300 BAUD?!? (Click!) NO CARRIER
  18. BBC -- RIAA responsible by hether · · Score: 3, Interesting

    The BBC reported this earlier today:
    http://news.bbc.co.uk/hi/english/sci/tech/newsid_1 998000/1998686.stm

    I agree with the idea that the RIAA would definitely have motive when it came to a worm like this, or some random RIAA suporter. Good thing most intelligent people quit using Kazaa a long time ago, or for sure when they found out about the spyware.

    --

    Most people would die sooner than think; in fact, they do.
  19. The money trail.... by Mhrmnhrm · · Score: 3, Insightful

    Doesn't necessarily point to the culprit. Just because the webserver is hitting/serving up whatever the ad of the hour is, doesn't mean the person getting the checks is the virus writer. How difficult would it be for instance, for a blackhat to write a virus, have it hit/serve a bazillion ads, but send the money to a certain John Ashcroft, who just happens to live in DC, with a job at the DOJ? Especially given the talents of a true blackhat, this wouldn't be difficult at all. Unfortunately, that's what these posts of "Follow the money trail" are doing... it's entirely possible the writer borked up bigtime, but more likely that someone's being made a stooge, and that the money is just a red herring.

    --
    I suspect that one of these choices is incorrect. Correct.
    1. Re:The money trail.... by MoneyT · · Score: 2

      Given the average intelligence of an American citizen (fairly low seeing as how the NY Times is supposedly written at an 8th grade reading level) and the average intelligence of many people, I would be willing to bet that the money trail does at some point lead to the virus creator. And even if it doesn't, I would still be willing to be there is a trail back to the virus writer.

      --
      T Money
      World Domination with a plastic spoon since 1984
    2. Re:The money trail.... by VisMono · · Score: 1

      Actually, those who resort to base generalizations like yours would be a better candidate for a lower IQ.

      --
      'There is great chaos under heaven, and the situation is excellent.'
    3. Re:The money trail.... by MoneyT · · Score: 2

      Base generalizations are only dangerous if they are false. However, common sense is very lacking in this world. If you need any proof, you need not look any further than the warning lables on common household products such as a hair dryer (Do not use while sleeping or Do not use while showering) or on packages of peanuts (may contain nuts). Also, you might want to reconsider your position in society if you took offence to my previous statement and assumed it applied to you.

      --
      T Money
      World Domination with a plastic spoon since 1984
  20. Easy to catch the creators? by tekBuddha · · Score: 2, Interesting
    From the article:

    "In addition to eating up free disk space Benjamin takes additional actions: under the name of the infected computer's owner it opens an anonymous web site from which it displays advertising banners. This way Benjamin's creator profits by the resulting increase in advertising displays."

    Wouldn't it make sense then that you could track the creators of the worm to whomever is collecting the payout of these banner ads or am I misunderstanding how its working?

    1. Re:Easy to catch the creators? by Anonymous Coward · · Score: 0

      I would hope that the money is going to some offshore account. Or, I hope this person is good at money laundering.

  21. And this surprises anyone... Why? by wowbagger · · Score: 2

    Perhaps I am paranoid, perhaps I am an old fart, but I cannot see trusting any file I got from any of the P2P systems for precisely this reason.

  22. Using P2P by tswinzig · · Score: 3, Interesting

    Big whoop. P2P becomes the latest transport mechanism for viruses. It's not exploiting a hole in Kazaa, it's just sharing a folder with virus-infected executables labeled with intriguing names that are likely to be downloaded by Kazaa users.

    If these users are then dumb enough to run an executable file they download from an unknown source, they will be infected.

    Wow.

    --

    "And like that ... he's gone."
  23. Re:BBC // RIAA responsible by Anonymous Coward · · Score: 0

    I should have been more clear. I didn't mean to indicate the BBC thought the RIAA was responsible. Just that my post was about both.

  24. Requires user intervention by ZiGGyKAoS · · Score: 1

    awww this requiers that the user download and run it in order for it to infect the computer.

    One of these days there is going to be a serious flash worm on that fasttrack network. All one would have to do is find a buffer overflow in the server portion of it. Each computer knows about several others as a function of the program so finding exploitable hosts should be as trivial as doing a netstat -a.

  25. Infected? by rkent · · Score: 5, Interesting

    Okay, so... who's infected? any slashdotters get the

    "Error:
    Access error #03A:94574: Invalid pointer operation
    File possibly corrupted."

    message yet? If so, what did you do to clean up? Neither of the 2 articles gives a very good indication of that; I guess I'd start by deleting \windows\system32\explorer.scr and \windows\temp\Sys32, and removing these registry keys:

    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Cu rr entVersion\Run]
    "System-Service"="C:\\WINDOWS\\SYSTEM\\EXPLORER. SC R"

    [HKEY_LOCAL_MACHINE\Software\Microsoft] "syscod"="0065D7DB20008306B6A1"

    Seems like that should keep it from spreading, but that won't prevent a reinfection. Oh well; at least there's a popup notice when you get infected. that's nice.

    Looks like fasttrack users (kazaa, morpheus, AND grokster) are catching on... about 1/5 as many users on as usual for this time of day. And before you flame me as a pirate, I only trade Simpsons episodes which aren't available for sale yet :)

    1. Re:Infected? by Anonymous Coward · · Score: 0

      Excuse me, but how does the fact that you "only trade episodes that aren't available for sale yet" make you not a pirate? Is it only piracy if you rip copyrighted material that has made its way to DVD?

      "No, officer, see, I wasn't speeding. This is the 2003 model of this car, so it's not speeding until January first."

    2. Re:Infected? by Anonymous Coward · · Score: 0

      And before you flame me as a pirate, I only trade Simpsons episodes which aren't available for sale yet :)

      How does the Simpons make it exempt? You're still breaking the law - just because its not for sale doesn't mean you have the right to download it and play it.

    3. Re:Infected? by rkent · · Score: 1

      Is it only piracy if you rip copyrighted material that has made its way to DVD?

      Well... sort of. As far as I'm concerned. I used to tape the reruns off TV, is that piracy, too? All I'm doing is filling holes in my collection. I already bought the season 1 DVDs, and will most likely get season 2 as soon as it comes out.

      If you think that a 40 or 50M mpeg is anything like a replacement for DVD-quality audio and video (and therefore an excuse to not buy the DVD), you must not have watched one.

    4. Re:Infected? by Anonymous Coward · · Score: 0

      I'm not saying these crappy-bitrate-from-crappy-signal is nearly the same as DVD quality, but all the same it's breaking the law. If you recorded it yourself for your own use, sure, no problem. But just because you could have and didn't doesn't give you the right to 'round out your collection' from other people's collections, or to help other people with the same.

    5. Re:Infected? by ibis · · Score: 1

      format c:

    6. Re:Infected? by Gentle+Troll · · Score: 1

      I got it myself (first virus in nearly ten years). I dit what you said except that instead of removing Explorer.scr, I opened it with a text editor and removed a big chunk of it. I hope it will not be reinfected since the file is already there! Of course I will drop Kazaa anyway after this.... Thanks a lot, It stopped the nasty worm!

    7. Re:Infected? by Anonymous Coward · · Score: 0

      Oh piss off.

      Like you've never broken any laws.

      FUCKING HYPOCRITES!

    8. Re:Infected? by dogbowl · · Score: 1

      So then what if I recorded it for my own use, and then let my buddy Duane borrow it? Is that illegal?

      What if then Duane made a VHS copy for himself? Is that illegal?

      The answer is no and no, if you're wondering. It sounds to me like you've been brainwashed by 'the man'.
      How does changing mediums suddenly make something illegal?

      --

      These pretzels are making me thirsty.
    9. Re:Infected? by Evangelion · · Score: 2, Interesting


      Haven't you ever heard of Anime fansubs?

      People would copy japanese LD's, subtitle them themselves, and sell them (not for much, but still), and no one found anything wrong with this -- because the episodes/movies/oavs were not available in any english language format. The copyright owners usually never said a word. The fansubbers would respectfully, not distribute something that was available in english in north america.

      Your whining is reactionary and unessecary.

      That's what I get for coming back to slashdot, I guess...

