Slashdot Mirror


Lousy E-mail Filters Complicating Outlook Worms

Mar writes "FRISK Software founder Fridrik Skulason has issued an open letter in which he blames other anti-virus companies for much of the Sobig.F network load problems: 'If mail filters send out one message for every copy of Sobig.F received, they are in effect doubling the amount of traffic. This makes them a part of the problem, not a part of the solution.'"

100 of 461 comments (clear)

  1. But still less... by mindriot · · Score: 4, Interesting

    ...traffic than you'd have if the worm got to its target and continued spreading.

    1. Re:But still less... by nacturation · · Score: 5, Insightful

      ...traffic than you'd have if the worm got to its target and continued spreading.

      That's a lousy argument for obvious poor behavior on the part of anti-virus software. It's like saying every time the police catch a violent criminal, they should kick the ass of some random citizen. Hey, it may be annoying, but it's still less violence than you'd have if the criminal got to their target and acted violently.

      --
      Want to improve your Karma? Instead of "Post Anonymously", try the "Post Humously" option.
    2. Re:But still less... by Hayzeus · · Score: 2, Insightful

      That's beside the point. The problem isn't that the mail blocking is objectionable. It's the idiotic reply messages that worsen traffic problems. The email can be blocked with the stupid "warning" being returned to a forged address.

    3. Re:But still less... by American+AC+in+Paris · · Score: 5, Insightful
      ...traffic than you'd have if the worm got to its target and continued spreading.

      I'm still getting about 200-300 "You sent a message with SoBig.F! Patch your computer immediately!" every day.

      Trouble is, I'm on a Mac. I couldn't be infected with SoBig.F if I wanted to.*

      Further trouble is, SoBig.F spoofs the FROM: field, so these messages invariably go to everybody except the schmuck with the infected box.

      So no, these messages hurt far more than they help.

      [* Pedant filter: I suppose I could buy Virtual PC or somesuch and install a vulnerable version of Windows. That'd probably do the trick.]

      --

      Obliteracy: Words with explosions

    4. Re:But still less... by Anonymous Coward · · Score: 2, Informative

      The downside is that the lusers are protected but those who keep their system in shape and don't click on every attachment become victims and can't even do anything about it. After 30000 SoBig.F related messages you learn that it is nearly impossible to filter bounces. They come in all languages, with or without headers. Some mention the worm, others don't because they're just "user unknown" bounces. My system is clean. The 900+ wormmails per day were easily filtered, but I had to sort through more than 100 bounces a day. To me, the bounces where the real problem.

    5. Re:But still less... by gi-tux · · Score: 2, Insightful

      And on top of that, some of them return the virus with the message. Therefore, it you don't have virus protection (which is stupid) and your address is forged on one, you might get a copy and also get infected.

      There are people out there that don't understand that email addresses are easy to forge. I had two people last night a church services comment about me sending them a virus. I never check email with anything except Linux at home and even at that I have virus scanning on and working to make sure. I also received a few messages bounced by corporate systems that included the virus within the message they sent me, to "notify me that I was infected". Glad I wasn't on Windows.

      --
      I have no sig, does anyone have one to spare?
    6. Re:But still less... by mindriot · · Score: 4, Insightful

      Of course you're right. The bounces are becoming a problem because most new worm variants fake the From: header anyway. The question would be, what percentage of total SoBig.F-related traffic comes from bounces? It might, of course, be as high as 50% if every message sent is bounced; but Frisk didn't really point out how much the Bounce problem contributed to the general worm traffic.

      I'd be happy if bounces in SoBig-like cases were reduced, but I find it a weak argument to blame the worm problem on anti-virus software without giving numbers of how much bounces actually added to the problem. (Well, it's another anti-virus software producer writing this statement, so this open letter could be considered a PR statement to some extent.)

      Somehow this also reminds me of those stupid Windows firewall products that by default alert you of every single stupid network packet...

    7. Re:But still less... by arivanov · · Score: 4, Insightful

      It is well known that the Sobig.F and many other viruses forge the sender address. These viruses are identified by the relevant filter product.

      Then, why on earth do you send a notification to an address that is known to be forged?

      The answer is simple - free advertising payed with your and my money. It is not stupidity. It is malice. An outright form of advertising a product by SPAM. I think that any Washington (or other state with antispam laws) resident should sue them for this.

      --
      Baker's Law: Misery no longer loves company. Nowadays it insists on it
      http://www.sigsegv.cx/
    8. Re:But still less... by gl4ss · · Score: 2, Insightful

      it's just utterly stupid from the companies making the software, for crying out loud, most of the programs can tell about sobig.f that it forges it's address(have a flag for it in their virus db, so it wouldn't be much of a chore to add it to NOT send warning email to that forged address)!

      but i guess it's just a nice feature some phb's think that is cool.

      --
      world was created 5 seconds before this post as it is.
    9. Re:But still less... by mph · · Score: 4, Insightful
      Further trouble is, SoBig.F spoofs the FROM: field, so these messages invariably go to everybody except the schmuck with the infected box.
      Yeah, I got tons of those Virus Warnings. I haven't run Windows, or any MS software, since 1995.

      The worst part of it is that the antivirus software sending these messages knows that it's SoBig.F. Thus, it should also know that the virus forges the From: header, and that it's pointless to send out the warning message to that address.

      So thanks, antivirus programmers. Thanks for wasting my time instead of doing your job correctly. How long would have taken to add an extra if(){} to your code, and another boolean field to your virus database?

    10. Re:But still less... by John+Miles · · Score: 4, Insightful

      And on top of that, some of them return the virus with the message. Therefore, it you don't have virus protection (which is stupid) and your address is forged on one, you might get a copy and also get infected.

      <rant>

      That's what utterly astonished me during the recent SoBig.F infestation. When an undelivered mail message with an attachment bounces, the mail servers return not just the subject line, or the message text, but the attachment to the putative sender.

      Were the architects of the common Internet mail utilities just plain stupid? What other conclusion can possibly be drawn? Who taught these epsilon-minus lackwits to use a computer, and why? What else am I supposed to think when a mail gateway or server is designed to bounce hundreds of kilobytes worth of attached junk to someone who, by definition, already has the data (since, after all, it's not as if he or she is the one who fucking sent it the first place)? And when it's designed to do so via an untrustworthy return address courtesy of the nullwits who designed the SMTP protocol, no less?

      It is WAY past time to scrap the Internet's existing email infrastructure in favor of something designed by actual engineers. What we have now is a giant, virtual Petri dish better suited for the cultivation of worms, viruses and spam than for communication between legitimate users.

      </rant>

      --
      Dahlmann tightly grips the knife, which he may have no idea how to use, and steps out into the plain.
    11. Re:But still less... by Lars+T. · · Score: 3, Funny

      Since many even return the offending atachment - they are knowingly spreading the virus. Which makes them terrorists.

      --

      Lars T.

      To the guy who modded me down from perfect to terrible Karma - Apple haters still suck

    12. Re:But still less... by LiquidCoooled · · Score: 2, Interesting

      Shouldn't it be handled one step further upstream - ie when the mail is being transmitted initially.
      In the same way that the server indicates error messages regarding destination addresses or transmission errors etc, couldnt the virus checker scan the data at that point, and only allow the data in if its clean?

      --
      liqbase :: faster than paper
    13. Re:But still less... by pboulang · · Score: 2, Insightful
      Who are terrorists? The AV companies or the people that don't know how to configure the software?

      Terrorism has INTENT. The behavior you are referring to I think may be better classified as sociopathic.

      I am only offended by that comment by today's date. I'm sure I will get over it tomorrow.

      --

      This comment is guaranteed*

      *not guaranteed

    14. Re:But still less... by dspfreak · · Score: 2, Insightful
      About as long as it took you to write that comment. Hmmm, too bad that stuff isn't open source, or it would be fixed by now.

