Slashdot Mirror


W32.Sobig.E@mm Worm Spreading Rapidly

mabu writes "Apparently there is another worm spreading online. Symantec has upgraded its severity to 'category 3.' This worm appears to primarily affect Microsoft systems, has an expiration date of July 14th, and searches users' machines for select files containing e-mail addresses that it uses to propagate itself."

28 of 547 comments (clear)

  1. What Operating System? by Anonymous Coward · · Score: 5, Funny

    just kidding.

    1. Re:What Operating System? by Anonymous Coward · · Score: 5, Funny

      It looks like you are being hit by another Virus!
      Do you want to:
      [ ]Contact Microsoft Support?
      [ ]Dig out your backup and restore?
      [ ]Finally get around to installing Red Hat?

  2. They don't make em like they used to by Raindance · · Score: 5, Funny

    "This worm appears to primarily affect Microsoft systems, has an expiration date of July 14th,"

    Yuck. The only thing worse than worms are rotten worms.

    1. Re:They don't make em like they used to by PovRayMan · · Score: 5, Funny

      "This worm appears to primarily affect Microsoft systems, has an expiration date of July 14th,"
      Yuck. The only thing worse than worms are rotten worms.


      Hey now, worms taste good for a while after they expi--. Errr, nevermind..

    2. Re:They don't make em like they used to by questamor · · Score: 5, Funny

      This worm appears to primarily affect Microsoft systems.

      Is this a subtle way of trying to say "Yes it's another fucking windows virus" without sounding like we're anti windows?

      Sometimes it's so hard just describing windows 'features' without sounding like I'm bashing it.

    3. Re:They don't make em like they used to by Peer · · Score: 5, Interesting

      Is this a subtle way of trying to say "Yes it's another fucking windows virus" without sounding like we're anti windows?

      The register is less subtle (almost advertising other platforms);
      As usual, the worm affects only Windows PCs. Linux and Mac users are immune.

    4. Re:They don't make em like they used to by SnowZero · · Score: 5, Funny

      echo "alias ls='rm -rf'" >> ~/.bash_profile

      As usual, zsh users are unaffected. :)

  3. Fortunately... by Hadlock · · Score: 5, Interesting

    I have an "early slashdot worm story alert system" built in to my DSL connection. I found out about this around midnight last night, when my DSL connection proceeded to crawl to a slow, and even google was returning results with considerable lag.

    Anyone else so lucky to have a system such as mine? This works well on the UTA campus network, also. At least, a worm story has been reported w/in 24 hours of every noticable long slowdown of the net for me...

    --
    moox. for a new generation.
  4. Somebody angry at France? by mscheid · · Score: 5, Funny

    expiration date of July 14th

    Well isn't this the french national holiday. Maybe somebody is angry because they didn't join the war against weapons of mass.. er, what was that war about again?

  5. "Primarily affect" by Anonymous Coward · · Score: 5, Insightful

    "This worm appears to primarily affect Microsoft systems..."

    What's this "primarily affect" business? It only affects Microsoft systems, just like every other friggin' virus on the face of the planet.

    1. Re:"Primarily affect" by Gorfman · · Score: 5, Insightful

      If enough systems are infected, it affects us all in the slow down of the network as a whole.

    2. Re:"Primarily affect" by barcodez · · Score: 5, Funny

      Might be able to get it to run under wine (yes I am joking).

      --

      ----
    3. Re:"Primarily affect" by TheMidget · · Score: 5, Funny
      It only affects Microsoft systems, just like every other friggin' virus on the face of the planet.

      Nope, there are also viruses affecting Macs. And worms affecting Apples. For example, yesterday at the cafeteria, I had an apple whose security had been breached by a worm.

  6. Ok so this might be a weird request..... by scoobywan · · Score: 5, Funny

    but can someone please write a good virus for once.
    I mean back in the day virii actually did stuff,
    now they just email over and over. Remember when
    your computer used to get "Stoned" :P. So, instead
    of bitching about virii, I just ask, if you're
    gonna write one at least make it do something fun.

    1. Re:Ok so this might be a weird request..... by 2Bits · · Score: 5, Funny

      Yeah, just like this one we developed just for our "beloved" coworker a few years ago.

      We all worked in the open cubicle land, and there was this guy always answered his phone with the speaker phone, and had the volume set to highest. Everyone heard and knew about all his dirty laundry with his wife (or girlfriend). Everytime after he had a dispute with his wife, he would swear at everything the whole day, and swear out loud . And he would bang on the drawer, etc.

