Slashdot Mirror


Yet Another Windows Worm

kraksmoka writes "MSNBC is reporting that yet another active worm is taking over computers in 115 countries today. 'Antivirus companies were on high alert Thursday after the rapid spread of a new computer worm that includes particularly malicious snooping techniques. Bugbear.B, a variant of a worm released last year, installs keylogging software, back-door software, and in some cases even attempts to control infected computersâ(TM) modems. Some of the wormâ(TM)s functions are designed to specially target financial institutions.' Yummy!"

34 of 726 comments (clear)

  1. Alreay run into this... by Anonymous Coward · · Score: 5, Interesting

    I've already run into this with one of our banking customers... now if they'd only bought the firewall solution from us that stripped email attatchments based on mime type and/or file extension (why the hell any half-way reasonable person would double-click on a .pif file in their email is beyond me). If I'd only known 10 years ago (before I was legally an adult) the kind of security that existed at some of the small to medium sized banks, I probably I've already run into this with one of our banking customers... now if they'd only bought the firewall solution from us that stripped email attatchments based on mime type and/or file extension. If I'd only known 10 years ago (before I was legally an adult) the kind of security that existed at some of the small to medium sized banks, I probably would have made some very different career choices--I suppose it's better this way... (Posted anonymously for obvious reasons)

    1. Re:Alreay run into this... by Anonymous Coward · · Score: 5, Informative

      Only if you are 2 years behind in your patches.

      http://www.microsoft.com/technet/security/bullet in /MS01-020.asp

    2. Re:Alreay run into this... by Thing+1 · · Score: 5, Informative
      Here's an article on disabling windows script hosting.

      Pretty simple really; for Windows 2000:

      * Open "My Computer"
      * Select "Tools/Folder Options"
      * Click on File Types tab
      * Find VBScript Script File
      * Select Delete
      * Click OK
      For other versions of Windows, click on the link (it has instructions for 95, 98, NT and 2K; I'd imagine XP is similar to 2K but it was written in 2001 prior to XP's existence).

      I'm trying to find instructions for modifying the security in Outlook 2000 as well, so it doesn't do anything automatically without a) my approval at the very least, or b) me asking it to run an attachment.

      If anyone has pointers/links to articles on Outlook security, please post. Thanks!

      --
      I feel fantastic, and I'm still alive.
    3. Re:Alreay run into this... by LiquidCoooled · · Score: 5, Interesting

      there are plenty of people out there who are using windows 98 on a modem.
      Over the last 2 years they have allowed windows update to drip the updates to them.
      Last week Joe's hard drive crashed and he reinstalled.

      I cant see him sitting there for the next 8 hours downloading patches - sure, he will run windows update if we are lucky, but he's likely to be getting his other more important (to him) stuff setup to be worrying about critical updates.
      Waiting for a mail about college?
      Waiting for his girlfriend to get back to him?

      Whatever it is, his thoughts at best would be "I'll just quickly check my mails..........."

      I dont think its entirely stupidity, its human nature.

      --
      liqbase :: faster than paper
    4. Re:Alreay run into this... by Anonymous Coward · · Score: 5, Funny

      Waiting for his girlfriend to get back to him?

      This is why Linux users are less suceptible to worms...

    5. Re:Alreay run into this... by darien · · Score: 5, Funny

      This is an EXE, not a VBScript.

      That's OK. Just go into the registry and delete this branch:

      My Computer\HKEY_CLASSES_ROOT\.exe

      Reboot, and I guarantee that computer won't have a problem with rogue .exe files again.

  2. Frustratingly typical day in the life of Microsoft by dtolton · · Score: 5, Insightful

    It's frustrating how many viruses Windows keeps getting slammed with.
    There are some people that will point to a Linux worm or virus here
    or there, but I run both Windows and Linux servers and there is
    simply no comparison with the amount of worms Windows based machines
    receive. Some people say it's because Windows is much more prevalent
    than the Linux, but there are a lot of servers running Linux now.

    The amount of work required to keep up with just doing updates has
    finally gotten to me. Last night I noticed my Windows server was
    sending packets like mad, suspicious I did a netstat -an, it was
    making connections to hundreds of other machines. Tired of this
    dance, I decided to just shut the windows server down. Maybe one day
    I'll patch it...then again, maybe I'll just leave it shut down for
    good.

