Slashdot Mirror


Targeted Worm Hits Kazaa's Network

sh0rtie writes: "Kaspersky Labs and the BBC are reporting that the Fasttrack network that Kazaa uses has been hit by its first targeted worm virus dubbed 'Benjamin.' Is this a clever RIAA creation or that of a mischievous virus writer? I guess we will never know, but the result is that it seems to be bringing unsuspecting users machines to a crawl with full hard drives and clogging up the Fasttrack network with massive amounts of traffic bringing more headaches for ISPs and sysadmins worldwide."

81 of 300 comments (clear)

  1. "Clever RIAA creation"??? by Wakko+Warner · · Score: 3, Funny

    Look at the kind of music these fellows put out. Now tell me anything they create is "clever".

    - A.P.

    --
    "Remember when the U.S. had a drug problem, and then we declared a War On Drugs, and now you can't buy drugs anymore?"
    1. Re:"Clever RIAA creation"??? by Wakko+Warner · · Score: 2

      When you own the means of production, distribution, and broadcast, does anything you create need to be clever?

      - A.P.

      --
      "Remember when the U.S. had a drug problem, and then we declared a War On Drugs, and now you can't buy drugs anymore?"
  2. of all days.... by jeffy124 · · Score: 5, Interesting

    the day the secret Kazaa/Brilliant network came to life is the day that this worm gets let loose.

    --
    The One Rule Of Chess You'll Ever Need: Don't play someone who carries a kit in their bookbag.
  3. Warez Connection by _bobs.pizza_ · · Score: 2, Insightful

    how big of a surprise is this? The whole idea behind kazaa is that you can get music that you don't own. This reminds me a lot of the warez sites out there. How many of us trust them?

    You get what you pay for.

    1. Re:Warez Connection by shepd · · Score: 2

      I remember hearing about a leaked study from a long time ago done by a virus detection company.

      The results seemed to (at the time) finger purchased software and hardware as the prime infection point for many machines.

      Why?

      At the time, BBSes autochecked files for viruses, and most people ran their disks through CPAV/F-Prot before giving them to others (since people "smart" enough to copy a disk were, at the time, able to run simple virus detection software). However, at the same time, major brand name companies didn't bother as much.

      I can even remember a friend buying formatted floppies that came with a virus dropper on the disks...

      If 100 people download infected software from one illegitimate site before the infection is pointed out and cleaned, that's just 100 people. Imagine the destruction that happens when you go gold and don't find out until a few weeks later that your CDs (or computers, or floppies, whatever) include a virus.

      If anyone can find a link to that study, I'd really appreciate it. :-)

      Sometimes you get more than you pay for.

      Your PC is now stoned !!!

      --
      If you could be told what you can see or read, then it follows that you could be told what to say or think - BoC
  4. Stupid Virus Writer? by Saeculorum · · Score: 5, Insightful

    From the article...

    In addition to eating up free disk space Benjamin takes additional actions: under the name of the infected computer's owner it opens an anonymous web site from which it displays advertising banners. This way Benjamin's creator profits by the resulting increase in advertising displays.

    I might be wrong, but I'd think it'd be quite easy to find where the money from the advertising banners is going to. Quite simple to find the virus writer.

    Of course, the recipient of the advertising revenue may not be the virus writer, but it's a good place to start.

    Stupid people amuse me.

  5. I fail to see the "worm" here... by Bollie · · Score: 3, Funny

    but the result is that it seems to be bringing unsuspecting users machines to a crawl with full hard drives and clogging up the Fasttrack network with massive amounts of traffic

    What? Doesn't that happen every time a new cammed version of Spider-Man or AOTC's is released?

  6. Hide the spice! by Limburgher · · Score: 3, Funny

    The worm is coming! It can smell the spice on your hard drive! Delete it, or it'll smash through it and destroy you!

    --

    You are not the customer.

    1. Re:Hide the spice! by liquidsin · · Score: 2

      Some of us just enjoyed the video games...

      The Dune game that was like warcraft (erect buildings, build army, kill foes) was the first pc game I ever bought, I think...

      --
      do not read this line twice.
  7. Next Time A Warhol Worm? by cybrpnk2 · · Score: 5, Interesting

    Some very scary research has been aimed at discovering just how fast a worm could infect the entire Internet. This is the so-called Warhol worm, so named because instead of getting 15 minutes of fame, it would only take 15 minutes to infect the entire internet. If some nut combines a Warhol worm with a Kazza worm, we are in deep trouble.

  8. How is it activated? by Shagg · · Score: 4, Insightful

    The way I understand the article, it replicates itself in someone's share directory and waits for other Kaaza users to download it. How is it executed on the remote user's computer then? Do they have to specifically run the virus program, or is there a security hole in the Kaaza client somewhere that automatically executes the virus?

    I'm assuming users that download this file must specifically execute it. If this is true, then IMHO any person who downloads an unknown .exe from a P2P network and runs it without at least scanning it, deservers what they get.