    10. Re:Infected? by Anonymous Coward · · Score: 0

      come back? it isn't is if you ever left, looking at your continual stream of 1 rated, boring comments.

      cheers,

      your mother.

  26. whats the difference by lazelank · · Score: 1

    so this worm jumps onto your computer and puts ad software on it so you will have to wade through a million adds to read /. is this any different from kazaa already? o wait, you agreed to let kazaa do that when you clicked i agree after the eula.

    meh

  27. These poor script kiddies by Henry+V+.009 · · Score: 4, Insightful

    Whenever I think of what could be achieved by a virus using a P2P system, I am all the more astounded by the limited imaginations of these puny 13-year-old hackers.

    How about using a million computers working in parallel to break an weak encryption and read some third world govenment's military email?

    What about creating a secondary virus that uses known windows vulnerabilities and has a mathematically reasonable replication scheme to install itself on hundreds of millions more computers, and then use that to bring down the entire internet on a given day?

    What about turning these people's P2P servers into a humungous free proxy network, defeating internet censorship attempts of evil totalitarian regimes (like China)?

    1. Re:These poor script kiddies by Anonymous Coward · · Score: 0

      Because the possiblity is that you might get caught.. there is always that possibility, so you do something annoying; just to piss people off and stay anonymous. If you do get caught the charges won't be lowering the GDP of some third world country but just vandalism and some community service.

    2. Re:These poor script kiddies by Arakonfap · · Score: 1

      I agree completely!

      It's always the same dumb worm/virus. Replication is the only real goal - no distributed computing, no political vendeta, not even maliciousness (which I'm thankful for, even though I needn't worry of infection).

      This one has the popup ad thing, but my guess is the money is going to a randomly selected target.

      This reminds me a lot of that viri/worm on the gnutella network a year+ back.

    3. Re:These poor script kiddies by Anonymous Coward · · Score: 0

      Woa, woa. After reading through your post, I'm amazed by the imaginations of puny 13-year old hackers.

    4. Re:These poor script kiddies by gad_zuki! · · Score: 4, Funny

      Those are coded so well that they don't get noticed. Your PC is probably rendering 3D storyboards for Pixar and helping Japan simulate a-bomb explosions. Thankfully, everyone blames the lag on Microsoft products.

      Occasionally the cabal writes 'press viruses' like these to keep Kaspersky busy.

    5. Re:These poor script kiddies by JanusFury · · Score: 2

      You bastard! We said we'd let you leave the cabal if you promised not to give away our secrets!

      You'll pay for this, oh will you pay. We'll see who's laughing when you get arrested and strip-searched by the CIA for stealing secret government documents and hiding them in your anal cavity!

      --
      using namespace slashdot;
      troll::post();
  28. Malware by Anonymous Coward · · Score: 0

    Sic Semper Malware

  29. Bad Business by Tazzy531 · · Score: 2

    Ever since the whole deal with Kazaa and spyware and using your computer for distibuted computing, I've uninstalled and left them for good. Come on...think about it. If a company does not have the "consumer's" best interests in mind, it will not be able to succeed. What are they going to do when there is a major security issue that opens up your private data to the world? "Ooops..who cares..not my fault..they aren't paying us"

    Kazaa has turned into bad news waiting to happen.

    --


    _______________________________
    "I'm not Conceited...I'm just a realist..."
  30. Kazaa Lite? by flatt · · Score: 1

    Anyone know how this thing is spread and if Kazaa Lite can get it even with the Brilliant Digital stuff disabled?

    1. Re:Kazaa Lite? by kilroy_hau · · Score: 1

      Read the article. this is a trojan thath you download from the Kazaa Network (so kazaa lite is vulnerable too) But you have to download it and then execute it.

      --


      Kilroy was here!
  31. Advertising? by jfengel · · Score: 3, Informative

    According to the article, the worm sets up a web site for doing advertising, presumably porn. I'd think that that the sites being advertised would be a good place to start figuring out who's responsible.

    It's an amusing idea to use a worm to carry a proft-generating payload, but it sounds like it'll leave a really big paper trail. The more advertisers you get, the bigger the trail.

  32. riaa by mosch · · Score: 4, Funny
    Is this a clever RIAA creation...
    I mean you no disrespect, but you're a fucking retard.

    "hey guys, I've got a great idea. let's make a virus that will expose ourselves to billions of dollars of liability, but will only shut down some minor piracy for a day or two, until anti-virus software makers have protection for it".

    1. Re:riaa by Anonymous Coward · · Score: 0
      "hey guys, I've got a great idea. let's make a virus that will expose ourselves to billions of dollars of liability, but will only shut down some minor piracy for a day or two, until anti-virus software makers have protection for it".
      Since they have demonstrated that they own the most of the legislative and enough of the judicial branches of the Federal government, why do you think would this sound like a bad idea to them?
    2. Re:riaa by UnknownQ · · Score: 1
      "let's make a virus that will expose ourselves to billions of dollars of liability"

      But only if they get caught, and viruses can destroy the reputation of the file sharing software so they are causing much more trouble then "shut[ing] down some minor piracy for a day or two". If they are the ones doing it, that is...
      --
      Wherever you go, there you are!
    3. Re:riaa by Man+of+E · · Score: 3, Interesting
      "let's make a virus that will expose ourselves to billions of dollars of liability, but will only shut down some minor piracy for a day or two, until anti-virus software makers have protection for it"

      Seems like a pretty good idea to me, actually, especially when you consider how many idiots are on Kazaa. Since the program has no built-in calls to antivirus software, they'll become infected and lose confidence. A smaller percentage of geeks with huge bandwidth, hard drives and the brains to use antivirus software will stay on, but Kazaa will leave a sour taste in Joe Sixpack's mouth and lead him back to the golden path of CD-buying.

      Now suppose the advertising "paper trail" that everyone is talking about leads to some random hacker they picked as a scapegoat, and it's unlikely that anyone will suspect they're behind it all. Liability, schmiability.

      Okay, time to take the tinfoil hat back off :-)

      --
      Ceci n'est pas une sig
    4. Re:riaa by VivianC · · Score: 3, Informative

      You must be right. The RIAA has no history of messing up peoples computers.

      And how do you think all the kazza "pirates" are going to recoup money for not getting the files they were intending to steal?

      --
      Viv

      Gmail invites for ip
    5. Re:riaa by I+Want+GNU! · · Score: 3, Interesting

      Actually, this is EXACTLY the kind of tactics they like to use. Have you seen this article? They tried to get a law passed to hack someone's PC.

      Cigarette companies kill millions of their own customers, Enron executives steal everyone's requirement accounts, and mostly these type of companies get off scot free. Not to mention all the investment advice companies with conflicts of interest, telling people to buy then selling after the price goes up, or vice versa.

      Of course, with all the lobbyists and lawyers and paper shredders, it's not like anything would come of this.

    6. Re:riaa by linzeal · · Score: 1

      Or to another p2p network with antivirus hooks.

    7. Re:riaa by Anonymous Coward · · Score: 0

      Ok, how about one or two executives get together and decide to do this. They get some funds (wouldn't need much) and hire a "Mr. Black" to go find a hacker somewhere (probably in another country) to write the virus.
      The virus writer knows only "Mr. Black". Mr. Black need not even know who the person who hired him works for.

    8. Re:riaa by beckett · · Score: 1

      meant to be humorous or funny: not serious? waggishness? facetiousness?

    9. Re:riaa by mmmk · · Score: 1

      ROFL... I don't think there will be to much of a loss on the "pirates" side.. It's not like they are selling the stuff.. it's peer to peer file SHARING not peer to peer file selling..

    10. Re:riaa by hound3000 · · Score: 1
      "hey guys, I've got a great idea. let's make a virus that will expose ourselves to billions of dollars of liability, but will only shut down some minor piracy for a day or two, until anti-virus software makers have protection for it".


      I work for a company that sends me out to people's houses to fix their computers. And this is what I hear...

      What, I thought I had an Anti-Virus on there... What do you mean I have to keep it updated? Why is that? Why do people make viruses anyways?

      I'm still running into Nimba and SirCam out here.
    11. Re:riaa by btellier · · Score: 2

      Really? I could've sworn that the tobacco industry was forced to pay out billions in damages and Enron is in financial ruin. I believe one of their execs commited suicide as well. Not exactly scot free.