      --
      "Tolerance is the virtue of the man without convictions." -- G. K. Chesterton
    15. Re:But still less... by isomeme · · Score: 4, Insightful

      It can actually exceed 50% in some scenarios. For example:

      1. Trojan fakes from address of 'joe@foo.com', sends email to 'sue@bar.com' with infected attachment.

      2. Filter at 'bar.com' detects infected attachment, sends rejection email from 'sue@bar.com' to 'joe@foo.com'.

      3. It turns out that 'joe@foo.com' is no longer a valid address. 'foo.com' mail agent sends a delivery failure email to 'sue@bar.com'.

      Thus we get two pointless administrative emails generated by a single infected email.

      I am seeing this happening quite commonly, by the way.

      --
      When all you have is a hammer, everything looks like a skull.
    16. Re:But still less... by AKnightCowboy · · Score: 4, Funny
      Were the architects of the common Internet mail utilities just plain stupid? What other conclusion can possibly be drawn? Who taught these epsilon-minus lackwits to use a computer, and why?

      Why don't you go ask him:

      SIMPLE MAIL TRANSFER PROTOCOL
      Jonathan B. Postel
      August 1982
      Information Sciences Institute
      University of Southern California
      4676 Admiralty Way
      Marina del Rey, California 90291
      (213) 822-1511

      I'm sure many of us would love it if you met up with him and had a spirited debate about the issue very soon.

      Did you ever stop to think that many of the Internet's protocols were designed when there were no fuckwits running operating systems that are a virtual "petri dish" for viruses and worms?

    17. Re:But still less... by LiquidCoooled · · Score: 3, Interesting

      I would not want to ban based upon email address, there would be no way to identify the fake from the real.
      No, the AV companies need to start working on an effecient mailserver (or simply hook into the existing ones), and prevent sucessful transmission of viral contents.

      Because it would be on an upstream server away from the users, Virus definition files will be updated quicker, and protection will be automatic.

      The problem then becomes one of localised ISP traffic only, and this can be cured by the ISP themselves. Another benfit of this, the ISP can send a single "You are infected" mail to the Account holder of the source IP.
      For Unknown IP addresses - simply block relay access :)

      --
      liqbase :: faster than paper
    18. Re:But still less... by John+Miles · · Score: 2, Interesting

      Did you ever stop to think that many of the Internet's protocols were designed when there were no fuckwits running operating systems that are a virtual "petri dish" for viruses and worms?

      (Shrug) Bad engineering is bad engineering. Postel's accomplishments were legion, but in the email department, he and his colleagues dropped the ball big-time. There's just no room to defend the decisions that were made.

      The minute the Internet showed signs of growing out of the obscure DARPA-funded labs where it was born, the engineers should have started paying attention to security and authentication issues. It would not exactly have been hard to fix SMTP by disallowing open relays and including a trivial sender-authentication mechanism to prevent forged headers, but now it's probably too late. A couple dozen lines of C code written between coffee breaks at USC would have made all the difference.

      That being said, the bouncing-attachment idiocy most likely has more to do with the default configurations of popular server-side virus filter packages than with anything Postel was involved with. The common denominator is that people with a great deal of responsibility in the Internet engineering field seemed to have taken leave of their senses at a few critical junctures with no one around to say "Hey, wait, maybe that's not a smart thing to do."

      --
      Dahlmann tightly grips the knife, which he may have no idea how to use, and steps out into the plain.
    19. Re:But still less... by SSpade · · Score: 2, Interesting

      So thanks, antivirus programmers. Thanks for wasting my time instead of doing your job correctly. How long would have taken to add an extra if(){} to your code, and another boolean field to your virus database?

      They are doing their job correctly. They're using spam (email? check. bulk? check. unsolicited? check. heck, commercial? check) to advertise their virus filtering products.

      They're violating various state anti-spam laws, so there's one obvious way to encourage them to stop spamming.

    20. Re:But still less... by isomeme · · Score: 2, Informative

      Good post, overall, but I have to object to your phrase "the nullwits who designed the SMTP protocol". SMTP was designed at a time when the nascent internet was more or less a research preserve, all users of which were cooperative and well-intentioned. SMTP uses what I call "Moria security", for reasons which will be obvious to Tolkien fans.

      SMTP lacks meaningful authentication features for the same reasons that TCP/IP lacks such features; they weren't needed at the time, and better to get something working out there and doing good than to sit on it while you build in design features that might possibly someday become useful.

      A dirt path is a perfectly useful way for a few hikers to climb a hill. When a stream of passenger cars start using that path and a few of them lose their oil pans, don't blame the people who created the path.

      --
      When all you have is a hammer, everything looks like a skull.
  2. Stupid Bounce by crayiii · · Score: 3, Redundant

    After so many viri's that fake return to headers it's stupid to continue responding to them. No I didn't read the article...

  3. Yes, virus bounces suck by Anonymous Coward · · Score: 3, Insightful

    The email bounce is nearly dead now. Between spam and viruses faking the from and reply-to headers, it's become almost a menace. I got nearly as many bounces as I did sobig messages.

    1. Re:Yes, virus bounces suck by i.r.id10t · · Score: 2, Insightful

      I actually got more bounce messages than sobigs... 10 messages saying sobig spoofed my addy as the sender, and no sobigs (we got good email admins here).

      --
      Don't blame me, I voted for Kodos
    2. Re:Yes, virus bounces suck by realdpk · · Score: 4, Insightful

      The bounces from the anti-virus software programs is pretty damned close to spam. Close enough that it gets their name out there, but not close enough that they'd actually be pinned about it except by the most self-righteous of the anti-spammers.

    3. Re:Yes, virus bounces suck by Xzzy · · Score: 4, Funny

      I must have really smart friends, because I didn't get a single bounce! /preen

      Or maybe I just have no friends. /sigh

    4. Re:Yes, virus bounces suck by i.r.id10t · · Score: 2, Funny

      Same boat... do I get happy because no one is sending the virus to me, or do I get depressed because I'm not in anyones contact list?

      --
      Don't blame me, I voted for Kodos
    5. Re:Yes, virus bounces suck by Jucius+Maximus · · Score: 2, Insightful
      "The email bounce is nearly dead now. Between spam and viruses faking the from and reply-to headers, it's become almost a menace. I got nearly as many bounces as I did sobig messages."

      On my main account, I got exactly 0 sobig bounces and 0 actual sobig messages. This applies for all versions of sobig. (Only the competent get access to my real address.)

      On my main 'spam address' however, it got about a 10:1 ratio of bounces to sobig messages. I guess a lot of spammers got infected and since they have a lot of e-mail addresses for spam purposes on their systems, a number of sobig messages went out with my address on them.

    6. Re:Yes, virus bounces suck by AnotherBlackHat · · Score: 3, Insightful

      The bounces from the anti-virus software programs is pretty damned close to spam.


      Not just close - they meet most of the definitions of "spam" that I've heard;

      They're excessive unwanted emails.

      They're unsolicited bulk.

      They're mass mailings from a stranger.

      They're sent without consent.

      They're commerical (they're an ad for the anti-virus software that sends them.)

      -- this is not a .sig

  4. How come we even get them? by TerryAtWork · · Score: 4, Interesting

    This is completely stoppable at the ISP level. I received over 1,000 SoBig.F messages, not one of which had to go through!

    --
    It's Christmas everyday with BitTorrent.
    1. Re:How come we even get them? by ConceptJunkie · · Score: 2, Interesting

      My ISP offers Postini, which is a pretty decent spam filter, for free. Therefore the 20,000 or so SoBig virus and related crap got stopped before it reached the mail server.

      Of course, the folks at Postini have failed to take Microsoft's abysmal software into account: You can view/delete quarantied spam up to 200 at a time, but viruses must be deleted 10 at a time. Thpthpthpthpthpptt!

      Microsoft: Creating the most effective virus development tools for over 10 years!

      --
      You are in a maze of twisty little passages, all alike.
    2. Re:How come we even get them? by ajs · · Score: 2, Insightful

      1. The world isn't quite that authroitarian.
      2. Your desire to have people behave politely doesn't override the general need to have the Internet remain an open exchange of packets between peers.
      3. What's an ISP? What's a customer? Should UUNet filter mail coming from their peers? Should a University filter mail coming from its own dekstops? What about labs that have their own Internet presence, but are part of the University? What about multi-homed businesses?