    --
    Unix is user friendly, it's just selective about who its friends are.
    1. Re:How is it activated? by bonzoesc · · Score: 3, Funny
      The Kazzzasaazaz installer connects to the FastTrack network to download the actual filesharing program (the functionality in the installer + search + spyware and ads and robot monkeys that confuse your clock cycles for bananas and eat them while throwing monkey poop all over your hard drive). Since the client itself also has built in functionality to display stuff, it would be entirely possible to exploit a buffer overflow bug or something like that that slipped through the probably non-existend QC or some such.

      But Kaszzzasdfddsafaszzza is for frat boys, sorostitutes, and pre-teen girls. Real men use FTP or DC++.

  9. Clever RIAA Creation by BlueFall · · Score: 2, Insightful

    Is this a clever RIAA creation?

    What an incredibly irresponsible statement. Don't go pointing fingers until you have some evidence.

    1. Re:Clever RIAA Creation by Aexia · · Score: 4, Interesting

      Yes, quite irresponsible. After all, when has the RIAA ever done anything malicious to innocent computer users' systems?

  10. BBC -- RIAA responsible by hether · · Score: 3, Interesting

    The BBC reported this earlier today:
    http://news.bbc.co.uk/hi/english/sci/tech/newsid_1 998000/1998686.stm

    I agree with the idea that the RIAA would definitely have motive when it came to a worm like this, or some random RIAA suporter. Good thing most intelligent people quit using Kazaa a long time ago, or for sure when they found out about the spyware.

    --

    Most people would die sooner than think; in fact, they do.
  11. The money trail.... by Mhrmnhrm · · Score: 3, Insightful

    Doesn't necessarily point to the culprit. Just because the webserver is hitting/serving up whatever the ad of the hour is, doesn't mean the person getting the checks is the virus writer. How difficult would it be for instance, for a blackhat to write a virus, have it hit/serve a bazillion ads, but send the money to a certain John Ashcroft, who just happens to live in DC, with a job at the DOJ? Especially given the talents of a true blackhat, this wouldn't be difficult at all. Unfortunately, that's what these posts of "Follow the money trail" are doing... it's entirely possible the writer borked up bigtime, but more likely that someone's being made a stooge, and that the money is just a red herring.

    --
    I suspect that one of these choices is incorrect. Correct.
    1. Re:The money trail.... by MoneyT · · Score: 2

      Given the average intelligence of an American citizen (fairly low seeing as how the NY Times is supposedly written at an 8th grade reading level) and the average intelligence of many people, I would be willing to bet that the money trail does at some point lead to the virus creator. And even if it doesn't, I would still be willing to be there is a trail back to the virus writer.

      --
      T Money
      World Domination with a plastic spoon since 1984
    2. Re:The money trail.... by MoneyT · · Score: 2

      Base generalizations are only dangerous if they are false. However, common sense is very lacking in this world. If you need any proof, you need not look any further than the warning lables on common household products such as a hair dryer (Do not use while sleeping or Do not use while showering) or on packages of peanuts (may contain nuts). Also, you might want to reconsider your position in society if you took offence to my previous statement and assumed it applied to you.

      --
      T Money
      World Domination with a plastic spoon since 1984
  12. Easy to catch the creators? by tekBuddha · · Score: 2, Interesting
    From the article:

    "In addition to eating up free disk space Benjamin takes additional actions: under the name of the infected computer's owner it opens an anonymous web site from which it displays advertising banners. This way Benjamin's creator profits by the resulting increase in advertising displays."

    Wouldn't it make sense then that you could track the creators of the worm to whomever is collecting the payout of these banner ads or am I misunderstanding how its working?

  13. And this surprises anyone... Why? by wowbagger · · Score: 2

    Perhaps I am paranoid, perhaps I am an old fart, but I cannot see trusting any file I got from any of the P2P systems for precisely this reason.

  14. Using P2P by tswinzig · · Score: 3, Interesting

    Big whoop. P2P becomes the latest transport mechanism for viruses. It's not exploiting a hole in Kazaa, it's just sharing a folder with virus-infected executables labeled with intriguing names that are likely to be downloaded by Kazaa users.

    If these users are then dumb enough to run an executable file they download from an unknown source, they will be infected.

    Wow.

    --

    "And like that ... he's gone."
  15. Infected? by rkent · · Score: 5, Interesting

    Okay, so... who's infected? any slashdotters get the

    "Error:
    Access error #03A:94574: Invalid pointer operation
    File possibly corrupted."

    message yet? If so, what did you do to clean up? Neither of the 2 articles gives a very good indication of that; I guess I'd start by deleting \windows\system32\explorer.scr and \windows\temp\Sys32, and removing these registry keys:

    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Cu rr entVersion\Run]
    "System-Service"="C:\\WINDOWS\\SYSTEM\\EXPLORER. SC R"

    [HKEY_LOCAL_MACHINE\Software\Microsoft] "syscod"="0065D7DB20008306B6A1"

    Seems like that should keep it from spreading, but that won't prevent a reinfection. Oh well; at least there's a popup notice when you get infected. that's nice.