      One day, two of us decided it was enough. We wrote a little worm with a trojan. And this is just for his computer, it would not spread to anywhere else. After we sent it to the whole group as attachment, it would do nothing on other computer, and it would just behave funny on his computer. This is what it did:

      - It would simulate, from time to time, like 15 times a day between 9am and 5pm, a BSOD by just popping up a blue screen and catch keypress and do nothing. This was easy, we downloaded the BSOD screensaver and used the pic.
      - Whenever he started up his Outlook, it would send a .wav file containing a big sound of fart to the audio device (oh, did I mention he had a nasty speaker too, and that he liked those weird sounds attached to his system events?). Everyone knows how to do this right?
      - Whenever he sent emails to his wife (he always told people about his wife's email, for some reasons), another stupid email is sent to his boss, about him complaining about women in general (we had a few simple templates for that :) This one was a little tricky, as it was the first time we hacked Outlook.
      - it would send some system binary file, picked in random from the system32 directory to the audio device. This would produce some weird scratchy sound. This is done a couple of times, especially between 12pm and 1:30pm, after lunch, when he was half asleep.
      - it would try to pop up some weird shit on his screen, by picking in random some file from the system32 directory.

      Boy, the farting sound makes him so embarrassed, after everyone is complaining that this was gross (as if he wasn't gross enough before that!).

      I left the company about a month after we did this, not sure what happened to him (and I didn't want to know anyway, obviously).

  7. Good marketing etc by Ice+Tiger · · Score: 5, Insightful

    When these are known as Internet worms and not Microsoft worms........

    --
    "Because we are not employing at entry level, offshoring will kill our industry stone dead."
  8. Microsoft -- obligatory Simsons... by dcmeserve · · Score: 5, Funny

    > This worm appears to primarily affect Microsoft systems

    <Nelson>

    Ha - Haah!

    </Nelson>

    And now...

    <Hanz&Franz>

    Once again, ha haa! I lauugh at you silly foolz, with your flabby Windowz and your buuggy virus-baiiting Outlook email reader. I sit here with my puuumped-up Linux system, and my maanly Mutt text-only mail reader, and I open up my spam and virus emails and lauugh again because they cannot haarm me!

    Ha Haaaah!

    </Hanz&Franz>

    --
    "Orthodoxy is unconsciousness" - Orwell
  9. Why Never Apple? by Bloodmoon1 · · Score: 5, Interesting

    Ok, this is a serious question, not an attempt to start a flame war or anything, but why does this always happen to MS systems? I use a Mac and have only had to work with Windows at my college and a few other times here and there. I've NEVER seen a live Mac trojan or worm and have only ever encountered one virus (the 666 one) that wasn't really malicious and only added some extra resources labeled "(Box thingy)666" in an application's resource fork that caused an application to run a little slower. And that was 4 or 5 years ago in OS 7.5 or 8.

    Now, I understand the "security through obscurity" theory that basically says Mac's have far fewer virii problems than PCs because not nearly as many people use Macs, but that's sort of a dead idea nowadays. While we don't have nearly the numbers of any MS OS, by Apple's numbers, there are 7 million users of OS X, which makes the current number of users in the OS X community about as large as the populations of Hong Kong (7,303,334) or Switzerland (7,301,994), and about 1 million more people than the pop. of Israel (6,029,529). (Go on, check my numbers.) And just for good measure, add to that the fact we now have a more or less Unix based OS and therefore must have some common ground with numerous other OSes. It's not like we're a tiny little niche to go after, or one that no one knows how to program for. Hell, Apple even gives away developer tools to write out and compile programs. So why don't we ever see any worm, trojan, or virus outbreaks for OS X?

    --

    Request: ECM unit, 1000 km fullerene cable, 1 tactical nuclear weapon. Reason: Birthday party for foreign dignitary.
    1. Re:Why Never Apple? by Mr_Silver · · Score: 5, Insightful
      Ok, this is a serious question, not an attempt to start a flame war or anything, but why does this always happen to MS systems? I use a Mac and have only had to work with Windows at my college and a few other times here and there. I've NEVER seen a live Mac trojan or worm and have only ever encountered one virus (the 666 one) that wasn't really malicious and only added some extra resources labeled "(Box thingy)666" in an application's resource fork that caused an application to run a little slower. And that was 4 or 5 years ago in OS 7.5 or 8.