    Interestingly, my GNU\Debian Linux box is happily sitting right next
    to it serving up pages. I haven't had to reboot it in ages, I imagine
    it will be running until a nifty new kernel comes out that I just
    have to have.

    See ya Microsoft.

    --

    Doug Tolton

    "The destruction of a value which is, will not bring value to that which isn't." -John Galt
  3. it's a good one! by thomasmd · · Score: 5, Interesting

    This one spread through my university like wildfire today! It even seems to fake Norton virus definition updating, such that the computer appears to be updating it's virus definitions but isn't. It seemed to spread via hijacked messages that it attached itself to.

  4. Poor Windows.... by Dr.+Photo · · Score: 5, Funny

    It's time to face the facts: Windows just isn't ready for the desktop.

  5. How to Fix MS Software by MBCook · · Score: 5, Interesting
    ... and in some cases even attempts to control infected computersâ(TM) modems.

    Seems to me that would be the way to get these things fixed permanantly. Make a worm that would call MS tech support on peoples modems. Or any other MS 800 number. Untill something costs them a LOT of money, these will continue to show up.

    --
    Comment forecast: Bits of genius surrounded by a sea of mediocrity.
  6. Patch Available by Eberlin · · Score: 5, Funny

    Quick, get your patch here

    1. Re:Patch Available by damiam · · Score: 5, Informative
      Crap. It broke my machine. I can't play GTA anymore!

      Sure you can.

      --
      It's hard to be religious when certain people are never incinerated by bolts of lightning.
  7. Re:Frustratingly typical day in the life of Micros by dtolton · · Score: 5, Informative

    Yeah, because it's a lot of work to set windows to do updates automatically. Just a troll, nothing to see here.

    You obviously don't administer servers with Enterprise Level Code. If you did, you'd know that with Microsoft you can't simply use automatic updates. Microsoft Service Packs break systems all the time. If you run ASP.NET and Sql Server code, you get bitch slapped everytime they release a service pack or "security fix". They consistently change functionality, without warning. Then they just post on their website (three months later) that the service pack changed the way some undocumented feature worked, but you weren't supposed to use it that way anyway, so tough shit.

    Ha!! Automatic updates my ass.

    --

    Doug Tolton

    "The destruction of a value which is, will not bring value to that which isn't." -John Galt
  8. Re:Frustratingly typical day in the life of Micros by spurious+cowherd · · Score: 5, Insightful

    *tweet*

    time out.

    any admin who sets production servers to be "automatically updated" deserves to be terminated with prejudice.

    you test all patches before deployment.

    --

    Time flies like an arrow, fruit flies like a banana.

  9. It's a nasty one by jdreed1024 · · Score: 5, Interesting
    This hit MIT starting this morning. It's quite clever about where it gets the addresses and e-mails from. It knows how to scan the mailbox formats of many common e-mail clients, not just Outlook. It sends itself as an attachment to actual messages from the infected user's inbox. So the body is not something obvious ("I send you this file to have your advice"). I actually thought several of the messages I received were real, since they pertained to recent business around campus. (I didn't open the attachments, of course seeing the .scr extension - not that it does much to an OS X box). It's backdoor runs on a fairly standard port (1080) that's used for plenty of legitimate apps (proxy servers) so scanning your network for open ports won't necessarily find it for you. (as opposed to scanning and seeing that port 31337 is open, or something like that, which obviously "wrong"). The keylogger component is quite scary too. It's one of the more advanced viruses I've seen recently...

    On a related note, anti-virus programs is one place where I can actually see a potential useful application of "trusted computing" (no, not necessarily Palladium). If there could be some way to to tell the OS "Look, I don't care if you're the administrator or not: the only programs that are allowed to terminate the anti-virus scanner process are the scanner itself, and, say, Task Manager". By using keys to prove their identity, it _might_ make it a lot harder for virii to terminate anti-virus programs. (Note to slashbots: I'm not saying Palladium is good because it will do this (I don't even know if it does). I'm saying this is one potential application of some as-yet-undeveloped implemenation of "trusted computing".

    --
    There is no sig, there is only Zuul.
  10. Fools! by displaced80 · · Score: 5, Interesting

    Any readers in the UK with Sky Digital, switch to channel 268.

    Overnight, the channel plays a Flash-based word game, where viewers SMS in answers. It's running on a Windows PC, and the screen currently being broadcast to 7 million homes is....