    Looks like fasttrack users (kazaa, morpheus, AND grokster) are catching on... about 1/5 as many users on as usual for this time of day. And before you flame me as a pirate, I only trade Simpsons episodes which aren't available for sale yet :)

    1. Re:Infected? by Evangelion · · Score: 2, Interesting


      Haven't you ever heard of Anime fansubs?

      People would copy japanese LD's, subtitle them themselves, and sell them (not for much, but still), and no one found anything wrong with this -- because the episodes/movies/oavs were not available in any english language format. The copyright owners usually never said a word. The fansubbers would respectfully, not distribute something that was available in english in north america.

      Your whining is reactionary and unessecary.

      That's what I get for coming back to slashdot, I guess...

  16. These poor script kiddies by Henry+V+.009 · · Score: 4, Insightful

    Whenever I think of what could be achieved by a virus using a P2P system, I am all the more astounded by the limited imaginations of these puny 13-year-old hackers.

    How about using a million computers working in parallel to break an weak encryption and read some third world govenment's military email?

    What about creating a secondary virus that uses known windows vulnerabilities and has a mathematically reasonable replication scheme to install itself on hundreds of millions more computers, and then use that to bring down the entire internet on a given day?

    What about turning these people's P2P servers into a humungous free proxy network, defeating internet censorship attempts of evil totalitarian regimes (like China)?

    1. Re:These poor script kiddies by gad_zuki! · · Score: 4, Funny

      Those are coded so well that they don't get noticed. Your PC is probably rendering 3D storyboards for Pixar and helping Japan simulate a-bomb explosions. Thankfully, everyone blames the lag on Microsoft products.

      Occasionally the cabal writes 'press viruses' like these to keep Kaspersky busy.

    2. Re:These poor script kiddies by JanusFury · · Score: 2

      You bastard! We said we'd let you leave the cabal if you promised not to give away our secrets!

      You'll pay for this, oh will you pay. We'll see who's laughing when you get arrested and strip-searched by the CIA for stealing secret government documents and hiding them in your anal cavity!

      --
      using namespace slashdot;
      troll::post();
  17. Bad Business by Tazzy531 · · Score: 2

    Ever since the whole deal with Kazaa and spyware and using your computer for distibuted computing, I've uninstalled and left them for good. Come on...think about it. If a company does not have the "consumer's" best interests in mind, it will not be able to succeed. What are they going to do when there is a major security issue that opens up your private data to the world? "Ooops..who cares..not my fault..they aren't paying us"

    Kazaa has turned into bad news waiting to happen.

    --


    _______________________________
    "I'm not Conceited...I'm just a realist..."
  18. Advertising? by jfengel · · Score: 3, Informative

    According to the article, the worm sets up a web site for doing advertising, presumably porn. I'd think that that the sites being advertised would be a good place to start figuring out who's responsible.

    It's an amusing idea to use a worm to carry a proft-generating payload, but it sounds like it'll leave a really big paper trail. The more advertisers you get, the bigger the trail.

  19. riaa by mosch · · Score: 4, Funny
    Is this a clever RIAA creation...
    I mean you no disrespect, but you're a fucking retard.

    "hey guys, I've got a great idea. let's make a virus that will expose ourselves to billions of dollars of liability, but will only shut down some minor piracy for a day or two, until anti-virus software makers have protection for it".

    1. Re:riaa by Man+of+E · · Score: 3, Interesting
      "let's make a virus that will expose ourselves to billions of dollars of liability, but will only shut down some minor piracy for a day or two, until anti-virus software makers have protection for it"

      Seems like a pretty good idea to me, actually, especially when you consider how many idiots are on Kazaa. Since the program has no built-in calls to antivirus software, they'll become infected and lose confidence. A smaller percentage of geeks with huge bandwidth, hard drives and the brains to use antivirus software will stay on, but Kazaa will leave a sour taste in Joe Sixpack's mouth and lead him back to the golden path of CD-buying.

      Now suppose the advertising "paper trail" that everyone is talking about leads to some random hacker they picked as a scapegoat, and it's unlikely that anyone will suspect they're behind it all. Liability, schmiability.

      Okay, time to take the tinfoil hat back off :-)

      --
      Ceci n'est pas une sig
    2. Re:riaa by VivianC · · Score: 3, Informative

      You must be right. The RIAA has no history of messing up peoples computers.

      And how do you think all the kazza "pirates" are going to recoup money for not getting the files they were intending to steal?

      --
      Viv

      Gmail invites for ip
    3. Re:riaa by I+Want+GNU! · · Score: 3, Interesting

      Actually, this is EXACTLY the kind of tactics they like to use. Have you seen this article? They tried to get a law passed to hack someone's PC.

      Cigarette companies kill millions of their own customers, Enron executives steal everyone's requirement accounts, and mostly these type of companies get off scot free. Not to mention all the investment advice companies with conflicts of interest, telling people to buy then selling after the price goes up, or vice versa.

      Of course, with all the lobbyists and lawyers and paper shredders, it's not like anything would come of this.