      The point is that they tried to PASS A LAW to hack someone's PC. It didn't go through and they didn't hack anyone. They're not going to create a malicious virus that has reprecussions based on legal precedent and risk having to pay out billions in damages just so a few losers get their hard drives filled up.

      Take off your tinfoil hat and think.

    12. Re:riaa by showboat · · Score: 1

      "requirement accounts?"

      If you knew what was going on, Enron set up false partnerships to hide debt from the company's books. The loss of RETIREment accounts was nearly enevitable, however quasi-legal.

      But, these people are all idiots, so who care what some bored it guy in the basement unleashes? The only sufferers will be more idiots, the majority of which run the universe and everything, so total anarchy will erupt.

      Isn't that what many of you young tuxters are about? (In the sense that linux is a reaction to windows for many, while it's a legitamate way of life to anybody with a brain -- seek the analogy.)

    13. Re:riaa by greenrd · · Score: 1
      Since the program has no built-in calls to antivirus software

      Uh, this lame virus is actually an ordinary exe file. So any decent antivirus program should be able to stop it, given an updated pattern file. No hooks needed into Kazaa, unless it launches exe files in a very weird way.

    14. Re:riaa by terrymr · · Score: 2

      You forget the RIAA lobbying to be released from liability for damage caused (by them deliberately) to people's computer systems when the terrorism bill was passing through congress. Even though their amendment was defeated they said they already had the legal right to do this from other statutes passed by congress.

  33. Re:BBC -- RIAA responsible by jacoplane · · Score: 2

    I don't see the RIAA mentioned at all in that article. Perhaps your link is incorrect?

  34. Cant beat them in court, stamp them out by nurb432 · · Score: 1

    Seems pretty clear to me.. Its either the RIAA fighting back the only way they can, or a sympathizer..

    Either way same result, people with nothing better to do, then mess with others.

    And no i dont want to get into legality discussions.. its just a statment that people should mind their own damned business.

    --
    ---- Booth was a patriot ----
    1. Re:Cant beat them in court, stamp them out by Anonymous Coward · · Score: 0
      Its either the RIAA fighting back the only way they can, or a sympathizer..

      Or is it just some retard trying to get attention ?
      To think that all virii makers have an agenda of some sort is really over estimating some of these guys' intellectual abilities.

      As it was posted above, why can't they think of something either useful (at least to some persons, like bypassing government-controlled proxies) or that could really be destructive ?
  35. Cons-piracy theory by Kirby-meister · · Score: 4, Interesting
    A lot of people will probably put this on the RIAA/other copyright crusaders, but I see P2P networks as a huge market for propogating virii and sending people trojans.

    Large file-sharing networks like Kazaa have birthmarks in the shapes of bulls-eye's.

    1. Re:Cons-piracy theory by VisMono · · Score: 1

      THE REVENGE OF MORPHUES!!

      --
      'There is great chaos under heaven, and the situation is excellent.'
  36. For fear of stating the obvious... by Restil · · Score: 5, Interesting

    But if banner ads which will profit the creator of the virus are posted on every single infected computer... how hard would it be really to follow the money to find the author of the worm?

    Or was I the first one to read the article? :)

    -Restil

    --
    Play with my webcams and lights here
    1. Re:For fear of stating the obvious... by amuro98 · · Score: 1

      Why does everyone assume that the owner of the website or whoever is getting the money from the advertising is the author?

      If the worm opened up Playboy.com, would you be crying for Hugh Hefner to be arrested for writing the worm?

    2. Re:For fear of stating the obvious... by MattCohn.com · · Score: 0

      How many millions of people can post that exact same comment before the mod points shift from informative/insitefull to redundent?

  37. I don't give a sh*t about karma. This is BIG NEWS. by Artifice_Eternity · · Score: 1, Offtopic

    Sorry your story got rejected and you don't get any karma, but please. Enough with the ragging on people because they talk about other stuff besides your pet topic.

    This is not the first time I (or people I know) have submitted matters of major general interest that have been ignored. I'm not a biologist or paleontologist, so it's not my "pet topic," but I'm smart enough to recognize that Gould was a genius and a major figure in the history of science.

    Apparently you, like the nameless /. editor who rejected the story, are not.

  38. virus? by bilbobuggins · · Score: 5, Funny
    it seems to be bringing unsuspecting users machines to a crawl with full hard drives and clogging up the Fasttrack network with massive amounts of traffic

    i had this virus once, only i named it 'roommate'.

    1. Re:virus? by Kynde · · Score: 1

      >>it seems to be bringing unsuspecting users machines to a crawl with full hard drives and clogging up the Fasttrack network with massive amounts of traffic

      >i had this virus once, only i named it 'roommate'.

      My coworker is experiencing similar symptoms on his box. I think he called it XP...

      --
      1 Earth is warming, 2 It's us, 3 it's royally bad, 4 we need to take action NOW
  39. Hmm by skinfitz · · Score: 1

    I remember the topic of Kazaa infection being brought up on Bugtraq Bugtraq months ago.

  40. Yeah... by Anonymous Coward · · Score: 0

    Intelligent people switched to Kazaa Lite.

  41. Yep, Hit me. Here's what I did. by sailor420 · · Score: 5, Informative

    Hit me the other day. Just noticed it last night, and I (think) I have it under control.

    First, look out for small downloads, specifically anything with names such as "installer" or "downloader." I dont know how I got mine, but my brother's machine got hit after he tried to d/l the newest version of Britannica. Serves him right. When I went to see what he downloaded, I saw that it was a file around 700k.

    Yes, it does spread over Kazaa lite.

    Once it is installed, it proceeds to fill up your machine with approximately 700k files, usually in windows or winnt/temp/sys32. Thats where all mine were (Im running W2K).

    However, dont go crazy yet. I downloaded the newest virus update for NAV (dated 5/17) and ran it. It picked all the downloads right up. Since they were all junk files that it had downloaded, I had it delete them all.

    So far, so good. Havent had any recurrence since then (although this was last night, so I dont consider it enough time to truly test). Hopefully it really is this easy to clean up, but Im sure I will quickly find out.

    Hope this helps.

    1. Re:Yep, Hit me. Here's what I did. by stevey · · Score: 2, Insightful

      People who download .exe's from filesharing systems are kinda asking for trouble, aren't they?

    2. Re:Yep, Hit me. Here's what I did. by chad_r · · Score: 1

      Anyone know how this affects Kazaa Lite running under Wine? I have everything but E:/Program Files mounted read-only, so I figure I shouldn't worry too much. But the lights on my DSl router are unusually non-blinking; maybe their network did crash.

  42. free software innovation by tps12 · · Score: 0, Flamebait

    bringing unsuspecting users machines to a crawl with full hard drives and clogging up the Fasttrack network with massive amounts of traffic

    Sounds like Kazaa has finally caught up with Gnutella. Proof once again of OSS's superiority.

    --

    Karma: Good (despite my invention of the Karma: sig)
    1. Re:free software innovation by MoneyT · · Score: 2

      And what will you do when the code for the virus is recompiled to run in *NIX? No OS is perfectly secure, the fact that *NIX based OSes and Mac OS was not hit is just an indication of the limited programing skills and/or time of the creator.

      --
      T Money
      World Domination with a plastic spoon since 1984
    2. Re:free software innovation by Bryan+Andersen · · Score: 1
      And what will you do when the code for the virus is recompiled to run in *NIX? No OS is perfectly secure, the fact that *NIX based OSes and Mac OS was not hit is just an indication of the limited programing skills and/or time of the creator.

      Atleast under *NIX one has permitions and optional quotas. Both help greatly in keeping crap from infecting a system or causing DoS situations. As an example I'm running a news retreival program under the account news. If someone managed to exploit it they would only be able to fill up partition /data2. That is because that is the only place that the news user is allowd to create or modify files. I even have news locked out of using the main /tmp directory. If it dosen't need access something I disabled it via access control lists. I also have throttles on the maximum percentage of memory and CPU allowed.

    3. Re:free software innovation by MoneyT · · Score: 2

      Theoreticaly the same could done in a closed source system. While I see your point that there are more blockages to be avoided if you were to create a sucessful *NIX virus, that does not mean that it is any less threatening to a system. Even if it could only fill up /data2, it's still using HD resources, leading to fragmentation, longer seek times and reduced system performance. All in all a nusence rather than a serious problem, but a problem no less.