    McAfee dialog box: 'bugbear.b High Virus Advisory....'

    Hmmm.

    (wandering OT - the channel, 'Friendly TV' is apparently being run by students on work experience. A nightly live-broadcast show is 'Girl Talk', where... girls... talk... about... things. Whatever comes into their heads. Oh, and they get progressively more drunk as the evening progresses, which no doubt helps.)

    --
    What's the frequency, Kenneth?
  11. Educate the user by Anonymous Coward · · Score: 5, Insightful

    The people that open these attachments aren't system admins. They aren't network programmers. They aren't even computer literate half the time. Most of the time they treat the computer like a magical device that mysteriously allows them to type and send mail very fast. My mom doesn't even know what a zip/exe/jpg file is. I think it is hard for us to imagine not knowing what we know about computers, but the fact is, that most people using computers don't know a fraction as much as anyone reading slashdot. In fact, most of these "virus" are technically trojans. They are all exploiting the ignorance of the user to mass infect others. There is nothing any operating system can do to stop this. If we were all running Linux, more people would be tricked into running as a SuperUser or Root or some other exploit virus programmers would find. In the end, it's not which is it the right operating system, but have we educated the person behind the machine.

  12. Re:Blah, blah... by jdreed1024 · · Score: 5, Informative
    The patch for this was out 2 years ago. No excuse.

    Uh... Patch for what? I was unaware I could apply a "patch" that would prevent me from getting viruses. It exploits a user vulnerability (stupidity), not an OS one. And McAfee seems to disagree with you about when this was discovered. See here

    --
    There is no sig, there is only Zuul.
  13. The Outlook exploit... by SIGBUS · · Score: 5, Informative

    ...is one involving how it handles MIME types, especially within IFRAMEs. What happens is, the message headers will say it's one type, such as audio/x-midi, while the payload is really an EXE file, sometimes misidentified as a .bat or a .pif. The unpatched Outlook or OE thinks, "Ah, a MIDI file! Let's play it!" and blithely passes it to the OS, which thinks, "Ah, an executable! Let's run it!".

    One more example of why HTML doesn't belong in email, aside from web bugs and other BS.

    --
    Oh, no! You have walked into the slavering fangs of a lurking grue!
  14. Re:Frustratingly typical day in the life of Micros by Osty · · Score: 5, Insightful

    And if they didn't repell attacks, that would be almost good too.

    Because there's nothing quite like a 100,000 machine-strong DDoS network of Redhat machines on cable modems. I hope you meant that if machines are not repelling attacks, then that would prompt bug fixes. However, as you see in the Windows world, most attacks are targetted at already-fixed issues. The machines that get infected are the ones that didn't stay up to date (or in lots of cases a few years ago, were running software they shouldn't be running, like personal Redhat machines running BIND because it was installed and started by default in an "install everything" scenario, the installation option used by most newbies because they're afraid of missing something during the initial install and not knowing how to install it later).


    No, successful virus/worm/hax0r infections are never desired. Better for the issues to be found by competent and moral ("moral" being that they don't use the exploit maliciously) people before a major virus or worm is written. There are excellent patch distribution channels for both Windows and Linux these days. People really should use them. And for production servers that don't use them because they need to do validation before deploying the fix, they need to get off their asses and do the validation. There's no excuse for a 2 year old bug causing issues now. That's 1 year, 11 months, and 3 weeks of laziness (assuming it takes about a week to do a validation and deploy the fix and any resulting changes).

  15. Re:Modem.. by dorko · · Score: 5, Interesting
    Bzzt. Wrong. Thanks for playing.

    This worm does try hard to get on the 'net. Copied from Symantec.

    If W32.Bugbear.B determines that the default e-mail address for the local system belongs to a banking company, it enables auto-dialing through the registry.
    This is accomplished by setting the following value:
    "EnableAutodial"="0000001"
    in the registry key

    HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Internet Settings
    The worm contains a large list (over one thousand) of targeted bank domain names from around the world. This is likely in an attempt to steal passwords more effectively. Therefore, banking institutions may be considered to be more at at risk.
    Looks like they're trying to obtain passwords to bank specific systems.
  16. Re:Blah, blah... by stefanlasiewski · · Score: 5, Informative

    Patch for what? ... It exploits a user vulnerability (stupidity), not an OS one.