      I get a slew of these messages, and I have to admit to not having the time to solve the problem, but it's easily solved, if a monumental social engineering problem.

      What you need to do is this: first, get everyone to agree that they need to use SMTP/TLS. Second, get everyone to agree to get a key that's signed by a CA. Notice I didn't say "ISPs" above... that's because not everyone relates to their upstream in the same way, and some people (big Universities for example) tend to peer with multiple providers.

      Once everyone has a CA-signed key for their TLS-only mail then we can kill this sort of thing, dead. You send spam, you get axed. You send spam from multiple certs owned by the same entity, that entity gets axed. You send spam from multiple certs owned by multiple entities with the same CA, that CA gets axed.

      Apply SpamAssassin-like weighting to this process (weighting each key and entity and CA based on frequency of good or bad mail) and you quickly evolve a system of personal and community reputation that lets us get back to business without hurting those who don't deserve to be hurt (e.g. you might use a bad CA and work for a bad company, but if your key is never used for spam, you will evolved a good reputation over time).

      The same is true of viruses, it's just slightly more important to track individual sender keys (which will reprsent homes, corporate divisions and whatever other units make sense for you to create a unique mail server) when it comes to viruses. Databases of keys will have to be huge, but they can be distributed on various useful boundaries in the same way as DNS (e.g. by CA and then by organization).

      We'll get there, it's just that the pain threshold has to increase to the point that we all nod our heads and say, "I'm shutting off non-TLS now".

      I already run TLS on my server, how about you?

    3. Re:How come we even get them? by lseltzer · · Score: 5, Interesting

      My latest column deals with this too. I got a lot of e-mail in response from ISPs talking about how it would be difficult/expensive to implement and that it would violate customer privacy. One said it would be a HIPAA violation. My own ISP (Speakeasy.net) virus-scans all e-mail that goes through their servers; is that a HIPAA violation? A lot of them are also scared of losing customers after offending them by blocking their outbound port 25 access, but does an ISP really want business from someone infected with Sobig?

      It is true that since Sobig uses its own SMTP server the ISP would have to do the monitoring via a port 25 monitor. I'm not completely sure how difficult/expensive this would be to implement on a large scale, but there's an opportunity for someone who comes up with a cheap solution. I suppose it could be part of a general IDS, but it needs to be something price-accessible to an ISP.

      Larry Seltzer
      Security Editor, eWEEK.com
      http://security.eweek.com/

    4. Re:How come we even get them? by nacturation · · Score: 3, Interesting

      It is true that since Sobig uses its own SMTP server the ISP would have to do the monitoring via a port 25 monitor. I'm not completely sure how difficult/expensive this would be to implement on a large scale, but there's an opportunity for someone who comes up with a cheap solution. I suppose it could be part of a general IDS, but it needs to be something price-accessible to an ISP.

      This is trivial. Allow for normal port 25 access to the ISP's email server (with the usual restrictions on volume and content) and, for external port 25 access, there's a number of possibilities:

      1. Allow the client to setup a pre-determined list of specific hosts they want to connect to. This might be done using a web-based interface.
      2. Only allow the first 10 hosts (per dialup connection, per DHCP lease, per hour, etc.) to be accessible via port 25. This should satisfy even power users as few need to check mail on over 10 different servers. Adjust number as appropriate.
      3. Setup a proxy service which allows unlimited port 25 access. Any viruses which include their own SMTP delivery engines won't know about the proxy and will simply fail. There's no additional security risk to using your ISP's proxy than using the ISP's connection itself, as both can be logged with equal ease.

      --
      Want to improve your Karma? Instead of "Post Anonymously", try the "Post Humously" option.
    5. Re:How come we even get them? by Tony-A · · Score: 2, Interesting

      Something I don't think I've seen addressed in coping with these things. Short-term versus long term. The tactics and priorities are quite different.
      Getting rid of all of them is a long-term process.
      In the short term, you want to stay operational with minimal colateral damage. While emergency training will certainly help, it's almost a certainty that what needs to be done is not covered in the book. Sophisticated tools could certainly help, but it seems to me that with TCPDUMP and a pair of eyes and almost no knowledge it would be obvious that something was going on plus a few clues as to what and from where. I suspect that the best bet for long-term survivability is to leave decisions at the point of crisis to the whim of whoever is manning the stuff at the time.
      One PC goes wild. Probably ignored since there's plenty of capacity to handle it.
      One PC goes wild and a large bunch of it neighbors do too. You do something to stop the flood. Probably catches a bit of legitimate stuff too. Then you look and see what's making the flood and refine your stuff a bit. After such as Slammer, I would rather see a mixed-up mess that gets the internet back operational in an hour than something carefully thought-out that gets it back in 24 hours.

  5. This is so true by blunte · · Score: 5, Funny

    Our Norton Exchange AV kicks out "we-saved-your-butt" emails to the admin, the original recip, and back at the "sender", who of course knows nothing about it since it was forged.

    I've just been creating more and more filters that send to trash with no notification to anyone.

    Of course, you have to pay attention when you first turn some of the capabilities on, as Norton kindly preset you to block AOL mail :) Serves AOL right...

    --
    .sigs are for post^Hers.
    1. Re:This is so true by toddestan · · Score: 4, Funny

      Maybe I should configure an autoresponder that responds to the message from Norton AV that tells the person how to turn off the autoresponse?

      *ducks*

    2. Re:This is so true by xanadu-xtroot.com · · Score: 3, Funny



      Must
      Consult
      Someone
      Else


      --
      I'm not a prophet or a stone-age man,
      I'm just a mortal with potential of a super man.
  6. How about a real email client or real rules? by TWX · · Score: 4, Insightful

    Do most users exchange executable files? How about just blocking them if they're executable... How about getting an email client that isn't known for it's ability to spread received infected email without the user having to even open the email?

    /been using pine since 1996...

    --
    Do not look into laser with remaining eye.
    1. Re:How about a real email client or real rules? by Elwood+P+Dowd · · Score: 3, Insightful

      There have been semi-successful email viruses where the user had to download a .zip attachment, decompress, run the executable, and click "yes" to install.

      Sure, we can remove capabilities in order to increase safety, but with users like that... I'm really not sure what we should do. Authenticating the sender and receiver of all email would be a step.

      --

      There are no trails. There are no trees out here.
    2. Re:How about a real email client or real rules? by 1010011010 · · Score: 2, Informative
      --
      Napster-to-go says "Fill and refill your compatible MP3 player", which is a lie. It's not MP3. It's WMA with DRM.
  7. Hallelujah! by PopeAlien · · Score: 4, Insightful

    Not only are they doubling traffic, they can help spread the virus.. I've recieved bounced email containing the virus, since the the return address is randomized this in effect helps to spread the virus. Why include the attachment in a bounce message?

  8. Re:Mod story -1 (Duh...) by blunte · · Score: 2, Insightful

    Duh it may be, but that's the default behavior for Norton's Exchange AV software.

    You have to fool around with it in a most confusing way to get it to stop doing that. Like all good Windows management interfaces, it's confusing and inconsistent. But I digress...

    --
    .sigs are for post^Hers.
  9. Letter contents incase of /.'ing by B5_geek · · Score: 3, Informative


    Why (some) anti-virus companies are to blame for the recent
    e-mail flood

    As everyone should now know, Sobig.F has generated a tremendous amount of e-mail traffic world-wide. However, part of the blame for this traffic should be placed on some of the anti-virus companies.

    What I am referring to is the large number of incorrectly configured mail filters that respond by sending a "virus alert" to the "From:" address. As Sobig.F falsifies the "From:" address, these e-mails just clutter up the mailboxes of innocent, non-infected people. These messages cause unnecessary annoyance and worry, as they typically (and incorrectly) claim that people have sent out a virus.

    When you get an e-mail, warning you of a Sobig.F infection, with a subject line similar to these:

    * *** detected and quarantined a virus in a message you sent.
    * Warning: E-mail viruses detected
    * Virus Detected by ***
    * This is an alert from ***

    it usually means that someone, somewhere has made a bad decision on how to react to infected mail, either by selecting a substandard product or by configuring it incorrectly.