    4. Re:riaa by btellier · · Score: 2

      Really? I could've sworn that the tobacco industry was forced to pay out billions in damages and Enron is in financial ruin. I believe one of their execs commited suicide as well. Not exactly scot free.

      The point is that they tried to PASS A LAW to hack someone's PC. It didn't go through and they didn't hack anyone. They're not going to create a malicious virus that has reprecussions based on legal precedent and risk having to pay out billions in damages just so a few losers get their hard drives filled up.

      Take off your tinfoil hat and think.

    5. Re:riaa by terrymr · · Score: 2

      You forget the RIAA lobbying to be released from liability for damage caused (by them deliberately) to people's computer systems when the terrorism bill was passing through congress. Even though their amendment was defeated they said they already had the legal right to do this from other statutes passed by congress.

  20. Re:BBC -- RIAA responsible by jacoplane · · Score: 2

    I don't see the RIAA mentioned at all in that article. Perhaps your link is incorrect?

  21. Cons-piracy theory by Kirby-meister · · Score: 4, Interesting
    A lot of people will probably put this on the RIAA/other copyright crusaders, but I see P2P networks as a huge market for propogating virii and sending people trojans.

    Large file-sharing networks like Kazaa have birthmarks in the shapes of bulls-eye's.

  22. For fear of stating the obvious... by Restil · · Score: 5, Interesting

    But if banner ads which will profit the creator of the virus are posted on every single infected computer... how hard would it be really to follow the money to find the author of the worm?

    Or was I the first one to read the article? :)

    -Restil

    --
    Play with my webcams and lights here
  23. virus? by bilbobuggins · · Score: 5, Funny
    it seems to be bringing unsuspecting users machines to a crawl with full hard drives and clogging up the Fasttrack network with massive amounts of traffic

    i had this virus once, only i named it 'roommate'.

  24. Yep, Hit me. Here's what I did. by sailor420 · · Score: 5, Informative

    Hit me the other day. Just noticed it last night, and I (think) I have it under control.

    First, look out for small downloads, specifically anything with names such as "installer" or "downloader." I dont know how I got mine, but my brother's machine got hit after he tried to d/l the newest version of Britannica. Serves him right. When I went to see what he downloaded, I saw that it was a file around 700k.

    Yes, it does spread over Kazaa lite.

    Once it is installed, it proceeds to fill up your machine with approximately 700k files, usually in windows or winnt/temp/sys32. Thats where all mine were (Im running W2K).

    However, dont go crazy yet. I downloaded the newest virus update for NAV (dated 5/17) and ran it. It picked all the downloads right up. Since they were all junk files that it had downloaded, I had it delete them all.

    So far, so good. Havent had any recurrence since then (although this was last night, so I dont consider it enough time to truly test). Hopefully it really is this easy to clean up, but Im sure I will quickly find out.

    Hope this helps.

    1. Re:Yep, Hit me. Here's what I did. by stevey · · Score: 2, Insightful

      People who download .exe's from filesharing systems are kinda asking for trouble, aren't they?

  25. ...hyperlink?? by skinfitz · · Score: 2, Interesting

    ...I dont know what happened to the hyperlink there - here is the link in text form:

    http://online.securityfocus.com/archive/1/254627 /2 002-05-17/2002-05-23/1

    And another try at a hyperlink.

  26. Virus companies need the virus makers by bigmouth_strikes · · Score: 5, Interesting
    "This event once again demonstrates the necessity to filter all incoming files for viruses, regardless of how well protected this or any other network is. Before use all data should be run through a mandatory check for virus code using the latest virus database update," commented Denis Zenkin, Kaspersky Labs Head of Corporate Communications.
    Gee, I'm so grateful for Kaspersky Labs that they provide this valuable information. They only forgot to add

    "If you refer to this article, we'll give you $5 rebate off your next virus update purchase." added Zenkin with a smile.

    As much as we need the anti-virus software, the anti-virus companies need the virus makers. Without a worm or a virus that makes CNN headlines every 6 months, people will forget to buy updates, patches etc etc. The public forgets quickly, and will not buy new products from the AV companies if they don't feel a threat.

    Sure, the problem is real, but part of me can't shake the feeling that somewhere there is a anti-virus company executive ordering a new plasma HDTV when he sees this news. Or maybe it's just becase X-Files ended yesterday that I'm seeing conspiracies everywhere.

    --
    Oh, I can't help quoting you because everything that you said rings true
    1. Re:Virus companies need the virus makers by Triskaidekaphobia · · Score: 2, Insightful

      And Doctor's "need" the influenza virus. Doesn't mean they like it.

    2. Re:Virus companies need the virus makers by zangdesign · · Score: 2

      True. But computer viruses don't kill people.

      Yet.