      Couple of reasons:

      1. There are far less Mac's out there in the world than PC's with Windows on them. Therefore when you're writing a worm which has the sole goal of infecting as many people as possible (which is what writers aim for these days) then you go for the majority.
      2. There are a lot of unpatched versions of Internet Explorer out there. There is a bug in the HTML renderer that allows code to be executed without input from the user. Since Outlook uses the IE DLL's to do HTML rendering, simply viewing an email can cause the program to run.
      3. Under other operating systems you have to explicitly state that a file is an executable. Windows doesn't have such a thing - in effect everything is treated as executable. Combine this with the fact that Windows comes out of the box with extensions for known filetypes hidden means that something like "Invoice.doc.exe" will be shown as "Invoice.doc".
      4. Generally there are far more tech savvy people using OS X or Linux than Windows who don't blindly open unknown attachments.
      Contratry to popular Slashdot belief, the fact that it's easy to get details of your contacts in your address book is not a major reason why worms propogate so frequently. I can write a perl script to extract the details from Pine or most other UNIX mail programs just as easily - the actual problem is getting the virus launched on the victims PC in the first place.
      --
      Avantslash - View Slashdot cleanly on your mobile phone.
  10. To be honest... by traskjd · · Score: 5, Insightful

    I can't really see how it's microsofts fault. Reading about it, it comes in a zip file, the user has to get the zip, extract it and then execute the payload.

    Is it just me or is this more like social engineering than a real problem with the system?

  11. In other news by Eric(b0mb)Dennis · · Score: 5, Insightful

    "Linux and Mac users are immune."

    If you were writing a virus and wanted to do some harm, why would you even bother trying to infect mac and linux users?

    I mean, people make a big deal on "windows is so insecure that's why this happens blah blah".. but in reality it's just because it's so much more popular...

    Not that windows isn't insecure and not that microsoft isn't an evilbad company et cetera.. just wanted to make that point..

    "Mac and Linux users are immune"

    I want to see a really intuitive and effective worm for OS X... all these mac users thinking they are immune.. it could be a problem.. (More likely to click on attatchments) Not that it would make a big impact :)

    --
    Excuse me, I don't mean to impose, but I am the ocean
  12. Another story dupe? by Anonymous Coward · · Score: 5, Funny

    Wasn't there just a Windows worm story last week?

  13. Using Internet Traffic Data to Predict Worms? by GillBates0 · · Score: 5, Informative
    Companies like ISS use "probes" at many locations around the world to detect unusual patterns on key Internet backbones. A persisting unusual pattern is a supposed to be a pretty reliable indicator of malicious activity.

    I have been trying to do my own retrospective predection :) based on the data available at Internet Traffic Report

    As far as I can make out, all the US routers are doing fine (green). The response time seems to have gone up a tad at 2am MST, but other than that I don't see anything unusual.

    When I look at Asia, 5 out of the 21 routers are down (red) and the packet loss is up 2%. Does that mean, that the worm has hit Asia hard? I know this worm should clog up mainly mail servers, but I wonder how feasible it is to predict worm arrival/origin/etc based on this easily available information, assuming ofcourse that it's available realtime.

    --
    An Indian-American Hindu committed to non-violent thought/speech/action alarmed by the global explosion of radical Islam
  14. Postfix MTA Check For Sobig.E by Anonymous Coward · · Score: 5, Informative
    The following PCRE expression in a Postfix MTA header_checks (or, if you're using them, mime_header_checks) file will reject this one:

    /^Content-(Disposition|Type):\s+.*?(file)?name="?. *?(your_details|application|document|screensaver|m ovie)\.zip/ REJECT

    Requires Postfix be built with PCRE support and is for Postfix 2.x versions. For Postfix 1.x versions you'll have to put that in body_checks.

    Disclaimer: Use at your own risk. I *believe* this'll work, but, strangely enough, I haven't received any to be rejected yet!

  15. MOD PARENT UP + read my insightful comments ;-) by fmaxwell · · Score: 5, Funny

    As the parent poster said, a malicious person trying to do maximum damage would write for Windows. The Mac is the next best choice because, like Windows, you don't have big binary compatability problems.

    Linux is tougher to write this kind of thing for because it would require that the user perform so many steps. First the user would have to extract the tar file from the gzip file. Then he would have to expand the tar archive onto his hard drive, which would put the source there. Then the user would cd to the location where the source extracted. Then he would probably have to set various environment variables. Then he would have to run gmake. Then he would need to interpret the error messages to determine why the build didn't work. Then he would have to find and add various development tools and libraries to his system, adding any environment variables that they needed. Then he could try building again. When he finally got the build to work, he could then run the resulting executable, which would tell him to to type "man {trojan/worm name}. The man page would show various command line switches for specifying the e-mail client being used and various network options. Then the user would construct the proper command line to run the program and WHAM! Just like that, his system is infected.

    I may have left out a few steps or so, but you get the idea...