    Worse yet, if mail filters send out one message for every copy of Sobig.F received, they are in effect doubling the amount of traffic. This makes them a part of the problem, not a part of the solution.

    The problem is that some commercial mail filters have this behaviour set as the default. At least one filter gives only two options: Always send a "virus alert" to the "From" address of every infected e-mail received or "pass the message through to the recipient". Clearly neither of these options are acceptable.

    I have only one word for this: Stupid!

    Acceptable behaviour would be one of the following:

    1. Have the mail filter properly distinguish between worms that falsify the "From:" address and ones that do not and only send a warning message when the "From:" address is likely to be genuine.

    2. Do not send the alerts at all.

    In fact, sending an alert automatically to the From: address for every virus or worm received by e-mail should not even be a selectable option.

    With Sobig.F scheduled to die out today, Sept. 10th, the problem might go away for a while - until the next similar worm appears. And this is the scary part. Sobig.F didn't really infect that many machines world-wide, maybe only 200.000 or so. This is only a fraction of the number of machines infected by Msblaster (Lovsan). Now imagine a worm combining the distribution method of Msblaster with the mass-mailing feature of Sobig.F. The flood of traffic might practically render the Internet unusable.

    Eventually, some virus author will create a virus like this, maybe this month, maybe in a few years, but it will happen. And when it does we do not need the anti-virus companies making a bad situation worse.

    I hope the "guilty" anti-virus producers will be updating their products in the near future, but this is not going to happen unless their customers request it.

    Fridrik Skulason ( frisk@f-prot.com )
    Founder of FRISK Software International

    --
    "The price good men pay for indifference to public affairs is to be ruled by evil men." ~Plato (427-347 BC)
  10. No doubt! by tbase · · Score: 4, Interesting

    If the e-mail filter is smart enough to know it's Sobig.F, why isn't it smart enough to know the "from" is spoofed?!?!?

    I set our filters to just delete anything with an executable attachment, but that didn't to crap for the stupid "Virus Detected" warnings.

    One guy was sending us about 150 copies a day, and the others his PC sent out with our address as the "from" resulted in about 50-75 Virus warnings a day - from the first day it popped up until it expired. I had his IP address, and called and e-mailed his ISP (Birch.net) a dozen or more times, and they did squat. 150 x ~100k x # of people in his address book - not to mention the undeliverables and virus warnings - and they did nothing.

    --

    666-607: 6th floor apartment of the beast
  11. Fuzzy Math by Akai · · Score: 4, Interesting

    The SoBig.(X) (all of 'em, been getting them for months, good thing Evolution doesn't care) are all around 100K a piece.

    A "your message was filtered" is maybe 2-3K including all headers (more likely under 1k), so responding to messages with Virus' in them adds 1-3% not 100% to the traffic.

    That being said, since most of the current generation of SoBig happily fake the "From" email address, a reply to the from address doesn't really help anyone either.

    So in the worst case scenario, a 3K reply to a fake email address results in a bounce message, so at the most you've got 5% overhead, and theoretically for that 6K of email, you've saved a user from getting infected, which would generate 100K*1000's of data.

    I'd say it's not too high a price to pay.

    --
    Please send all UCE to scally@devolution.com so I can f
    1. Re:Fuzzy Math by realdpk · · Score: 5, Insightful

      There's some flaws in the logic.

      First, there's a cost per message that you're not including. Every message I get I have to consider and read, or delete. I'm getting tons of virus bounces, even though I've never sent a virus - the virus uses forged headers. So, for me, someone who has no way to contract a virus, my "work"load has gone up noticably, and the price I pay went from $0 to $X where X is a positive number.

      Second, the autoresponder is not a necessary part of the virus removal. The savings is already there by blocking the virus from infecting the user's computer. The bounce is just an extra thing the anti-virus people put in to try to advertise their product.

      It's *pretty damn close* to being spam.

    2. Re:Fuzzy Math by Zak3056 · · Score: 2, Interesting

      A "your message was filtered" is maybe 2-3K including all headers (more likely under 1k), so responding to messages with Virus' in them adds 1-3% not 100% to the traffic.

      First off, disclaimer: My mail servers have been (until SoBig) configured to send "Hey, you sent us a virus" messages. We stopped this practice because SoBig is so damn prolific that it proved to us this was absolutely worthless and harmful.

      That said, there are some REALLY stupid people out there that not only bounce to the "sender," but are also kind enough to INCLUDE A COPY OF THE DAMN ATTACHMENT.

      These, ahem, "virus scanners" really DO increase the load by 100%, and worse yet, are actually SPREADING the virus!

      --
      What part of "shall not be infringed" is so hard to understand?
    3. Re:Fuzzy Math by MSG · · Score: 2, Informative

      A "your message was filtered" is maybe 2-3K including all headers (more likely under 1k), so responding to messages with Virus' in them adds 1-3% not 100% to the traffic.

      There are bigger problems than just the total amount of traffic. Lets say you run a domain that's in thousands and thousands of address books and Internet cache files... like "real.com". Now lets say that a multithreaded virus starts emailing itself as rapidly as possible to all of the addresses it can find... like SoBig.F.

      Care to guess what the result is? Something to the tune of 10,000 attempted connections PER MINUTE. That's way more than our mail servers are configured to accept (they're rate throttled). While load on the machines stayed acceptable due to their throttling incoming connections, access to port 25 was highly contended. People outside the company trying to send us mail obviously experienced delays. I can only imagine what was going on at better known domains.

      Here's the hitch: The overhead of accepting a connection is greater than the cost of the rest of the message. Judging by the messages that actually did get through, probably only 1000 connections per minute of the 10000 were the SoBig virus. The other 9000 were bounce notices from other systems. So, in our case the traffic increase wasn't 1-3%, and it wasn't 100%, it was 900%. There's no good reason for it, either. Those bounce messages don't protect anyone from getting infected, they just waste bandwidth.

    4. Re:Fuzzy Math by Snowdog668 · · Score: 4, Interesting

      You'd be right and I wouldn't care if I only got the headers. Unfortunately about 95% of the bounce messages I've gotten contain the original attachment as well. Thank goodness I check that account on webmail so I didn't have to wait to download the messages over dial-up(stuck in the great broadband wasteland). It was easy to get rid of from my point of view because all I had to do was was go down the list and mark all the e-mails that were 100k for deletion and get rid of them. If I had to actually download each message over my dial-up account because some sysadmin decided to bounce the entire message I'd be seriously pissed.

      --
      I wouldn't say I'm a bad gambler but the last time I went to Vegas I even lost a buck on the soda machine.
  12. I completely agree by PktLoss · · Score: 4, Insightful

    One member of our software development team ended up receiving over 10,000messages/hour during our peak load, about equally split between virus messages, and bounce backs/mailer daemon messages. The latter weren't blocked by the standard anti-spam solution.

    The messages generally contain no usefull information, and are deleted without reading.

    Spam catchers should be combined with anti virus solutions, to ensure that authentic messages do generate some sort of response, either to the sender or receiving, informing them of the infection. The technologies would mesh well in this case.

  13. 5xx is the answer by hey · · Score: 3, Informative
  14. We've started to filter bounce messages. by Future+Man+3000 · · Score: 2, Interesting
    All the bounces from viruses and faked spam 'From:' headers amount to about 5% of our worthless inbox content, so we've just decided to filter the stuff for a while until either the viruses die down or we determine that we really need the bounce messages for some reason.

    It's pretty rare that an e-mail that we send out does not eventually get to its recipient, and in most cases the e-mail is in response to something so the recipient will let us know if they aren't getting a message from us, so this system has been working out well so far.

    --

    I never vote for anyone. I always vote against.
    -- W.C. Fields

  15. Doubling messages, not traffic by fadden · · Score: 2, Informative

    The SoBig.F virus message was much larger than a "we found a virus" letter, because it included a copy of the virus itself. The number of messages bouncing around may have doubled, but the total bandwidth required did not.