      --
      To celebrate the occasion of my 1000th post, I will post no more forever on Slashdot. Goodbye.
  27. Re:yeah, it was the RIAA by tempest303 · · Score: 2

    Yeah, I'm grinnin' ear to ear as well. While I don't think it was RIAA that created this, I found this part f*cking brilliant:

    Congratulations on your free copy of photoshop (which is alright because you wouldn't have bought it), Windows XP (which is alright, because Microsoft is evil), the new Dave Matthews Band CD (which is alright, because the RIAA is evil), and that DivX of episode 2 (which is alright, because the MPAA is evil).

    Couldn't have said it better. *applause*

  28. Re:Oh, by the way, STEPHEN JAY GOULD DIED by nomadic · · Score: 2

    Boo hoo for you, did you consider that maybe 13 other people submitted it before you, it's maybe 200 submissions down on the queue, and it might get posted later? Sorry your story got rejected and you don't get any karma, but please. Enough with the ragging on people because they talk about other stuff besides your pet topic.

    I doubt the original poster cares about karma; he's complaining about the fact that the editors just have no apparent ability to pick stories anymore. Gould was a brilliant scientist whose passing should be major news. Instead we get an endless succession of stories about file sharing and wireless networks. Interspersed, ironically, with self-congratulatory stories about how brilliant, well-rounded, and scientifically literate geeks in general are.

  29. Re:yeah, it was the RIAA by grung0r · · Score: 2, Insightful

    I know the RIAA didn't write it, it was proabably some self-rightous bastard alot like yourself. How can you possibly defend a company that acts the way RIAA members do? Do you think they care about you? You think all these "thives" go away that their gonna lower prices, or create good content? HA! They are using file sharing as an exuse to pass legislation that gives them a future stranglehold on content creation. "oh, you want to distrubute a song you wrote and performed? Not without the RIAA watermark seal of approval!" Stop defending companys whose soul goal is to make your computer into a nutered VCR, incapable of doing anything without the xxAA's express writen consent.

  30. Hard to tell the worm from the software by BCoates · · Score: 5, Insightful

    Hmm, uses your drive space and bandwidth, pops up ads, modifies your system configuration without your permission...

    Looks to me like the only difference between this trojan and the programs it comes in is that one has a EULA.

    Time for virus writers to wise up and disclaim liability with an incomprehensible clickthrough like all the other writers of malicious code...

    --
    Benjamin Coates

  31. Re:Oh, by the way, STEPHEN JAY GOULD DIED by MoneyT · · Score: 2

    If the original poster actualy cared about his Karma, do you honestly think he would have posted under his account instead of anonymously?

    --
    T Money
    World Domination with a plastic spoon since 1984
  32. Re:Oh, by the way, STEPHEN JAY GOULD DIED by DouglasA · · Score: 2
    Gould was a brilliant scientist whose passing should be major news.

    Yes, it is major news. That's why it's on the front page of CNN, Boston.com, etc. I do not need Slashdot to cover stories that I'll hear about anyway. I come to Slashdot to get more interesting, off-the-beaten-path stories, or sometimes interesting commentary on hugely important news (not just the passing of someone famous).

    Making the Slashdot front page does not mean that the Kazaa worm is more important that SJG. It's called perspective.

  33. MOD THE PARENT POST UP by MoneyT · · Score: 2

    And then go here to read the story with out signing up:

    http://www.majcher.com/nytview.html

    --
    T Money
    World Domination with a plastic spoon since 1984
  34. Re:JESUS MADE THE UNIVERSE by southpolesammy · · Score: 2, Funny


    Evolution is just more Yankee bullshit. Ever since reconstruction, the Yankees have been destroying the truth.

    Yet another reason to hate Steinbrenner....um, uh, oh nevermind...

    --
    Rule #1 -- Politics always trumps technology.
  35. protection is easy... by sluggie · · Score: 4, Insightful

    Just filter out all files under 1 meg... it worked for me since I guess it only shows up when searching for software...

    1. Re:protection is easy... by thumbtack · · Score: 2

      WHAT? And give up my 56kbps MP3 files? OH MY GOD, this is even worse than I thought!

  36. Re:free software innovation by MoneyT · · Score: 2

    And what will you do when the code for the virus is recompiled to run in *NIX? No OS is perfectly secure, the fact that *NIX based OSes and Mac OS was not hit is just an indication of the limited programing skills and/or time of the creator.

    --
    T Money
    World Domination with a plastic spoon since 1984
  37. No he didn't by commodoresloat · · Score: 2

    Don't you mean Stephen King?

  38. Re:Using P2P/End Users.... by tswinzig · · Score: 2

    Yes this is true but ALOT of end users dont know any better or arent smart enough not to or just dont care.

    If you mean "A LOT," you are correct. (I don't know what "ALOT" is, though... is it anything like "ALITTLE?")

    I know they always say all the time not to do it but I still have end users trying to open virus e-mails

    Then if you maintain that network you need to setup a filter to delete executable attachments from incoming/outgoing email!

    --

    "And like that ... he's gone."
  39. Re:Overhyped? by TheLibra · · Score: 5, Informative
    Just find out where the checks are going and arrest him!