      --
      T Money
      World Domination with a plastic spoon since 1984
  43. Re:yeah, it was the RIAA by rhazes · · Score: 0, Troll

    bout time i saw shpongle on slashdot....even if it was just a sig.

  44. ...hyperlink?? by skinfitz · · Score: 2, Interesting

    ...I dont know what happened to the hyperlink there - here is the link in text form:

    http://online.securityfocus.com/archive/1/254627 /2 002-05-17/2002-05-23/1

    And another try at a hyperlink.

  45. Re:yeah, it was the RIAA by Anonymous Coward · · Score: 0

    My Linux box seems to be unaffected. Bahahahaha! Off to download some more shitznit.

  46. Virus companies need the virus makers by bigmouth_strikes · · Score: 5, Interesting
    "This event once again demonstrates the necessity to filter all incoming files for viruses, regardless of how well protected this or any other network is. Before use all data should be run through a mandatory check for virus code using the latest virus database update," commented Denis Zenkin, Kaspersky Labs Head of Corporate Communications.
    Gee, I'm so grateful for Kaspersky Labs that they provide this valuable information. They only forgot to add

    "If you refer to this article, we'll give you $5 rebate off your next virus update purchase." added Zenkin with a smile.

    As much as we need the anti-virus software, the anti-virus companies need the virus makers. Without a worm or a virus that makes CNN headlines every 6 months, people will forget to buy updates, patches etc etc. The public forgets quickly, and will not buy new products from the AV companies if they don't feel a threat.

    Sure, the problem is real, but part of me can't shake the feeling that somewhere there is a anti-virus company executive ordering a new plasma HDTV when he sees this news. Or maybe it's just becase X-Files ended yesterday that I'm seeing conspiracies everywhere.

    --
    Oh, I can't help quoting you because everything that you said rings true
    1. Re:Virus companies need the virus makers by Triskaidekaphobia · · Score: 2, Insightful

      And Doctor's "need" the influenza virus. Doesn't mean they like it.

    2. Re:Virus companies need the virus makers by Anonymous Coward · · Score: 0

      Slashdot poster's need to learn the English language.

    3. Re:Virus companies need the virus makers by Anonymous Coward · · Score: 0

      dermatoglyphics

    4. Re:Virus companies need the virus makers by Anonymous Coward · · Score: 0

      Clever boy. Have a cookie.

    5. Re:Virus companies need the virus makers by Anonymous Coward · · Score: 0

      Can't wait to get my hands on a worm I can unleash on spammers.

    6. Re:Virus companies need the virus makers by zangdesign · · Score: 2

      True. But computer viruses don't kill people.

      Yet.

      --
      To celebrate the occasion of my 1000th post, I will post no more forever on Slashdot. Goodbye.
  47. STFU troll by Anonymous Coward · · Score: 0

    no one gives a shit, that's why there is the submit news feature of slashdot, if you want to write an article about it without it being rejected go to kuro5hin.org. until then, get the fuck away you damn dirty troll

  48. Re:yeah, it was the RIAA by tempest303 · · Score: 2

    Yeah, I'm grinnin' ear to ear as well. While I don't think it was RIAA that created this, I found this part f*cking brilliant:

    Congratulations on your free copy of photoshop (which is alright because you wouldn't have bought it), Windows XP (which is alright, because Microsoft is evil), the new Dave Matthews Band CD (which is alright, because the RIAA is evil), and that DivX of episode 2 (which is alright, because the MPAA is evil).

    Couldn't have said it better. *applause*

  49. Re:yeah, it was the RIAA by tempest303 · · Score: 1

    grr. my Lameness Engine must be kicking in - i re-re-reread your post, and you obviously don't think that RIAA made the worm either.

    happypollylogies all around.

  50. Re:Irony. by grrlygeeky · · Score: 1

    Yeah, because AIDS is a purely homosexual phenomenon. It doesn't spread like wildfire through unsafe heterosexual relations in Africa. It certainly doesn't affect heterosexual drug users, people who have had blood transfusions, ordinary everyday heterosexuals whose mate had an unwise affair. I'm sure a loving god smites innocent people to "cure" the world of men who love other men, while doing nothing to wife batterers, rapists, child molesters, and other creeps. This worm may be a well deserved plague on thieves, but don't compare it to a misbegotten theory that blames a real tragedy, AIDS, on its own innocent victims.

  51. AudioGalaxy by psycht · · Score: 1

    i guess it would be under a similar assumption that this worm could target other sharing software like AudioGalaxy, imesh, limewire, etc..

    any word on the truth of this?

    1. Re:AudioGalaxy by Anonymous Coward · · Score: 0

      are you a fucking idiot, this worm only targets the fasttrack network, so it would only affect kazaa and grokster DUH

      audiogalaxy imesh and limewire all have fucking spyware

      and most run on the gnutella network

      if u want a gnutella client use limewire clean or for the fastrack if u want a virus use kazza lite but u obviously are too stupid to do this

    2. Re:AudioGalaxy by The_Unforgiven · · Score: 1

      it could easily be spread on any p2p network, as I understand it...

      The code doesn't seem to be specific to any network, it just started the spread on fasttrack.

      --
      http://wsulug.org
    3. Re:AudioGalaxy by amuro98 · · Score: 2

      So long as they allow files that can contain executable content (benjamin uses a .scr file, for instance) then, yes.

      There's nothing really special here. All they did was take Melissa, modify it a bit, then start sharing files named "naked gurlz.jpg.scr" Someone downloads it, clicks on it, and the rest is history.

  52. Funniest geed joke evar!! by Thud457 · · Score: 0

    Why can't nerds tell Halloween from Easter?

    Because 31(hex) == 29(oct)!

    --

    the preceding comment is my own and in no way reflects the opinion of the Joint Chiefs of Staff

    1. Re:Funniest geed joke evar!! by Anonymous Coward · · Score: 0

      You are pretty stupid. The joke is "Why can't nerds tell the difference between Halloween and Christmas?"

      Because 31(OCT) == 25 (DEC).

      Fucknut. Shazaaaaaam!

    2. Re:Funniest geed joke evar!! by Anonymous Coward · · Score: 0
      yhbt. hth. hand.

      YAAD

  53. Re:yeah, it was the RIAA by grung0r · · Score: 2, Insightful

    I know the RIAA didn't write it, it was proabably some self-rightous bastard alot like yourself. How can you possibly defend a company that acts the way RIAA members do? Do you think they care about you? You think all these "thives" go away that their gonna lower prices, or create good content? HA! They are using file sharing as an exuse to pass legislation that gives them a future stranglehold on content creation. "oh, you want to distrubute a song you wrote and performed? Not without the RIAA watermark seal of approval!" Stop defending companys whose soul goal is to make your computer into a nutered VCR, incapable of doing anything without the xxAA's express writen consent.

  54. Hard to tell the worm from the software by BCoates · · Score: 5, Insightful

    Hmm, uses your drive space and bandwidth, pops up ads, modifies your system configuration without your permission...

    Looks to me like the only difference between this trojan and the programs it comes in is that one has a EULA.

    Time for virus writers to wise up and disclaim liability with an incomprehensible clickthrough like all the other writers of malicious code...

    --
    Benjamin Coates

  55. Wait a minute ... by RebelWithoutAClue · · Score: 1
    This isnt a worm.

    A real worm would do something like pretend to be an update and get the host to download an infected version of the client.

    Hmm, sounds Familiar doesn't it ...

    --
    "However beautiful the strategy, you should occasionally look at the results" - Winston Churchill
  56. It would be way cool if it was the RIAA by Anonymous Coward · · Score: 0

    Imagine the possibilities...

  57. If I was... by vidnet · · Score: 0
    ...an RIAA supporting cynical bastard, I'd say they deserve it.

    They deserve it.

  58. Re:Using P2P/End Users.... by MrWinkey · · Score: 1

    Yes this is true but ALOT of end users dont know any better or arent smart enough not to or just dont care. I know they always say all the time not to do it but I still have end users trying to open virus e-mails (the virus *.exe is gone) and the dept director downloading mp3's to his machine. He stopped after that article I sent him on the internal mp3 server costing the company tons of monies. Like it matters anyways rebuilding workstations is fun.....