    Patch, for the exploit in IE.

    According to Symantec and McAfee, Bugbear.B uses an IE exploit that was fixed over 2 years ago : "Outgoing messages look to make use of the Incorrect MIME Header Can Cause IE to Execute E-mail Attachment vulnerability (MS01-020)".

    --
    "Can of worms? The can is open... the worms are everywhere."
  17. The Fun Of Reading Other People's E-Mail by KU_Fletch · · Score: 5, Funny

    Our University is being hit hard, especially because almost all classes and departments have these massive listservs and the listserv software is so archaic that it doesn't have viral replication blocking. Oh well, at least I get the personal enjoyment of reading other people's e-mails that get cloned. So far I've got 2 that involve people talking about me behind my back. There's always a golden lining people.

    --
    It's not stupid. It's advanced.
  18. Re:Frustratingly typical day in the life of Micros by nolife · · Score: 5, Informative

    Yeah, just imagine if something like Apache gets popular, imagine the havoc people could cause with uptimes on those OS's.

    Yes, the server community is different from userland and every piece of software will have its flaws, but popularity is not proportional to the amount of worms and viruses, lack of quality is.

    --
    Bad boys rape our young girls but Violet gives willingly.
  19. Re:windows vs *nix - un-informed is un-informed by Soko · · Score: 5, Insightful

    that's not really true though, since there are holes in windows that have been there since windows version 1. Sure there are holes in any program, but at least most of the unix/linux/macos viruses don't cause the computer to crash. In almost every case, unix/linux/bsd viruses are really just exploiting a single program.

    The point being...? Really, you have done nothing to assist our underinformed cyrax777. Let me help, please.

    First, causing the box to crash or not is irrelevant, as is what program allowed the compromise - a compromised machine is no longer yours. Time to re-install the whole machine.

    The reason *nix is much harder to infect in the first place is users run with user privileges, as do all the child processes that they create. Thus, the e-mail client cannot over-write any system files since it lacks the autority to do so. This is where "rooting" the box comes from - you need to elevate your normal privs to super user status in order to do any real damage. You can tell most *nixes that "This user account can never elevate it's priveleges", and it likely never will. System services, like say the Apache HTTP server, are usually set up to run as under-priveleged users as well, so compromising them leads to even more difficulty controlling the whole machine - there's very few opennings in the *nix security armour. In contrast, right now my XP laptop is running login.scr as SYSTEM. Yup, a screen saver with system level privs. IIS on NT/Win2K is the same way - out of the box it runs under the SYSTEM account. If one of these is compromised, it's not your machine anymore. Now you know where a lot of the issues with Windows security lie.

    This reflects one of the design philosophies of *nix: only give users the privileges they need, and have a huge, well defined wall between them and the system. Windows seems to come from the other end - give it all, and try to take away what's dangerous. IMHO, that's where Windows fails - miserably.

    Soko

    --
    "Depression is merely anger without enthusiasm." - Anonymous
  20. Re:Frustratingly typical day in the life of Micros by SN74S181 · · Score: 5, Insightful

    Here's a secret you might not know:

    On Unix/Linux Desktop systems there is nothing on the system as important as the user's data in his home directory.

    So the whole notion that trojans/worms etc. can't hurt the systems that 'mere users' will be using as there is more and more of a push to Linux desktop systems is just plain nonsense. If it wipes out an employee's whole writeable diskspace, it's done all the damage it could possibly do. Nobody cares that everything that rolled off the Install CD is still there and might even be pristine.

  21. Re:Commercial Idea by _Sprocket_ · · Score: 5, Funny

    Close. I believe the quote actually goes...

    "Do you have a sex life?"

    "No, I read PC Gamer."

  22. How to permanently disable HTML mail in Outlook XP by cscx · · Score: 5, Informative

    First, run Office Update so you have at least Outlook SP1 (SP2 has been out for a while, in fact). Next, add the following value to the registry:

    HKCU/Software/Microsoft/Office/10.0/Outlook/Opti on s/Mail

    REG_DWORD: ReadAsPlain = 0x01

    Outlook will convert all HTML to plain text before rendering it, and turn all embedded images, etc into attachments.

    Thought I'd share that little tidbit.