    I'm afraid it's not that easy, CmdrTaco. Firstly, you are assuming that the money is going to someone associated with the virus writer. However, from what I understand, there are three types of people who write viruses:
    1. The Attention Getter: This person wants the hype, the name, and the infamy to achieve some sort of status in the cracker or skr1pt k1dd13 community. They don't do it for the money, they just want to be 1337.
    2. The Student: They do it for the study of viruses. They do it to learn. Sometimes it is legit, such as the programmers of anti-virus software, and sometimes it is a hacker (note the distinction I use here) who wishes to understand the why and how of a particular exploit. But we can rule out this type of writer because while they are sometimes in it for the money, they never want to actually cause harm, they want to learn, and their creations are rarely unleashed.
    3. The Causehead: These people write the virus because they feel it will advance their cause. Be it governmental, corporate, or Greenpeace, they have their reasons. They also do not do it for the money.
    4. But take a virus that makes money, such as Benjamin. Well, who says it has to go to the virus-writer. It could very well be a script that sets up the funds to go to any account, anywhere. If the writer was a cause-head, the money could very well be going to Save The Wales or some such to benefit that cause. Or even to a totally unsuspecting list of random accounts, to take away money from the corporations that have to pay for the advertising.


    5. But let us assume that the money is going to the author of Benjamin for a moment. There is also unfortunately the issue of money laundering, offshore accounts, vapor operations, and rerouting of transfers that can make finding out where the money goes all but impossible if someone is clever enough to do it.

      Assuming that someone is keeping the money for themselves, there are a variety of ways that it could be done. As referenced by Carl Sifakis...

      Method 1 Typical Drug Dealer Method

      • 1) Get a million dollars ( how you do this is you own business.)
      • 2) Fly to the Grand Cayman Islands and take your million with you.
      • 3) Some banks in that area sell legitimate off-the-shelf corporations. (These are shell corporations or holding companies. Some even come complete with a board of directors. Buy one of these corporations from the bank.
      • 4) Open an account in one of those banks under the corporation's name and deposit the remainder of your money.
      • 5) Enjoy the islands, get some sun and then go home.
      • 6) When you arrive at home, "borrow" $100,000 from the corporation in the islands by wire transfer. (As sneaky as this sounds, it is totally legal.)
      • 7) Open a restaurant with a bar.
      • 8) At the end of each month, take proceeds from whatever criminal thing you've got going on the side and deposit it in the bank as the take from the bar. It is a good idea to to over report how well you restaurant/bar is doing but not to get to greedy. The Internal Revenue Service takes a dim view of a pizza parlor that purports to do several hundred thousand dollars a month in revenue. If you don't get greedy you won't get investigated. They just don't have the manpower. It is also a good idea to plow some of the proceeds into the legitimate corporation too. If the company does well on its own it can expand and offer more laundering potential.
      • 9) Your criminal money is now clean as a whistle. Pay taxes on it.

      Method 2 The Loanback Method

      • 1) A New Jersey gambler has half a million dollars in profits salted away in a numbered Swiss bank account. He buys a string of car washes( another great way to over report potential sales) for $1 million financing it with 50,000 grand down and $450,000 with a legitimate first mortgage.
      • 2) He "borrows" the other half million from his Swiss bank.
      • 3) Since he is borrowing his own money and repaying it as if it too is a legitimate loan that means he has interest charges. This charade allows him to pay himself the interest and deduct that same interest from his taxes, thus bringing the money back into the country.
      • 4) Once he has paid of his loan to himself he may relend it to himself.

      Method 3 The Money Broker Shuffle Problem

      Mr A is Columbian drug lord. He has a million dollars sitting in New York badly in need of deodorization. Mr B is a legitimate Columbian businessman who wants to buy a million dollars worth of U.S. computers but his government wants 21 cents for every dollar he buys with his pesos.

      Solution: They hire a money broker who for a nominal fee will solve the problem.

      • 1) The million dollars is smurfed or smuggled overland to an account in a Mexican bank. ("smurfing" is process of wire transfer of money in tiny chunks less than 10,000 dollars. This is effort intensive but necessary. Billions of dollars are wire tranfered everyday but only transactions larger than 10 grand are documented by banking institutions. Transactions smaller than this are fully covered under banking insurance. Thus larger transactions are carefully tracked in case something goes wrong. Law enforment also does not possess the manpower to check all these transactions and never will. This is an every damn minute,24 hour a day phenomenon.)
      • 2) The broker writes a check for U.S. 1 million at a correspondent bank in New York City and gives it to XYZ computers.
      • 3) XYZ computers ships Mr B. his machines from its Panamanian free zone warehouse
      • 4) Mr B gives the money broker a million dollars worth of pesos.
      • 5) Pesos become sqeaky clean pocket change of Mr A. Annual loss of revenue to Columbian government: 6-8 billion dollars.