    However, as the recipient of 300+ messages a day, I for one would be delighted if the virus scanners had an option to Just Shut Up when they find a specific virus. While I don't believe the scanners aggravated the problem -- indeed, by reducing its transmission, they certainly improved matters -- the bogus reject messages were a highly visible and easily avoidable irritant.

  16. Good for this guy... by fuqqer · · Score: 5, Interesting

    I work in Tech support for a telecommunications company and I get at least three calls per day regarding a message from Norton Antivirus. The message falsely states that they were a sender of the sobig.f virus. Of course, our users are completely up to date with their virus software and our e-mail servers catch the sobig virus. A big shame on you to Norton for having an e-mail enabled warning like that. It preys on the stupidity of end users.

    Granted, if nobody talked about AIDS, the infection rate would probably skyrocket too. So is it better that there be a symptom of the virus such as increased network traffic. Or is it better to not inform external users and try to repair in house?

    Maybe it offers a little job security too though.

  17. It's viewed as promotion by mcrbids · · Score: 5, Interesting

    One of my clients is an ISP - and they *want* the bounces to go out for the simple reason that it broadcasts to the world that "your mail is safe with us".

    So the bounce messages go something like "Our mail server detected a virus in an email you appear to have sent, and we protected our customer ... For more information about our services come to --URL--"

    I don't know if it's effective at all, but it sure doesn't cost much - the virus notification is essentially a mild form of SPAM which few people really get up in arms about.

    Just to understand, there are market conditions behind those virus notices...

    --
    I have no problem with your religion until you decide it's reason to deprive others of the truth.
    1. Re:It's viewed as promotion by EvilBudMan · · Score: 2

      >>I don't know if it's effective at all, but it sure doesn't cost much - the virus notification is essentially a mild form of SPAM which few people really get up in arms about.

      We'll count me as one of the few. I think that Symantec and Network Associates should be counted as spammers now because of this.

      Spam is Spam. There ain't no mild form.

  18. Um... by Realistic_Dragon · · Score: 2, Insightful

    Wouldn't it be better to blame those resposible for Outlook for Outlook worms? (Be it users who fail to patch, admins to deploy it, Microsoft for writing it on one drunken weekend that involved a lot of monkey hookers and a boat load of cocaine.)

    It's certainly better than blaming a _client_ problem on the _network_ which when it was designed didn't anticipate (understandably) a near monoculture of such vunerable products being deployed.

    --
    Beep beep.
  19. Just got my hand slapped by Data Security by RobertB-DC · · Score: 4, Interesting

    I just got a call from the Data Security guy in my office. I've had run-ins with him before, because their scans of my PC would occasionally find that I run Eudora for my personal email rather than routing it through the corporate virus portal known as Outlook Express. My bosses have been supportive -- as long as I get my work done, who the heck cares what I've got installed?

    Now, I get 50-100 messages from "helpful" virus checkers telling me that I sent them a virus. Duh, of course I didn't. But what's worse is when they try to help my by sending the damned virus back to me! So my Eudora inbox fills up with viruses. No problem, I just delete them, right?

    But we've got real-time virus scanning installed, and the admins take a dim view of tweaking it to skip certain directories. It finds that In.mbx contains a virus and kills the file. Poof, there goes my Eudora inbox. Frustrating, but it was full of junk anyway.

    This morning, though, I get a call from the head Data Security honcho. Norton called mommy when it found the virus, and did it often enough for me to show up on the admin guy's radar again. Now, I'm going to have to quit using Eudora at work, just because brain-dead virus protection is sending me viruses! I'd fight it again, but I have to agree -- if I keep downloading viruses, I'm part of the problem.

    Thanks for nothing, AV companies. All you're doing is keeping yourselves in business with false virus alerts. Or maybe that was the "2. ???" in between "1. Spread Viruses" and "3. Profit!"

    --
    Stressed? Me? Of course not. Stress is what a rubber band feels before it breaks, silly.
  20. Not the problem by Spazmania · · Score: 2, Interesting

    The mail filters that send out a message for each virus message received are not the problem. Indeed, they're just following the basic requirements for bounced messages listed in RFC 2822.

    THE problem is the mail filters which also send a second message to postmaster@whatever domain. Whatever brainiac thought that one up should be shot.

    --
    Moderating "-1, Disagree" is simple censorship. Have the guts to post your opinion.
  21. Re:Outlook by Seth+Finklestein · · Score: 2, Insightful
    1. Low-level format lusers' hard drives.
    2. Install Linux.
    3. Save $900 per seat on annual licenses for operating system, office suite, and anti-virus software.
    4. Profit.
    --
    I'm not Seth Finkelstein. I still speak the truth.
  22. His two minutes by muffen · · Score: 3, Insightful

    I find this most interesting.

    Until recently, no e-mail worms spoofed the email address. F-Prot obviously never had the functionality of replying to infected emails.

    Until just recently, it was really good to reply to the sender alerting him about the fact that he sent out a virus/worm. Where was F-Prot back then??

    The way I see it, it's been three steps.
    Step 1: No email worms.
    Step 2: Email worms that didn't spoof the sender (replying to sender is good).
    Step 3: Email worms that spoof the sender (replying to sender is bad).

    Seems to me that F-Prot is complaining that everyone hasn't reached step 3 yet (with spoofed sender addresses, infected emails shouldn't be replied to), even though we pretty much reached it just now. Before Sobig, even though there were worms that spoofed the sender, they were a minority. After Sobig, spoofing worms are a majority, which means that AV products need to change. This won't happen in a second like it did for F-Prot, because most AV vendors didn't skip step 2 like F-Prot did.

    This coming from a company who 95% of computer users never heard, and who never even added the functionality of replying to emails even though it was really good until just recently, makes me believe his just looking for his two minutes of fame.

    1. Re:His two minutes by Juggler · · Score: 5, Informative
      Not true, most worms and viruses have spoofed the From address for quite a long time now.

      Autoreplies have always been problematic at best, which anyone who's experienced the annoyance caused by vacation programs on public mailing lists can attest to. Autoreplies to automatically generated traffic have always been a no-no.

      Viruses and worms are clearly autogenerated traffic.

      Also, although 95% of computer users have never heard of FRISK, Fridrik has been a respected member of the A/V community since it very began and wrote one of the very first virus scanners.

      Disclaimer: I work for FRISK, writing said e-mail filter code. But I can tell you with authority that the decision was taken a long time ago.

  23. Microsoft EULA Security Update enclosed: by Anonymous Coward · · Score: 4, Funny

    Critical Update:

    A security issue has been identified that could allow an attacker to compromise a computer running Microsoft Windows and install Linux on it. You can help protect your computer by installing this EULA from Microsoft. After you install this EULA, a NULL update will be downloaded for your benefit.

  24. Not doubling traffic. by Samurai+Cat! · · Score: 2, Insightful

    'If mail filters send out one message for every copy of Sobig.F received, they are in effect doubling the amount of traffic. This makes them a part of the problem, not a part of the solution.'

    Not quite. Fortunately the alert emails are (usually) just text, and not some several-kilobyte attachment. They may be doubling the messages, but certainly nowhere *near* the bandwidth used.

    One would hope the anti-virus tool folks could build in ways to sniff out "Oh, this is a SoBig-laden email" and *not* send out the completely useless alert to someone's address that happened to be the random "From" address used.

    --

    "People" using "unnecessary" quotes should be "shot".
  25. Matter of education and responsibility by stopbit · · Score: 2, Informative

    Until the anti-virus software developers, M$ and the general e-mail population can out-wit a 12 year old script kiddie, no progress will be made.

    --
    ~insert tech sarcasm here~
  26. Speaking of bad email filters... by Anonymous Coward · · Score: 4, Funny

    We have Mail Marshall here at work. I got the following mail from the system yesterday...

    MailMarshal (an automated content monitoring gateway) has stopped the following email for the following reason:

    It believes it may contain unacceptable language, or inappropriate material.

    Message: B000038072.00000001.mml
    From: xxx@xxx.com
    To: xxx@xxx.com
    Subject: Re: So Whuz Up?