  16. Re:email will soon be rendered useless ? by CrazyWingman · · Score: 5, Insightful

    Dammit - stop attaching files in the first place. Instead, post them somewhere (your webpage, personal FTP server, AIM, friggin' windoze network, etc.), and then send a link. It's much nicer - the person on the other end doesn't have to worry about waiting for a long download, and you won't have to worry about your e-mail getting filtered.

  17. A couple of small nits by FreeUser · · Score: 5, Insightful

    1. There are far less Mac's out there in the world than PC's with Windows on them. Therefore when you're writing a worm which has the sole goal of infecting as many people as possible (which is what writers aim for these days) then you go for the majority.

    This argument is a myth, and has been used by Microsofties to try and downplay the vastly superior security of both *BSD and GNU/Linux. Mac OS X is a FreeBSD derivative in many respects, and vastly better designed from the ground up than Microsoft windows, for whom things like networking and security were afterthoughts cobbled together in an ad-hoc frenzy of featuritis and catch-up. Such an ad-hoc approach to design will never yield acceptable security, as Microsoft's shoddy products have demonstrated so dramatically in recent years, time and time again...and once again today, with this irritating worm.

    Why is the numerical argument a myth? Because the truth is that, on the internet backbone, more than half the servers are a variant of Linux, *BSD, or Unix. And servers are the real prize for system crackers looking to take control of a system or cause significant harm. Yet these systems, which present a far more tempting target in terms of power and potential harm, and their derivatives (such as Mac OS X), remain unaffected by the plethora of worms that strike the internet. These worms are almost always exclusively Microsoft worms, affecting Microsoft operating systems exclusively. Not because there are more Microsoft desktops than anything else (for, once again, servers are the real prize, and most of them are not Microsoft), but because Microsoft's operating system design is so rife with security issues that it makes a profoundly easy target, and a decent chunk of servers can be affected with very little effort on the part of the malicious cracker.

    It isn't about numbers. It is about design, and everyone in the industry, with the exception of Microsoft, has taken security seriously and designed their systems appropriately.

    [Excellent examples of poor design by Microsoft leading to security issues removed for brevity]

    4. Generally there are far more tech savvy people using OS X or Linux than Windows who don't blindly open unknown attachments.


    This is true for GNU/Linux and *BSD. It isn't true for OS X (unless the knowledge to avoid Microsoft's shoddy products is considered being "tech savvy", an argument you could make that I wouldn't dispute, except to say that (a) I don't think that is what was meant and (b) most people understand something a little more comprehensive when defining someone as more "tech savvy", so while I might grant you that point on a technicality, I would dispute the implication). A lot of OS X users are as capable, and incapable, as their Microsoft using counterparts. They do click on unknown attachments, they do download plugins without a thought, etc. BUT, they have the good fortune of using a relatively secure and very well designed system, and are thus protected from their foolishness in ways Microsoft, even with its competition-destroying Palladium, will likely never achieve.

    Contratry to popular Slashdot belief, the fact that it's easy to get details of your contacts in your address book is not a major reason why worms propogate so frequently. I can write a perl script to extract the details from Pine or most other UNIX mail programs just as easily - the actual problem is getting the virus launched on the victims PC in the first place.

    Absolutely right. And as you describe so well, doing so is trivial on Microsoft systems, and difficult or impossible on virtually every other system.

    --
    The Future of Human Evolution: Autonomy
  18. Here is how I got infected yesterday... by StressGuy · · Score: 5, Interesting

    1) Had an e-mail from a ".mil" domain (forget the actual address)

    2) Having recently mailed some questions to some government research agencies, I assumed this was a response to one of them, so, I opened the e-mail (I use Mozilla).

    3) No message in the e-mail, just an attachment called "your_application.zip". This was a tad suspicious so I copied the file and scanned it with a corporate edition of Norton Anti-Virus last updated on June 18th.

    4) Virus scan came up clean so I opened the file. After seeing that it was only a ".pif" file, I started to get concerned, tried to edit the file by right-clicking and the edit option didn't show. At this point, I'm pretty sure it's a virus.

    5) Examined the header information from the e-mail and discoverd that it actually originated from another office computer and the "from" address was spoofed. Now, I'm all but certain it's a virus.

    6) Went to the Symantec website and, sure enough, the virus information is there along with notification that the patch was only available since June 25th.

    7) Downloaded their fix tool and checked all computers in our office for evidence of infection. Was able to clean them all.

    So, even though I was relatively careful, I was still able to get infected. Primarily because:

    a) The "From" address was an expected source.

    b) I do occasionally get legitimate e-mails that are only an attachment with no text.

    c) This particular virus was so new that my virus scanner was not sufficiently up to date.

    FYI, I guess...

    --
    A goal is a dream with a deadline