  23. Re:Frustratingly typical day in the life of Micros by Blkdeath · · Score: 5, Insightful
    Give it time. As Linux permeates industry and business it will start getting more attention from the virus writers. It's all a matter of ROI. Right now, attacking windows has a very high ROI.

    Which is exactly why so many worms target Apache rather than IIS.

    Batting down strawmen for 12 years and counting ...

    --
    BD Phone Home!

    Shameless plug. Like you weren't expecting it.

  24. Re:Frustratingly typical day in the life of Micros by Blkdeath · · Score: 5, Insightful
    On Unix/Linux Desktop systems there is nothing on the system as important as the user's data in his home directory.

    I don't know about you, but I administer systems with hundreds or thousands of users. It's *their* data I wish to protect, not that of the irresponsible schmoe who ran untrusted binary code.

    <OBSIMOM>
    But if they ask me nicely, maybe I'll keep that backup tape away from the degausser.
    </OBSIMON>

    --
    BD Phone Home!

    Shameless plug. Like you weren't expecting it.

  25. Re:How to permanently disable HTML mail in Outlook by Darby · · Score: 5, Funny

    add the following value to the registry:

    HKCU/Software/Microsoft/Office/10.0/Outlook/Opti on s/Mail

    REG_DWORD: ReadAsPlain = 0x01

    Outlook will convert all HTML to plain text before rendering it, and turn all embedded images, etc into attachments.


    And people claim that Linux (UNIX, whatever) is hard to handle.

  26. Good sources instead of product placement by SgtChaireBourne · · Score: 5, Informative
    I realize the editors are obligated to plug MS, including MSNBC, in any way, shape, or form that they can, but that only lends them credibility. Most of the articles are edited from wire feeds like Reuters, API, UP, AFP (usch), BBC, and so on. Please use those.

    In this case, other sites that covered this week's pair of Microsoft worms first -- and they'll cover next week's first, and so on. ZDNet, eWeek, Infoworld, Reuters, the Register and others covered it first. ZDNet has the bad habit however of sliding stories that reflect badly on MS quickly off the top pages and into obscurity.

    Worms like sobig and bugbear only affect products with design flaws. Brian Valentine, senior vice president in charge of Microsoft's Windows development, said it best:

    Our products just aren't engineered for security.
    In short, there's nothing you can do to improve your security except upgrade to a different client: Mozilla or Opera instead of MSIE, Eudora or others instead of OutLook, OpenOffice.org or WordPerfect instead of MS-Office. Usually by upgrading you get better functionality, ease of use in addition to stability.

    --
    Beta is broken and the link to classic doesn't work. Stop wasting our time or there won't be anybody left here.
  27. Actachments by 0xA · · Score: 5, Informative
    For every bug it strips out it will strip out a legitmite file as well.

    That's bullshit. You'll notice these things don't just use any old extension, they use executable extensions. If you setup your mailserver to strip .pif, .scr, .vbs etc you'll be in a much better world.

    When was the last time you got a legitimate email with a .pif attachment? Never, that's when. I setup this on all of my clients networks and have yet to have grabbed a single legit email.

    1. Re:Actachments by walt-sjc · · Score: 5, Insightful

      Why is this modded as a troll? It's the truth.

      I've been running a filter on email for about 5 years. Not ONCE has any of the email transmitted viruses / worms made it through, even to unpatched outlook and OE users.

      See John Hardin's procmail filter for a Very good example of how to do this.

      If you are running a corporate meail server and are not filtering for known executable extensions, you are a fucking idiot. Period. There is just no excuse to EVER allow unfiltered mail through. Would you put your corporate LAN on the internet with no firewall at all? Of course not, but by not filtering email, you have a hole the size of Yankee Stadium in your protection. It's like wearing a condom with the end cut off.

      The problem with anti-virus software is that it relies on the vendor to create and distribute filter definitions. It can take DAYS or WEEKS for vendors to identify a new virus, and create a definition, and for people to download the new rule set. This lag time is deadly. Antivirus software is a LAYER of security on email, but to rely on it alone is not enough.

      Security is a process, and a mindset. Everyone who knows anything at all about software knows that every program has bugs. All you can do is minimize exposure, and you do that with many layers of security. These layers don't have to be intrusive, but you need them to reduce your vunerabilities.

      Hey, if you want to bury your head in the sand and refuse to participate in security, that's fine with me. I charge by the hour.