    Please remove any inappropriate language and send it again.

    The blocked email will be automatically deleted after 5 days.

    MailMarshal Rule: Inbound Messages : Block Unacceptable Language Script Offensive Language (Basic) Triggered
    Expression: asshole Triggered 1 times weighting 5


    Email security by MailMarshal from Marshal Software.


    So the message tells both the ortiginal sender and I that it won't deliver the email because it contains the term "asshole". So it lets me know that by sending me an email telling me the exact same word that was supposed to be filtered? It seems like we've got a hypocrytical mail filter here :(

  27. Of course not. by SuiteSisterMary · · Score: 3, Interesting

    At no point should a response be generated for a virus. Maybe five years ago, when viruses tagged along with legitimate data, but nowadays, a virus generates it's own delivery system, and there's no point to a bounce.

    --
    Vintage computer games and RPG books available. Email me if you're interested.
  28. Challenge/response sucks by letxa2000 · · Score: 3, Interesting
    Yup, I agree that the whole idea of "bounce" has been killed by spam and by viruses.

    The statement "If mail filters send out one message for every copy of Sobig.F received, they are in effect doubling the amount of traffic. This makes them a part of the problem, not a part of the solution" is also what I've been saying for months. This is a condemnation of challenge/response. Challenge/response is flawed conceptually in that it assumes the return address is correct. In an age of spam (which it supposedly addresses) and viruses it is absurd to believe the return address exists and sending email to the return address just multiplies the problem.

    Challenge/response was never well thought out. It shifts the burden of spam filtering to the person that sends email to that user, and tends to mailbomb innocent users that happen to have their addresses forged by spam or viruses. All so someone can supposedly enjoy a spam-free existance with no thought to the hassle they are creating for others and the spam that they are creating by mailbombibf C/R challenges to forged addresses.

    Hopefully with much better filters already available Challenge/response will just disappear. It's bad technology.

  29. The response I got - it IS part of the problem by ctwxman · · Score: 5, Interesting

    I received hundreds of bouncebacks from one organization. So, I did a whois and wrote to the contact listed:
    My name is Geoff Fox and I am writing because I have received hundreds upon hundreds of message bounces from your **** mail server.
    These messages are not originating with me. These are SoBig virus generated and are spoofing my address as the return.
    I am asking nicely, but I need you to take action immediately. I am attaching a bounce message so you can see what I've received. From the headers it looks like they're actually coming from ***.com
    Sincerely, Geoff Fox

    I did get a response... but not what I had expected.

    Geoff, Thanks for raising the issue of the SoBig virus infection.
    From the information that you have provided, it does look like the infected machine is located at **** Architecs, Inc. of Harford, CT. Their contact information is provided below.
    Have your IT technical staff contact the admistrative contact or the technical contact below. They may not realize that they have a SoBig infected machine and that it needs to be cleaned.
    (whois stuff deleted)
    It was signed by their Director of IT Security.

    So, even at that level, he didn't realize he was doing something wrong... or that these bouncebacks came from him, not from the site that was infected. And, he felt it was my obligation to do something about it, not his!

  30. Re:Simple by klaxor · · Score: 2, Insightful

    This has already been implemented; for this reason, I can't send executable attachments to some of the people I know...

    I'm a programmer. I write games in my spare time. I really don't feel like mailing a floppy to everyone (friends and family) who might find my game interesting.

    Yeah, I understand that most executable attachments are probably viruses. However, this doesn't justify the intrusion on my freedom - I would expect a company to just delete virus emails, rather than a blanket rejection of something that could be a virus, but might be very important to the recipient.

  31. Here's what can be done. by Animats · · Score: 3, Insightful
    All autoresponders must start validating the "Received" chain, like SpamCop does. The open source community can help by packaging up a library to do just that, and putting it into any open source packages that generate mail responses. Writers who review programs should downgrade those that have autoresponders. I suggest the term "spamming autoresponder" be used for any program that replies to mail autonomously without checking the "Received" chain.

    Messages from known spamming autoresponders should be blocked by spam filters. A publicly available list of canned text appearing in messages from spamming autoresponders should be made available and placed into mail filters.

    That should deal with the problem.

    1. Re:Here's what can be done. by stevel · · Score: 2, Interesting

      I don't see how validating the received chain helps. That will detect forged headers, but not a forged From address, which is what the viruses do. There is no way to reliably detect a forged From address by looking at the headers.

      Consider - I, and a lot of you too, I'm sure - routinely send out e-mail with a From address that has a domain unrelated to that of the outgoing SMTP server we are using. How can you tell the difference between such messages and those forged by viruses?

  32. FYI Taco and Mar by Abm0raz · · Score: 5, Informative

    Lousy E-mail Filters Complicating Outlook Worms

    SoBig.F is not an Outlook worm. It is a Windows worm. It does not require Outlook to run. It has it's own built in MTA and grabs email addresses from cached webpages and local text files as well as the Outlook/Express address book.

    -Ab

    --
    Nothing fails quite like prayer.
  33. Virus autobounces are stupid by siskbc · · Score: 2, Insightful
    but I find it a weak argument to blame the worm problem on anti-virus software without giving numbers of how much bounces actually added to the problem

    I don't. Their contribution to the problem is only limited to their marketshare. Any antivirus can block the viruses - but using these idiots over better competitors results in how many *illions of extra messages? Not to mention the confusion it creates on behalf of less savvy recipients. How many people paid for tech service on their "infected" computers only to discover they were fine?

    Under any circumstances, I don't find this behavior acceptable.

    --

    -Looking for a job as a materials chemist or multivariat

    1. Re:Virus autobounces are stupid by pboulang · · Score: 2, Interesting
      It really isn't all that big of a deal. As said earlier, at MOST 1 email is generated. This effectively doubles the impact of something like SoBig. When looking at a virus that is spreading not linearly, but geometrically, this double-sized payload begins to have little total impact. We aren't talking MB of data, we're talking a couple KB per message.

      I suggest that at the very least, users get the message that there is something going on (even it it isn't there particular machine that is affected) and, knowing general users, they make admins aware: "What's this? Is this bad?!?" and anything to draw attention at the early stages of an outbreak (hmmm, maybe I should install patches) is a Good Thing(tm).

      --

      This comment is guaranteed*

      *not guaranteed

    2. Re:Virus autobounces are stupid by siskbc · · Score: 2, Insightful
      When looking at a virus that is spreading not linearly, but geometrically, this double-sized payload begins to have little total impact.

      Nope. Because the bounce rate is simply a linear factor of (market share of idiot AV vendor) * (virus propogation rage). So if the virus goes geometric, so does the bounce rate.

      We aren't talking MB of data, we're talking a couple KB per message.

      Remember the total overhead of sending a message as well.

      I suggest that at the very least, users get the message that there is something going on (even it it isn't there particular machine that is affected)

      That's *NOT* a good thing. If users get appropriate info, fine. But telling someone to upgrade when they could be just fine isn't good. People will start taking computers in for repair when they don't need them. Confusing people with constant virus warnings will make them blase about it and leave them with less information than they had before.

      is a Good Thing(tm).

      Like insider trading, Martha? ;)

      --

      -Looking for a job as a materials chemist or multivariat

    3. Re:Virus autobounces are stupid by pboulang · · Score: 2, Interesting
      When looking at a virus that is spreading not linearly, but geometrically, this double-sized payload begins to have little total impact.

      Nope. Because the bounce rate is simply a linear factor of (market share of idiot AV vendor) * (virus propogation rage). So if the virus goes geometric, so does the bounce rate.

      Gonna have to disagree with your conclusion. When you have x^y where x is the size/impact of a single letter and y is the branching factor (average number of recipients per message) than (x+1)^y isn't a great difference. You see what I am saying?

      I suggest that at the very least, users get the message that there is something going on (even it it isn't there particular machine that is affected)

      That's *NOT* a good thing. If users get appropriate info, fine. But telling someone to upgrade when they could be just fine isn't good. People will start taking computers in for repair when they don't need them. Confusing people with constant virus warnings will make them blase about it and leave them with less information than they had before.