      Method 4 The Omnibus Account Method

      Swiss banks (and others I'm sure) maintain what is known as "omnibus accounts" at American brokerage houses. This make it easy for mafiosi to purchase American blue chip stock anonymously. Naturally, if they make a profit they pay no capital gains taxes on it because there are no records in the U.S. tying them to the stock purchases and the Swiss banks are bound by their laws not to reveal the names of their investors. This enables them not only to make money but to manipulate the market by buying large blocks of stock through the banks and then exercising their proxies, enabling them to determine who will be on the board of directors and who will be C.E.O.


      In Short, if this person has half a brain, then just "seeing where the checks are going" will not reveal the culprit.

      The Libra Eagles may soar, but a weasel never gets sucked into a jet engine.
  40. adserver domain closed by Alan · · Score: 4, Interesting

    Hehehe, if you hit the page that the virus opens to get the author more page impressions (http://benjamin.xww.de/), you get:

    "
    Domain aufgrund von massiven Beschwerden gesperrt.
    Domain closed due to massive abuse.
    "

    Now I wonder if it was closed because someone wrote a virus, or because the virus worked so well he went over his bandwidth allocation! :)

  41. Re:BBC -- RIAA responsible by bricriu · · Score: 2

    I never used Kazaa... but I (used to) highly recommend KazaaLite. All of the functionality, none of the spyware. Oh well, back to my from-source LimeWire v1.6b.

    --

    AHHHHHHH! I'm burning with goodness again!
    - Reakk, Sluggy Freelance

  42. Re:Overhyped? by wdr1 · · Score: 2

    I'm afraid it's not that easy, CmdrTaco.

    FWIW, the person you responded too wasn't CmdrTaco.

    Give him points for being clever though.

    -Bill

    --
    SlashSig Karma: Excellent (mostly affected by moderatio
  43. Re:any surprise? by xtremex · · Score: 2

    I have a Kazaa clone that uses the Kazaa network w/o using the crappy Kazaa Software.Unfortunately, it's for windows only :(
    Go to http://cguru.cjb.net. It's called MyKazaa

    --
    If you're not a Liberal in your 20's, then you have no heart.If you're still a Liberal in your 30's you have no brain.
  44. Re:Oh, by the way, STEPHEN JAY GOULD DIED by ahde · · Score: 2

    1) Only political statements make the front page of any major mainstream publication. News, Ads, and everything else takes a back seat.

    2) Do you think when the Pope dies that it will make the front page on Slashdot? There are a whole heap more catholics than evolutionists in the world. Probably even on Slashdot.

    3) The Kazaa worm affects alot of people, and actually is relevant to the FUTURE. To top it all off, it's even "tech" or "computer" news, which is what slashdot is mostly about.

    4) Obituaries don't belong on the front page. See #1.

  45. Close Call for Me by doublem · · Score: 2

    Today was the first time in weeks I hadn't left my work computer on overnight downloading the latest and greatest 80's MP3s and Star Trek Enterprise AVIs. Tonight it is powered down. Such timing!

    --
    "Live Free or Die." Don't like it? Then keep out of the USA
  46. Re:moral/legal high ground? by Wakko+Warner · · Score: 2

    Yes, it's illegal to download Photoshop, but NO, I wouldn't have paid hundreds for it, and I don't require it, I just want to have it.

    I don't require a Viper RT/10, but I just want to have one, so I stole mine.

    So, unless you don't EVER speed EVEN A LITTLE bit over the limit, don't preach to us about NEVER downloading ANY copyrighted material.

    I never do. So, kindly eat a dick.

    People who attempt to justify their theft in any way are fucktards.

    - A.P.

    --
    "Remember when the U.S. had a drug problem, and then we declared a War On Drugs, and now you can't buy drugs anymore?"
  47. Found 'em! by _ph1ux_ · · Score: 3, Funny

    Pay to the order of : Hilary Rosen.

  48. 216 KB? by kubrick · · Score: 2

    Benjamin is written in Borland Delphi and is approximately 216 Kb in size.

    Bah, virus writers these days.... in my day that virus would have been written in carefully hand-tooled assembly, it would have been polymorphic and it would have been no larger than 5KB. Uphill both ways, etc. etc..... [mutter grumble grumble]

    --
    deus does not exist but if he does
  49. I just saw that in FUDD when I read it: by _ph1ux_ · · Score: 3, Insightful

    "Some wery scawy weseawch has been aimed at discobewing just how fast a worm could infect the entiwe Intewnet"

  50. Mmmquotas by Bastian · · Score: 2

    I had that problem, too, so I had to give my roommate's account on my computer a disk quota. . .

    What I really don't get was the way he would download piles of shit that he didn't even like, like boy bands.

  51. Conspiracy theory: morpheus? by seldolivaw · · Score: 2

    Given the dodgy tactics KaZaA used to grab market share from Morpheus (by shutting them out of the network) and how pissed off Morpheus was at them for doing that, I'm surprised no one has fingered them as a possible source of the worm. It's not a destructive worm: it just discourages people from using KaZaA. Now, who would *that* kind of worm benefit?

  52. Re:moral/legal high ground? by Wakko+Warner · · Score: 3, Interesting

    I have never gone above the speed limit in my life -- go suck three cocks.