    --
    Vote early. Vote often. Vote CowboyNeal.
  59. MOD THE PARENT POST UP by MoneyT · · Score: 2

    And then go here to read the story with out signing up:

    http://www.majcher.com/nytview.html

    --
    T Money
    World Domination with a plastic spoon since 1984
  60. That didn't take long by theCat · · Score: 1

    Readers are reminded of this /. discussion of the matter from April 7.

    Regarding networks, it should be clear by now that if you build it they will come. Virii, that is. When are people going to figure that one out? Worse, the hosts in this case probably didn't even know they were vulnerable. Another technological trap, sprung. Really makes me look forward to the day when the networks are more homogenious than they already are.

    --
    =^..^= all your rodent are belong to us
  61. Worm Effects by OrangeHairMan · · Score: 1

    All the worm does (or all that is known) is that it opens the benjamin.xww.de web site to display an advertisement. I would guess (and love ;) that it would do more...although I wonder how much money the writer is making...

    Orange

  62. Re:JESUS MADE THE UNIVERSE by southpolesammy · · Score: 2, Funny


    Evolution is just more Yankee bullshit. Ever since reconstruction, the Yankees have been destroying the truth.

    Yet another reason to hate Steinbrenner....um, uh, oh nevermind...

    --
    Rule #1 -- Politics always trumps technology.
  63. Social Engineering by sarcast · · Score: 1

    This seems to rely heavily on the user to be able to spread itself around. At first glance when I read the story, it seemed that maybe the virus was just running rampant on the network, but on reading the actual article, I find that someone actually has to run the virus.

    Do people not understand that they are downloading files from essentially untrusted sources and should be checking these files anyways? Especially programs.

    The social engineering aspect of this virus is what really leads to its spreading, not any inherent flaw in the design of the network. As usual, humans are the weakest link here.

  64. How ironic... by PsiAngel · · Score: 1

    An opt-in virus. Heh.

  65. OT: Linux distros by P2P by hey · · Score: 1

    I did a search for some Linux .iso's and rpm's on Gnutella and didn't find much. When I downloaded them from ftp sites it took days. So I have put a bunch of rpm's and iso's Gnutella. I'll see if there are any hits. This seems like a good (non-illegal) use of P2P.

  66. If only someone would invent the... by Anonymous Coward · · Score: 0

    GSVirus!

  67. Worm by Anonymous Coward · · Score: 0

    I used Kazaa once and it stores incoming files as incomplete .dat files until they are finished, as I was dling a song I get hit by Norton antivirus saying that I had a virus in a .dat file that I haven't even finished!

  68. protection is easy... by sluggie · · Score: 4, Insightful

    Just filter out all files under 1 meg... it worked for me since I guess it only shows up when searching for software...

    1. Re:protection is easy... by thumbtack · · Score: 2

      WHAT? And give up my 56kbps MP3 files? OH MY GOD, this is even worse than I thought!

  69. Congratulations... by Anonymous Coward · · Score: 0

    Thank you. Photoshop 7 is rather nice, it's been awhile since I d/l'ed 6.01 so the upgrade was welcomed. As you state, I would not have paid that kind of $ for a program I use maybe once a month for 10 minutes.
    Listen, I've paid many, many thousands for software over the years, and still do if it's something I need or will enjoy using a lot. But, I don't mind stealing it (I'll admit it's stealing, but I won't admit it's the same as stealing durable goods--then someone else is lacking it) if it is something I would never have paid for.
    As for music, I don't mind d/l'ing a couple radio band one-hit-wonders whose album I'd never buy. I buy about 6 new CDs a year, and have about 400 CDs altogether, most of which were overpriced (yes, the music companies were found GUILTY of price-fixing, REMEMBER?). I've also bought about 40 DVDs, and d/l a couple so-so DivX releases a month. Big deal.

  70. bitchslap parent thread! by Anonymous Coward · · Score: 0

    if ever there were a time for slashdot to bitchslap a thread, it's now

  71. Re:yeah, it was the RIAA by Anonymous Coward · · Score: 0
    am i the only person on slashdot whose reaction to this a bigass grin?

    Congratulations on your free copy of photoshop (which is alright because you wouldn't have bought it), Windows XP (which is alright, because Microsoft is evil), the new Dave Matthews Band CD (which is alright, because the RIAA is evil), and that DivX of episode 2 (which is alright, because the MPAA is evil).

    I hope you all enjoy your free gift, and I hope nobody here is so fucking broken as to consider the possibility that the RIAA made this virus seriously.
    Funny, my free copies of Gimp, Linux and LaTeX, and my free Peter Welker mp3s didn't come with any of that virus stuff. I guess that's why they say free-ware just doesn't measure up to the commercial stuff.

    P.S.: [meta] I'm trolling the folks who extol proprietary software, and assume that all mp3 downloads screw the artist. [/meta]

  72. Re:of all days....doh! by Anonymous Coward · · Score: 0

    Gee, you think having a back door into a system and remote control over it might make this "worm" easier to spread?

  73. moral/legal high ground? by Anonymous Coward · · Score: 0

    It's ok for you to take a hard-line approach and say that NO filesharing of copyrighted material is justified. But also consider other laws, unrelated to this.
    Do you ever intentionally drive over the speed limit? Come on, be honest. Of course you do. So, you say "well, it's just a *little* bit over the limit", or "only when I'm really in a hurry". Well, per your legal logic, it's still illegal. "Not hurting anyone to drive 56 in a 55mpg zone" you say? Well, maybe you haven't YET, but statistically, if everyone were to speed just a little, think how many more accidents there would be per year. Is even ONE death worth getting there a few minutes sooner? No.
    So, unless you don't EVER speed EVEN A LITTLE bit over the limit, don't preach to us about NEVER downloading ANY copyrighted material.
    Yes, it's illegal to download Photoshop, but NO, I wouldn't have paid hundreds for it, and I don't require it, I just want to have it.
    Think about it.

    1. Re:moral/legal high ground? by Anonymous Coward · · Score: 0

      I suppose having 100GB of illegal mp3s and Divx is just a little illegal too...

    2. Re:moral/legal high ground? by Wakko+Warner · · Score: 2

      Yes, it's illegal to download Photoshop, but NO, I wouldn't have paid hundreds for it, and I don't require it, I just want to have it.

      I don't require a Viper RT/10, but I just want to have one, so I stole mine.

      So, unless you don't EVER speed EVEN A LITTLE bit over the limit, don't preach to us about NEVER downloading ANY copyrighted material.

      I never do. So, kindly eat a dick.

      People who attempt to justify their theft in any way are fucktards.

      - A.P.

      --
      "Remember when the U.S. had a drug problem, and then we declared a War On Drugs, and now you can't buy drugs anymore?"
    3. Re:moral/legal high ground? by SkyMunky · · Score: 1

      Riiiiiiiiight. You never speed. Never have. MmmHmm.
      People who lie about breaking the law in any way are fucktards.

      As I said, I buy plenty of software. If you could buy your Kia every 5 years and test drive a Viper now and then without diminishing it's value, I don't think you've hurt anyone.

      Also, steal viper=someone else loses it; steal photoshop when you would not have bought it=more publicity for photoshop, nobody has lost it.

      Please don't download warez. You'll slow MY download.

      You cumfelch.

    4. Re:moral/legal high ground? by Wakko+Warner · · Score: 3, Interesting

      I have never gone above the speed limit in my life -- go suck three cocks.

      How is stealing one product different from stealing any other, simply because that product comes on a CD-Rom?

      It is deluded thieving slashdroids (with shitty high UIDs) like you that are ruining the Internet. Please eat a bullet.

      - A.P.

      --
      "Remember when the U.S. had a drug problem, and then we declared a War On Drugs, and now you can't buy drugs anymore?"
    5. Re:moral/legal high ground? by Anonymous Coward · · Score: 0

      If you can't see the difference, you're as much of an idiot as most of your posts indicate.
      The difference is (again), steal a car, and now somebody else is missing it. Steal a copy of photoshop, and NOBODY gives a shit. I wasn't buying it, and I'm still not. No delusion. Fact.