      What does one do if they think they have a virus? If they are in a corporate environment, they ping the help desk (and that would be ONCE per person, regardless of the number of emails they get). If they are a home user, they make sure they have updated virus software. If they are clueless, then they will take it somewhere and get anti-virus software installed. which is what we really want. There is crappy software that is vulnerable, and if you run windows, you MUST run some kind of AV and update patches, etc. If they are confused or blase about having a virus, screw em. That is like keeping an open SPAM relay.
      --

      This comment is guaranteed*

      *not guaranteed

    4. Re:Virus autobounces are stupid by siskbc · · Score: 3, Insightful
      Gonna have to disagree with your conclusion. When you have x^y where x is the size/impact of a single letter and y is the branching factor (average number of recipients per message) than (x+1)^y isn't a great difference. You see what I am saying?

      No, the math's still off. If x is the so big rate, and y is the exponential propogation rate, and A is the AV copmany's market share (between 0 and 1), the rate of propogation of Sobig is x^y. The rate of propogation of bounces is A(x^y). So the propogation rate of sobig + bounces is (1+A)(x^y), not (x+1)^y. Actually, if I amended your math, it would be worse (your formula assumes that a bounce can be branched). There, it would be (x+Ax)^y. And that would be a phenomenal impact. The way you write the formula (x+1)^y, it assumes that only one bounce were ever sent. If that were the case, no one would worry. But it's not. And if you take the derivative of my amended version of your formula, which is the incremental impact per message sent, it increases exponentially too. Think about that. I can do the calculus too if you like. Either way, it's bad. At best the impact is a constant fraction of the sobig rate. At worst, they work together geometrically.

      What does one do if they think they have a virus? If they are in a corporate environment, they ping the help desk (and that would be ONCE per person, regardless of the number of emails they get).

      Yeah, and in a large environment of thousands of people, that's *exactly* what the help desk needs. Trust me, I know some of these people, and it's driving them nuts.

      If they are a home user, they make sure they have updated virus software. If they are clueless, then they will take it somewhere and get anti-virus software installed.

      And if they were already up-to-date, then they just paid money for nothing. And once they get up-to-date and know they're OK, and they keep getting messages, they learn to ignore them. So when another message comes out that they're not prepared for, they think they are.

      --

      -Looking for a job as a materials chemist or multivariat

    5. Re:Virus autobounces are stupid by John+Miles · · Score: 2, Insightful

      To clarify: those forged bounces are a major propagation vector for the virus, resulting in the aforementioned geometric nastiness.

      Bouncing mail with attachments intact is unimaginably dumb.

      --
      Dahlmann tightly grips the knife, which he may have no idea how to use, and steps out into the plain.
    6. Re:Virus autobounces are stupid by bedessen · · Score: 2, Insightful

      Only on slashdot would someone get moderated as interesting for saying that a phenominon that doubles the rate of junk emails is insignificant because the rate is already high to begin with.

      I don't care if it's growing linearly, exponentially, or factorially. Doubling it means twice as much crap for email administrators to deal with and is hardly "not all that big of a deal."

    7. Re:Virus autobounces are stupid by pboulang · · Score: 2, Interesting
      Gonna have to disagree with your conclusion. When you have x^y where x is the size/impact of a single letter and y is the branching factor (average number of recipients per message) than (x+1)^y isn't a great difference. You see what I am saying?

      No, the math's still off. If x is the so big rate,

      Ok, your hypothetical is wrong, not what I was saying. X is the impact or cost of a single sobig email. This is how much? 600k? if for EACH sobig email X there is a "random" message saying "You sent spam" which cost about 2k, the total impact is X + epsilon which I indicated as 1, a small constant. Instead of 600K it is 602K. Please note that I am not even going to bother figuring in the cost of building/tearing down TCP/IP etc as you aren't concerned when one big image is split into multiple images on a web page are you?

      I think we need to look only at the normal case where for every sobig message sent that is "caught" an email is sent out. What I really wanted to point out wasn't when a bounce message is infectios (cause I agree wholeheartedly that sending that "back" infectable is dumb) but the case where a legitimate attempt to say "hey, there's and issue" is a couple KB is attempted.

      What does one do if they think they have a virus? If they are in a corporate environment, they ping the help desk (and that would be ONCE per person, regardless of the number of emails they get).

      Yeah, and in a large environment of thousands of people, that's *exactly* what the help desk needs. Trust me, I know some of these people, and it's driving them nuts.

      It is the JOB of people manning a help desk to correctly educate the users. It takes me as an outside consultant about 1 minute to explain it for even the dumbest users and nobody would run more than 50:1 user:hd ratio. A major virus breaks out, the phone is tied up for an hour. That is COMPLETELY acceptable.

      If they are a home user, they make sure they have updated virus software. If they are clueless, then they will take it somewhere and get anti-virus software installed.

      And if they were already up-to-date, then they just paid money for nothing. And once they get up-to-date and know they're OK, and they keep getting messages, they learn to ignore them. So when another message comes out that they're not prepared for, they think they are.

      Updating your virus software costs nothing. And if you need to pay because you don't have it, then are you saying that people should NOT have the latest AV SW?

      Yes, they don't understand when 50 emails come in saying they have a virus when they really don't... but they need to be responsible for finding out what this SoBig thing is, and every search engine and geek cousin or hired help knows.

      --

      This comment is guaranteed*

      *not guaranteed

  34. Troublesome? Yes, but necessary ... by ElektroHolunder · · Score: 4, Interesting

    I am currently looking into antivirus solutions for our company mailserver, and originally thought about disabling the bounce messages.

    But unfortunately it seems that it could be illegal in Germany to intercept a message without notifying the sender. As far as I understand it, eMail seems to be subject to the same regulations as snail mail here, so dropping the message silently could constitute a legal hazard ..

    1. Re:Troublesome? Yes, but necessary ... by Juggler · · Score: 2, Interesting
      In many countries it is illegal to for a communications carrier to drop messages (e.g. e-mail) without notifying someone. However, you can generally choose between notifing the sender and notifying the recipient.

      Notifying the recipient is the only technically "safe" course of action, since everything else may be forged and sending mail to it could be increasing the magnitude of the problem.

      If the recipient then requests that you discard all such warning messages for him, then that's probably also legal - so it boils down to how you word the contract with the recipient.

      I don't think law is really a practical obstacle in such cases. Additionally, in some countries in Europe (not sure about Germany) ISPs are granted specific permission to take steps to protect the network infrastructure from attacks, and virus outbreaks definately a form of attack.

      Disclaimer: I work for FRISK on e-mail filtering, but I'm not a lawyer. :-)

    2. Re:Troublesome? Yes, but necessary ... by ovidus+naso · · Score: 2, Insightful
      Solution: block it before the end of the SMTP exchange.

      Accept the email then scan it and notify concerned parties -> BAD.

      Refuse the message by giving an SMTP 5xx error instead of a 250 after the DATA part -> GOOD.

      Personnaly, I like the exim+exiscan combo.

      --
      ---------- ovidius naso
  35. Message Headers should be Compulsory by gvc · · Score: 5, Insightful

    Last year, my wife received a spate of "you sent this virus" messages. Worse, a number of her associates received "this person tried to send you a virus" message, referring to her.

    I followed up with several of the administrators running the virus filters. In all cases, the administrators had quarantined the messages without headers so it was impossible to tell what machine really sent the message. I would have liked to know this information so as to have some hope of tracing the owner of the infected machine.

    I understand why users are unaware of headers. Microsoft's products go out of their way to hide them. In Outlook Express, to get headers you have to find the relevant show headers pull-down and even then the headers appear in a too-small non-resizable window. You have to clip the contents and paste into a real window before the headers can be read/forwarded.

    The "From:" field of email means no more than the snail-mail return address that you scribble on an envelope. The header, like the snail-mail postmark, tells the origin.

    What is the excuse for vendors of email software (filtering or end-user) perpetrating unawareness of this basic property of email?