    How is stealing one product different from stealing any other, simply because that product comes on a CD-Rom?

    It is deluded thieving slashdroids (with shitty high UIDs) like you that are ruining the Internet. Please eat a bullet.

    - A.P.

    --
    "Remember when the U.S. had a drug problem, and then we declared a War On Drugs, and now you can't buy drugs anymore?"
  53. Re:free software innovation by MoneyT · · Score: 2

    Theoreticaly the same could done in a closed source system. While I see your point that there are more blockages to be avoided if you were to create a sucessful *NIX virus, that does not mean that it is any less threatening to a system. Even if it could only fill up /data2, it's still using HD resources, leading to fragmentation, longer seek times and reduced system performance. All in all a nusence rather than a serious problem, but a problem no less.

    --
    T Money
    World Domination with a plastic spoon since 1984
  54. Re:I said this would happen, and it did. by Animats · · Score: 3, Interesting
    Well, after finding a description of how this attack works, it looks like it's dumber than I thought. Apparently, it just floods the Kazaa system with copies of itself under different names, hoping somebody will run them. If run, it puts itself in the registry to run at every startup.

    So it requires manual intervention to propagate, and is thus more like a classic virus.

    We may yet see a Brilliant Projector based worm, but this apparently isn't it.

  55. Re:moral/legal high ground? by shepd · · Score: 2

    >I don't require a Viper RT/10, but I just want to have one, so I stole mine.

    Interesting how you confuse piracy with larceny.

    When you pirate a movie, or music you deprive no one of that movie or music; whereas when you commit GTA you deprive someone of their vehicle.

    Since a replicator is to matter as a CD-Burner is to data, would you still consider it theft if you replicated a Viper RT/10 using your own equipment and materials?

    If so I would humbly suggest you are a tiny minority of people, and that's the reason why both the dictionary and the law disagree with you.

    My search turns up nothing for "theft", "steal", or "larceny" in the Berne Convention. Methinks you are just plain confused on the issue. Hope this clears it up for you!

    >So, kindly eat a dick.

    Not that I'd want to; But its pretty hard when its shoved so far up your ass.

    >People who attempt to justify their theft in any way are fucktards.

    Agreed, to a certain degree (Les Miserables come to mind as a particular exemption). That's why Copyright Violation is a violation of copyright law, not (AFAIK) theft.

    Or at least that wasn't the intention of the people who created our modern day copyright system.

    --
    If you could be told what you can see or read, then it follows that you could be told what to say or think - BoC
  56. Re:Overhyped? by Pig+Hogger · · Score: 2
    ...
    1) A New Jersey gambler has half a million dollars
    ...
    He buys a string of car washes...
    That's how the IRS caught a launderer: he washed something like 450 cars during a 3 day blizzard...

    Dry-cleaners are a good money laundering method (no pun intended!!!). Some years ago, around here, someone started a chain of $1 dry-cleaners. Within weeks he was firebombed into oblivion.

  57. Re:AudioGalaxy by amuro98 · · Score: 2

    So long as they allow files that can contain executable content (benjamin uses a .scr file, for instance) then, yes.

    There's nothing really special here. All they did was take Melissa, modify it a bit, then start sharing files named "naked gurlz.jpg.scr" Someone downloads it, clicks on it, and the rest is history.

  58. The next big thing by Erik+Fish · · Score: 3, Informative

    WinMX 3.1 was just released a few days ago and it definitely seems to be everything it was hyped as being and more. It's got the many of the features of eDonkey without the bugs and shitty interface. It's also missing the spyware, ad banners and other crap that seems to plague every other p2p network.

    Reading this story was the nail in the coffin for Fastrack, AFAIC. I was going to stick around a while until the new WinMX got it's legs, but forget about that now.

  59. Re:Never dload something executable off of P2P by kraf · · Score: 2, Insightful

    > The lesson: never, ever download something executable off of a public P2P network like Kazaa, Gnutella, etc.

    Don't forget, gnutella runs on non-braindead platforms too.

  60. Hi Jonathan! by sombragris · · Score: 2, Informative

    Hi Jonathan, I made this post using lynx.

    --
    -- Look to the Rose that blows about us--"Lo, Laughing," she says, "into the World I blow..."
  61. This is a VIRUS, not a WORM. by Otto · · Score: 2

    It's an executable that the user must RUN to get infected. It then spreads itself via Kazaa and tricking other users into downloading it.

    Don't download executables over P2P and you won't get infected. Seems a damn_smart thing to do anyway doesn't it? These people getting hit with it are likely also the same guys who spread e-mail viruses by running attachments. :P

    --
    - Give a man a fire and he's warm for a day, but set him on fire and he's warm for the rest of his life.
  62. Re:moral/legal high ground? by Wakko+Warner · · Score: 2

    Or, are you Mother Theresa?

    Yes. I am without sin, and I am casting stones.

    Duck, motherfucker.

    - A.P.

    --
    "Remember when the U.S. had a drug problem, and then we declared a War On Drugs, and now you can't buy drugs anymore?"