      High UID? That's the best you can come up with? lol

      You're the kind of person that's ruining the internet for those of us who were using it long before the WWW came along and empowered fucks like you to believe that your self-righteous opinion is worth a damn.

    6. Re:moral/legal high ground? by Anonymous Coward · · Score: 0

      The difference is (again), steal a car, and now somebody else is missing it. Steal a copy of photoshop, and NOBODY gives a shit. I wasn't buying it, and I'm still not. No delusion. Fact.

      Try using this argument in a court of law, dickballs.

    7. Re:moral/legal high ground? by The_Unforgiven · · Score: 1

      kind of offtopic, but:

      I hear about obscure band.. say "Refused"...

      I DL a few mp3's

      I go buy CD...

      They just made money because I stole the songs....

      Now multiply this by how many bands I've found and tried by mp3, multiplied again by how many albums I bought by each...

      Damn, they made a lot of cash off my my theft, didn't they?

      --
      http://wsulug.org
    8. Re:moral/legal high ground? by shepd · · Score: 2

      >I don't require a Viper RT/10, but I just want to have one, so I stole mine.

      Interesting how you confuse piracy with larceny.

      When you pirate a movie, or music you deprive no one of that movie or music; whereas when you commit GTA you deprive someone of their vehicle.

      Since a replicator is to matter as a CD-Burner is to data, would you still consider it theft if you replicated a Viper RT/10 using your own equipment and materials?

      If so I would humbly suggest you are a tiny minority of people, and that's the reason why both the dictionary and the law disagree with you.

      My search turns up nothing for "theft", "steal", or "larceny" in the Berne Convention. Methinks you are just plain confused on the issue. Hope this clears it up for you!

      >So, kindly eat a dick.

      Not that I'd want to; But its pretty hard when its shoved so far up your ass.

      >People who attempt to justify their theft in any way are fucktards.

      Agreed, to a certain degree (Les Miserables come to mind as a particular exemption). That's why Copyright Violation is a violation of copyright law, not (AFAIK) theft.

      Or at least that wasn't the intention of the people who created our modern day copyright system.

      --
      If you could be told what you can see or read, then it follows that you could be told what to say or think - BoC
    9. Re:moral/legal high ground? by shepd · · Score: 1

      >I have never gone above the speed limit in my life -- go suck three cocks.

      Have you ever jaywalked?
      Have you ever timeshifted programming (such as NFL broadcasts) that specifically limit your right to do so?
      Have you forgotten to count your change and noticed that you're a penny richer at the end of the day?
      Have you ever broken something borrowed from a friend and told them you'd lost it?
      Have you ever written on your desk at school?
      Have you ever paid a bill a day late and not included late fees in the hopes that the company won't notice?
      Have you ever been infected by a virus?
      Do you drive your bike without a helmet?
      Do you walk your dogs without a leash?
      If not, have you ever forgotten to poop-n-scoop?
      Have you ever scratched a rental DVD or creased a rental tape without telling the manager?
      Or, are you Mother Theresa?

      Now go rim an asshole. Just cause you don't drive doesn't mean you've never broken the law.

      --
      If you could be told what you can see or read, then it follows that you could be told what to say or think - BoC
    10. Re:moral/legal high ground? by Anonymous Coward · · Score: 0

      >Try using this argument in a court of law, dickballs.

      Its called selective enforcement and has been used as a successful defence at a number of trials, cuntbreath.

    11. Re:moral/legal high ground? by Wakko+Warner · · Score: 2

      Or, are you Mother Theresa?

      Yes. I am without sin, and I am casting stones.

      Duck, motherfucker.

      - A.P.

      --
      "Remember when the U.S. had a drug problem, and then we declared a War On Drugs, and now you can't buy drugs anymore?"
    12. Re:moral/legal high ground? by Anonymous Coward · · Score: 0

      >I am without sin,
      >Duck, motherfucker.

      It seems you are not without sin.

      I've yet to meet a recognized religion that recommends public swearing.

      Does yours? What is it?

      Of course, you might have no religion, in which case you cannot speak of sin, since an understanding of sin would require an understanding of religion.

  74. Re:yeah, it was the RIAA by Anonymous Coward · · Score: 0

    Geez man the guy is not defending the RIAA in any way shape or form. He is simply implying that stealing is wrong, no matter if you judge the person evil or not.

  75. No he didn't by commodoresloat · · Score: 2

    Don't you mean Stephen King?

  76. Bad Idea! by Anonymous Coward · · Score: 0

    Umm I would not trust linux iso/rpms on P2P as much as I trust those copys of XP, any exe file, or any file for that matter. I know you already put trust into sites that offer them, but they are more trust worthy then p2p. Having said that, now the trolls are putting their 0wn3D copys up in hope that someone will actully get a broken linux iso from them.

    1. Re:Bad Idea! by Anonymous Coward · · Score: 0

      You can get MD5 checksums of the RedHat ISOs from the official site and the ISOs themselves from anywhere.

  77. Re:Using P2P/End Users.... by tswinzig · · Score: 2

    Yes this is true but ALOT of end users dont know any better or arent smart enough not to or just dont care.

    If you mean "A LOT," you are correct. (I don't know what "ALOT" is, though... is it anything like "ALITTLE?")

    I know they always say all the time not to do it but I still have end users trying to open virus e-mails

    Then if you maintain that network you need to setup a filter to delete executable attachments from incoming/outgoing email!

    --

    "And like that ... he's gone."
  78. No, no, no... by Anonymous Coward · · Score: 0

    He has to take his hard disk out of his computer...

    ...and then beat the living shit out of it with a sledgehammer.

    Problem solved. Symantec's instructions were very specific about this part - this is a very dangerous virus. IBM has sent a warning out about it today. Kaspersky labs have also found that squirrels in the immediate vicinity of an infected system can suddenly burst into flames. Understandably this has Greenpeace upset. DAMN YOU, SPACEMAN!

  79. Use Seeker! by Anonymous Coward · · Score: 0

    http://www.skyris.com/alpha.html

    no spyware, should scale (in theory) - go prove them wrong!

  80. adserver domain closed by Alan · · Score: 4, Interesting

    Hehehe, if you hit the page that the virus opens to get the author more page impressions (http://benjamin.xww.de/), you get:

    "
    Domain aufgrund von massiven Beschwerden gesperrt.
    Domain closed due to massive abuse.
    "

    Now I wonder if it was closed because someone wrote a virus, or because the virus worked so well he went over his bandwidth allocation! :)

  81. Use Seeker! by Anonymous Coward · · Score: 0

    New p2p network using a new secret architecture they claim will scale. No supernodes - whole new idea. Prove them wrong.

    no spyware
    no spyware
    no spyware

    check it out at:
    http://www.skyris.com/alpha.html

  82. Re:sabotage.....bad..... by Anonymous Coward · · Score: 0

    You say hypocrite I say fuckin-monkeys using guns get what they deserve. Now if this was an attack for knives or forks [or spoons or sporks] I would have a different position. Knives/forks for instance have far more legitimate uses than guns.

    I mean when is the last time you shot someone with a knife? Or reloaded a fork?

  83. Worm? or Trojan? by GrenDel+Fuego · · Score: 0, Redundant

    They're calling it a worm, but dosen't a worm need to propogate itself?

    This is making itself available for unsuspecting people to help it spread. This seems more like a trojan to me.

  84. Re:I don't give a sh*t about karma. This is BIG NE by Anonymous Coward · · Score: 0

    Who gives a rats ass, start your OWN news site. Be your own Anonymous Editor and censor what you want, christ.

  85. Use Seeker! by Anonymous Coward · · Score: 0

    the new Seeker always shows you the filename, never executes anything without the user explicity requesting such an act. No spyware, great new network architecture. Check it out at:

    http://www.skyris.com/alpha.html

    the next generation of file publishing

  86. Re:BBC -- RIAA responsible by bricriu · · Score: 2

    I never used Kazaa... but I (used to) highly recommend KazaaLite. All of the functionality, none of the spyware. Oh well, back to my from-source LimeWire v1.6b.

    --

    AHHHHHHH! I'm burning with goodness again!
    - Reakk, Sluggy Freelance

  87. Oh NO! by Anonymous Coward · · Score: 0

    My temp files are full of 1k files!