  36. Re: Forged From: viruses by frankie · · Score: 4, Informative
    Until recently, no e-mail worms spoofed the email address

    What is your definition of "recently"? Apparently it's about two years.

  37. an Idea by linuxislandsucks · · Score: 2, Interesting

    why not have the filter do a whois on the ip of sender and send the warning to the admin of that net block?

    seems like abetter solution as it gets the virus warning in hands of the person that can do soemthing about it rather than sent to people who have no virus on their systems..

    comeon how hard is it to parse the record gotten back from a whois query?

    --
    Don't Tread on OpenSource
  38. amavisd-new doesn't send mail for Sobig, others by ddkilzer · · Score: 2, Informative

    Later versions of the amavisd-new mail scanner don't send mail to sender addresses from virii/worms that forge mail headers, even if you have it configured to do so.

  39. Most Email antivirus solutions are just plain dumb by codeguy007 · · Score: 2, Interesting

    I remember the day that SoBig.F reared it's ugly head. I can into work and must have had 40-50 emails claiming I sent a virus to some person I have never heard of. It was so many I actually figured I better check and make sure I didn't have the virus.

    Even worse 1 in 4 of the messages sent the virus to me in the message bounce.

    But in reality antivirus software is playing a losing game, it tries to get out virus definitions to protect systems after the virus has been released. Not only that the viruses have much faster distribution rate than the definitions so it's a loosing battle. We need a new solution.

    I propose that we should call for a ban of Microsoft Lookout. In its short existence, it has become the most insecure piece of software every written -- surpassing Bind, Sendmail and even Wuftpd, programs much older than it.

    While we are at it lets call for banning direct access to the internet for all windows based systems. Let's face it. If you put a windows box bare on the net, eventually it is going to be compromised. Windows wasn't originally designed to work on the internet and Microsoft has shoehorned in the internet support without proper security measures taken.

    You can't rely on end users who are too afraid to install there own OS to properly secure and update the machine. Someone needs to do that for them and frankly Microsoft doesn't.

  40. No-IP.com did it right by splitretina · · Score: 2, Interesting

    I use No-IP.com. Within a few hours of the worm spreading they had turned off bounce notifications of virus messages. I received a total of 10 SoBig worm notifications messages, and none of the actual worm.

    I think it's up to the ISP administrators to stay up to date with what is going on and to stop these sort of things in their tracks. That is why I get my email through a third party: so I don't have to deal with the bull. They have a responsiblity to their customers. I think No-IP did a great job living up to that responsibility.

    Frisk has been around for a long time, I used f-prot in DOS. But I think the letter he wrote is definitely a marketing ploy. They have recently updated their site to a more modern interface and it seems they are attempting to make some kind of mainstream market pull. I have the f-prot trial on my work windows xp box and honestly, it's pretty good. Fast and stable and less intrusive than Norton AV. So it might be good for it to work out for them.

  41. What I Think by Matty_ · · Score: 3, Informative

    I administrate a mail server with around 550 accounts on it. We got slammed by Sobig.F and eventually had to block it using header_checks in Postfix.

    This won't catch every virus-infected file attachment (like Word macro viruses), but the regex I put in place will block files with certain file extensions (e.g. pif, exe, etc.) What's nice is that the mail is rejected during the SMTP transaction and produces no residual mail traffic since the sending mail server is the worm's SMTP engine.

    So, for anyone using Postfix 2 who would like to stop most e-mail worms, using header_checks to scan MIME headers is a very effective way to protect your customers/users.

  42. Re:The need for digital signatures. by Zigg · · Score: 3, Insightful

    Does anyone see any arguments against digitally signed mail, besides the large over-head of layering security onto a system that started w/o any, by design?

    The fact that the private keys are going to be stored on PCs owned by people who don't grok public/private key care one bit. Not to mention that a new worm should have no trouble lifting those keys off the box and spraying them around for a new forge attack.

  43. Cry me a river by maggard · · Score: 4, Insightful
    I just got a call from the Data Security guy in my office. I've had run-ins with him before, because their scans of my PC would occasionally find that I run Eudora for my personal email rather than routing it through the corporate virus portal known as Outlook Express.
    You on the clock? In the company office? Using company hardware? On an account with access to material the company would probably rather not get corrupted, infected, or randomly sent out to strangers?

    Uh huh.

    So you wanna read your personal email at the office. Fine if your company supports that.

    But then you just absolutely positively gotta use only your favorite email client, not the one already installed, not a web portal. The email client now installed by you, presumably licensed to you, that is not owned or supported by IS. The one that makes IS's day that much tougher by throwing one more ingredient into the stew that is the company's desktop computer.

    Now on top if it your personal email client reading your personal email is bringing in viruses to the company. Onto that corporate PC logged into the corporate network. And dammit those nasty folks in IS aren't willing to spend their time making exceptions to the virus scanning so your unique-in-the-company personal email client reading your personal, virus-infected email is exempted.

    Cry me a river.

    --
    I don't read ACs: If a post isn't worth so much as a nom de plume to its author then I wont bother either.
  44. Not lousy, just misconfigured by onecrazyfoo · · Score: 3, Informative

    I would imagine that most of the virus scanners for mail servers out there can be configured to not send out the notification to the forged From address. The virus scanner I am familiar with - RAV, has this capability. I had ours configured to send out the notification until Klez and other viruses made it a worthless endeavour. Unless of course you are an ISP that has no qualms about using the opportunity to advertise.

    It would be nice if GeCAD would rewrite their software to stop the notice from being sent when the virus is Klez, Sobig, etc. But since GeCAD got bought out by Microsoft who will be discontinuing their product line, I know that will never happen. Hopefully someone else like Sophos will.

  45. Re:Bounces are good, just not for Sobig.F by pe1chl · · Score: 2, Insightful

    Warning messages to the sender were good some time ago, but should be removed from any scanner now.

    ALL "modern" viruses fake the return address.

  46. Re:Nice try, but .... by 90XDoubleSide · · Score: 3, Interesting

    The real answer is that virus definition files should have a flag that is set for viruses that always use forged addresses that tells the antivirus never to send an email in reply to that virus.

    --
    "Reality is just a convenient measure of complexity" -Alvy Ray Smith
  47. What if it's not a virus? by ananiasanom · · Score: 2, Insightful

    I'm as annoyed by this as anybody. I've received hundreds of "rejects", far more than actual copies of the virus.

    But people seem to be forgetting one thing: anti-virus software has false positives

    If anti-virus software eats infected emails without bouncing them, then it will eat some real emails without bouncing them either. This is very bad, as the sender doesn't know his email hasn't been received.

    I don't know the solution. The assumption that once you send an email it will get to its destination is eroding anyway, due to over-zealous anti-spam systems operated by people who think that setting them to reject all emails is a good way of making a point. DSN is becoming more widespread, though God knows what problems that might cause for us if it becomes the norm.

  48. Big O by maestro156 · · Score: 2, Informative

    Examine the Computer Science principle of Big O.

    If you have an exponential function any constant multiplier or addition is thrown out of the equation as unimportant.

    O(2n) = O(n + k) = O(n)

    and so
    O((2x)^y) = O(x^y)

    The point is that the exponent is so important as to nullify the constant multiplier.

  49. I get about 1000+ virus bounces a day by Schwern · · Score: 2, Interesting

    I don't think I've gotten a single SoBig virus. Either they're not getting sent or something upstream is blocking them.

    OTOH, I get about 1000+ pieces of virus related junk. Its exceeded spam. About half is anti-virus software telling me they blocked a virus. The other half is various bounce messages and autoresponders from viruses going out to addresses that no longer exist or to list admin addresses, lists that require verification, etc... with my email address.

    How many legit pieces of email do I get a day? 100-200 maybe.

    The situation is absurd. If your email address is widely available (in my case, in the Perl documentation) you'll get clobbered. I had to franticly write a set of SpamAssassin rules to block the antivirus reponses to make my mail usable again.

    I've been archiving all my unfiltered, incoming mail since Feburary. 80,000 messages. If anyone seriously wants to run some statistics for how hard a popular email address gets hammered, I'll consider making it available.