    What will I do?

    Oh, they are all cookies, forget it...

  88. Re:Overhyped? -offtopic by dario_moreno · · Score: 1

    about your drug dealer method : I remember
    a video game arcade opening next to my school.
    Since it was 1994, having not seen this in 10
    years, we were very excited and promptly went there. There was a staff of three to five
    people, one MK2 machine, two pinballs hardly
    playable (one leg shorter than the other)...
    and that's all. Last time I drove by : it
    was still there, when major arcades (with one
    70 years old employee) close their doors long ago.
    Obvious money-laundering business to me
    (it is very hard to check the actual number
    of coins going through the machines).

    Same thing for a videoclub next to my university...which lasted about three weeks !
    Maybe they were not as careful, or did
    not bribe the correct people.

    --
    Google passes Turing test : see my journal
  89. Could someone enlighten me? by Lazyhound · · Score: 1
    In addition to eating up free disk space Benjamin takes additional actions: under the name of the infected computer's owner it opens an anonymous web site from which it displays advertising banners. This way Benjamin's creator profits by the resulting increase in advertising displays.

    OK, so how and where does the virus open these websites? And what can an infected user do about them?

    1. Re:Could someone enlighten me? by Lazyhound · · Score: 1

      Never mind, I get it. Oddly enough, I didn't get the error message, or the website pop-up. It must have been my security settings. In hindsight, this would explain why I got an "Allow Script?" dialog when there were no IE windows open...

  90. Kaspersky.com by mjbou · · Score: 0, Offtopic

    I have just been sent an email, I got it in Kmail on linux, - I've been sent a few virus emails lately, so far been imune to email infection by using linux + mozilla for certain attachments, to get all my mail.
    this seems to be from comcast.com
    jkastrati from Kaspersky with a W32.Elkern removal tool install.exe an odd "Attachment: 2" and a .htm which I opened with konqueror - bullshit USA property so I suspect install.exe is a virus

    Kaspersky sell Linux antivirus

    I use nabou, and fairly tihgt Mndrake Security, plus Bastille and portsentry - which plays me a few bars of Little Feat when I get scanned or port connection attempt.

  91. Re:yeah, it was the RIAA by Anonymous Coward · · Score: 0

    If you bothered to actually read his post, you'd see he's not defending the RIAA/MPAA in any way. He's just laughing at all the punks who think it's okay to infringe copyrights because they think that the RIAA/MPAA/MS is "evil".

    BTW, copyright infringement was illegal LONG before the DMCA.

  92. Been posted already by Anonymous Coward · · Score: 0

    http://slashdot.org/articles/02/05/20/2223200.shtm l?tid=134

  93. hmmm by idontneedanickname · · Score: 1

    does this also apply to the kazaaLITE? *quickly shuts down a program*-- it wasn't kazaalite! i swear!!

  94. You are a Troll by Anonymous Coward · · Score: 0

    indeed, don't take out your angst here.

  95. Re:yeah, it was the RIAA by Anonymous Coward · · Score: 0

    When unlicensed music is outlawed...

    Only outlaws will make unlicensed music!

  96. Guess it's kinda like AIDS . . . by Anonymous Coward · · Score: 0

    You start screwing around with the wrong stuff and you get a bad bug.

    Oh, but I use P2P to help people and share things legally!! Yeah right.

    Just desserts for pornos and pirates, I say.

    --$0.02

  97. Never dload something executable off of P2P by groberts65 · · Score: 1

    I am shocked it's taken someone this long to do this. All it takes it for someone to drop a file called something like CrackedPhotoshop7Installer.exe which removes every file on your hard drive into their Kazaa folder to cause "mass hysteria , dogs and cats sleeping together".

    The lesson: never, ever download something executable off of a public P2P network like Kazaa, Gnutella, etc.

    1. Re:Never dload something executable off of P2P by greenrd · · Score: 1
      Or even worse:

      Email a random mpeg from your downloads directory to all your addressbook, then corrupt (not delete) all your data files, while alternating between displaying an unclosable window with goatse.cx and a satanic picture with "your computer has been possessed" overlayed on it. And, for the icing on the cake, "upgrade" your BIOS and/or CPU microcode so that your machine is unbootable.

      That should have the desired effect quite nicely.

      Oops, I'm a terrorist now!

    2. Re:Never dload something executable off of P2P by kraf · · Score: 2, Insightful

      > The lesson: never, ever download something executable off of a public P2P network like Kazaa, Gnutella, etc.

      Don't forget, gnutella runs on non-braindead platforms too.

    3. Re:Never dload something executable off of P2P by EpsCylonB · · Score: 1

      If it really fucked up your computer it would spread very far would it ?.

    4. Re:Never dload something executable off of P2P by Anonymous Coward · · Score: 0

      Ssh.. this is Slashdot.. don't use your brain.

  98. Warhol Worm by Frogg · · Score: 1

    I'd not read about the Warhol Worm before: that's one hell of a bunch truly evil ideas!!

    If I had mod points today, you'd get +1 from me coz that's the most fascinating article on any kind of worm (theoretical or otherwise) that I've ever read (heers for the link!)

    ..what next? A Lord Vader Worm?

  99. +1 funny by Anonymous Coward · · Score: 0

    Well I thought it was funny man!

  100. Close Call for Me by doublem · · Score: 2

    Today was the first time in weeks I hadn't left my work computer on overnight downloading the latest and greatest 80's MP3s and Star Trek Enterprise AVIs. Tonight it is powered down. Such timing!

    --
    "Live Free or Die." Don't like it? Then keep out of the USA
  101. Obligatory Nelson Reference by lkaos · · Score: 1, Offtopic

    * pointing at all the half-wit, Windoze using, Kazaamazoo users

    HA HA!

    * pointing at script kiddie who was too stupid to put a TTL on his worm and therefore, max'd out the bandwidth on his site (along with drawing a whole bunch of attention to himself)

    HA HA!

    --
    int func(int a);
    func((b += 3, b));
  102. Yeah he did, bitch! by Anonymous Coward · · Score: 0

    hahahaha you be wrong, you low user id number nigga.

    Gould be DEAD, BITCH!

  103. It looks to be a screensaver script file by Anonymous Coward · · Score: 0

    Looks like my little brother installed this when he thought he was downloading Star Wars.

    It creates dummy files for each search term with a .scr extension.

    ex: User searches for "Metallica - Enter Sandman" it creates a ~500KB file called Metallica - Enter Sandman.scr containing the worm

    Because of all the searches on the network you can imagine how fast a hard drive can be filled with these dummy files.

    Turning off Kazaa will make the worm stop creating the files.

  104. access denied? by incom · · Score: 1

    If the infected files/directories won't delete restart and delete them in safe mode.

    --
    True genius is grasping a situation like a peice of fruit, and peircing it just right so that it drains dry.
  105. Re:doesn't affect the giFT network! by Anonymous Coward · · Score: 0

    gift.sourceforge.net

  106. Found 'em! by _ph1ux_ · · Score: 3, Funny

    Pay to the order of : Hilary Rosen.

  107. 216 KB? by kubrick · · Score: 2

    Benjamin is written in Borland Delphi and is approximately 216 Kb in size.

    Bah, virus writers these days.... in my day that virus would have been written in carefully hand-tooled assembly, it would have been polymorphic and it would have been no larger than 5KB. Uphill both ways, etc. etc..... [mutter grumble grumble]

    --
    deus does not exist but if he does
  108. I just saw that in FUDD when I read it: by _ph1ux_ · · Score: 3, Insightful

    "Some wery scawy weseawch has been aimed at discobewing just how fast a worm could infect the entiwe Intewnet"

  109. Mmmquotas by Bastian · · Score: 2

    I had that problem, too, so I had to give my roommate's account on my computer a disk quota. . .

    What I really don't get was the way he would download piles of shit that he didn't even like, like boy bands.

    1. Re:Mmmquotas by jred · · Score: 1

      Maybe he just *pretended* not to like them. Suppose it's possible he lived a hidden life, boybands and all? Hmmm.

      :)

      --

      jred
      I'm not a mechanic but I play one in my garage...
  110. Conspiracy theory: morpheus? by seldolivaw · · Score: 2

    Given the dodgy tactics KaZaA used to grab market share from Morpheus (by shutting them out of the network) and how pissed off Morpheus was at them for doing that, I'm surprised no one has fingered them as a possible source of the worm. It's not a destructive worm: it just discourages people from using KaZaA. Now, who would *that* kind of worm benefit?

  111. Re:BBC -- RIAA responsible by Anonymous Coward · · Score: 0

    If all you do is download .MP3 & .AVI, this "worm" shouldn't bother you at all. I think these two files types are safe so far...

    I can't see the connection to the Entainment industry. If any organizations would gain from this would be in the slopware business.

  112. what if some of the Al-Qaida members work for MS? by porky_pig_jr · · Score: 1

    What if some of the Al-Qaida members work for Microsoft. We'll never learn what are the bombs they have planted in the code.

  113. I said this would happen, and it did. by Animats · · Score: 1
    In a previous posting on Slashdot, I predicted that this would happen.

    Kazaa, as previously discussed, comes bundled with a piece of adware called "Projector", from Brilliant Digital Entertainment. Projector not only accepts ads from some specified server, it sets up a peer to peer network and passes them to other Projector clients. It can also distribute updates to itself in a peer to peer fashion. That's its normal operation. So as delivered, it's basically a worm, one that installs a backdoor in user's systems and sets up a whole network to exploit that backdoor for commercial purposes.

    The idea is that it allows Brilliant Digital, which is a tiny company in L.A. that used to produce hip-hop videos, to distribute vast numbers of ads without having a giant server farm. The Projector steals resources from the client machines to push ads around. It's peer-to-peer spam.

    This opens up a huge backdoor into millions of systems. All that's necessary to exploit it is to figure out how to insert new content into the peer to peer system. Worse, because this is a push-type system, an attack can spread very fast. It doesn't require any user intervention. It's an ideal environment for distributing an attack, because it has everything an attacker wants. Built-in!

    And now, somebody's used it.

    As I said previously, if you have any responsibility for computers that do anything important, get Brilliant's software off them now!

    1. Re:I said this would happen, and it did. by Animats · · Score: 3, Interesting
      Well, after finding a description of how this attack works, it looks like it's dumber than I thought. Apparently, it just floods the Kazaa system with copies of itself under different names, hoping somebody will run them. If run, it puts itself in the registry to run at every startup.

      So it requires manual intervention to propagate, and is thus more like a classic virus.

      We may yet see a Brilliant Projector based worm, but this apparently isn't it.

    2. Re:I said this would happen, and it did. by Anonymous Coward · · Score: 0
      Well, after finding a description of how this attack works, it looks like it's dumber than I thought.

      Yeah, well, reading the article is usually recommended before you shoot your mouth off. And now you look stupid.

  114. it might be interesting to know that... by CAIMLAS · · Score: 1, Offtopic

    "Benjamin" is the name of a Biblical character that was part of a large family of 12. He was the only one that stood up for his youngest brother, preventing his other brothers from stoning him to death due to jealousy.

    I'm not sure what relation this has to the RIAA and such, but I'm sure you can derive parallels. :)

    Oh, and it's my first name. Good choice! :)

    --
    ~/ssh slashdot.org ssh: connect to host slashdot.org port 22: too many beers
    1. Re:it might be interesting to know that... by cydnub · · Score: 1

      Acutally, I believe you are thinking of Reuben who was recorded as sticking up for Joseph (other brothers of Benjamin). Joseph was going to be killed by his other brothers because of Joseph's (later true) dreams of his ruling over them. Benjamin *was* the youngest brother. And there were 12 sons plus 1 daughter!

      See Genesis 37 and on...

      OK, OT me now!

  115. Re:yeah, it was the RIAA by Anonymous Coward · · Score: 0

    >Are you shpongled?

    Only when I have a divine moment of truth, or an inexpressible fault.

  116. 2600 by lemonk · · Score: 1

    Anyone else notice the cover of the latest issue of 2600 has a crying Benjamin Franklin bill? :)

    --
    You are only popular on the Internet.
  117. The next big thing by Erik+Fish · · Score: 3, Informative

    WinMX 3.1 was just released a few days ago and it definitely seems to be everything it was hyped as being and more. It's got the many of the features of eDonkey without the bugs and shitty interface. It's also missing the spyware, ad banners and other crap that seems to plague every other p2p network.

    Reading this story was the nail in the coffin for Fastrack, AFAIC. I was going to stick around a while until the new WinMX got it's legs, but forget about that now.

    1. Re:The next big thing by Cl1mh4224rd · · Score: 1

      this problem won't remain exclusive to kazaa/fastrack. in fact, if you're a smart user, you won't have to worry one bit about using kazaa. you're being overly paranoid, methinks.

      --
      People will pass up steak once a week, for crap every day.
  118. Hi Jonathan! by sombragris · · Score: 2, Informative

    Hi Jonathan, I made this post using lynx.

    --
    -- Look to the Rose that blows about us--"Lo, Laughing," she says, "into the World I blow..."
  119. Anti virus by skinfitz · · Score: 1

    I'm just wondering where they are going to steal anti virus software from.

    I'll bet at least some of them try P2P as a source...

  120. Re:Fuck the RIAA by Anonymous Coward · · Score: 0


    no dude, tuxracer is badass!

  121. Re:Ben Coates by Anonymous Coward · · Score: 0

    Were you tight end for the New England Patriots?

  122. This is a VIRUS, not a WORM. by Otto · · Score: 2

    It's an executable that the user must RUN to get infected. It then spreads itself via Kazaa and tricking other users into downloading it.

    Don't download executables over P2P and you won't get infected. Seems a damn_smart thing to do anyway doesn't it? These people getting hit with it are likely also the same guys who spread e-mail viruses by running attachments. :P

    --
    - Give a man a fire and he's warm for a day, but set him on fire and he's warm for the rest of his life.
  123. Here's how to fix it by npsimons · · Score: 1
    If so, what did you do to clean up?


    I patched this hole on all my boxes a long time ago. It's really easy too. I have to warn you, though, the patch is really quite large. About a CD's worth. There are also different versions depending on what your needs are. Go here to download the fix now. Have fun, and happy computing!

  124. Sounds like a job for Sisyphus by Anonymous Coward · · Score: 0

    Who is now in charge of fixing all security problems instead of pushing a boulder up a hill. Hey, since when does IBM run humor?

  125. Alternatively ... by Greedo · · Score: 1

    Perhaps the virus writer has a bone to pick with the companies that are being advertised, or the brokers.

    Making company X pay however many thousands of dollars in banner views is just as valid a motive as trying to collect that same money yourself ... but much easier to get away with, I suspect.

    --
    Tuus crepidae innexilis sunt.
  126. MOD PARENT SIDEWAYS (+-0) by Anonymous Coward · · Score: 0

    GET IT?

    i dont

  127. Ad-Aware by Anonymous Coward · · Score: 0
    I know this is yesterdays news, and the rants about Brilliant Digital may appear a little off-topic, but a lot of spyware out there can be deleted using Lavasofts Ad-Aware [http://www.lavasoft.de] (i think). I disabled all the spyware found on my computer and KaZaA still runs (as well as other software such as Audiogalaxy). It is also worth remembering this programs also have hacked versions which do not install spyware in the first place.

    The only reason I use KaZaA is to download episodes of Cowboy Bebop, as this hasn't even been released in my country yet!!!! I just finished episode 5, it rocked!

    It is also important to note that when using p2p to download executable files a risk is involved. The new system of hashing (pioneered by edonkey2000? and now available somewhere for use in conjuction with KaZaa and other p2p clients) greatly limits the risks involved as every file is given a unique key. So files indexed on [http://www.sharereactor.com] will therefore make your downloadables less risky.

  128. Two words (and explanation) by Anonymous Coward · · Score: 0

    dry run

    Whoever is doing this may well be doing a test run to see how well it works. The next one probably WILL do something really bad.

  129. A dimension too many by vidnet · · Score: 1

    The actual contents of the post was point out that a kill-all solution is applied to a group that some concider to be bad, like christian claims of homosexuality and aids.

    Guess I added a dimension too much. I'm sorry.