Slashdot Mirror


A Worm's Worm

Carnildo writes "There's a new worm out, according to the Register, but one with a twist. This one, called 'Dabber', infects computers by exploiting a security hole in the Sasser worm."

54 of 345 comments (clear)

  1. Ugh... by c0dedude · · Score: 5, Funny

    Jeez, they never fully test these worms before release. No wonder they'd have security issues.

    --
    Since when has this country used intellectual elite as a pejorative term?
    1. Re:Ugh... by irokitt · · Score: 5, Funny

      This is why every worm should be released under the GPL. Then independant worm enthusiasts can verify the security of worm code and contribute patches and improvements to the author.

      --
      If my answers frighten you, stop asking scary questions.
    2. Re:Ugh... by dealsites · · Score: 5, Funny

      I imagine that most of these virus writers are not formally educated in programming, but able to hack together code snippets they find on the web. It's a wonder some of them work as well as they do. I doubt they do peer review or use a CVS to manage their code.

      --
      New deal processing engine online: http://www.dealsites.net/livedeals.html

    3. Re:Ugh... by inertialmatrix · · Score: 5, Insightful

      "most of these virus writers are not formally educated in programming, but able to hack together code snippets they find on the web. It's a wonder some of them work..."

      heh.. sure, right. God knows that unless you have a masters in CS your only chance to program something like code red, blaster, or sasser is by hacking "together code snippets [you] find on the web" Christ, 3 years into a CS major, and aside from the calculus I have yet to make any large leaps in knowledge over what I already knew several years ago.

      Maybe that's what grad school is for?

    4. Re:Ugh... by httptech · · Score: 4, Informative

      This is already happening. Agobot is a GPLed malware project. Although it's not quite a worm, it can spread unattended once given the command to do so. Plenty of people are contributing to it (although some of them have been arrested in the past few days) and the feature list is quickly growing.

    5. Re:Ugh... by John+Hasler · · Score: 4, Insightful

      I imagine that many of these virus writers are professionals, well-paid by their spammer employers.

      --
      Warning: this article may contain humor, sarcasm, parody, and perhaps even irony. Read at your own risk.
    6. Re:Ugh... by jesser · · Score: 5, Funny

      So if I'm infected, I can demand a copy of the source code?

      --
      The shareholder is always right.
    7. Re:Ugh... by lommer · · Score: 4, Interesting

      I have a very serious suggestion, namely that Agobot, once it infects a host, should patch the host, remove spyware, and remove other virii, and then propogate itself a maximum of 10 times (to conserve bandwidth). Though you are still doing unauthorized stuff to other peoples' computers, if you're gonna make a virus, you may as well make it beneficial. Maybe that way fewe people would get arrested...

      Given that it's a GPL project, I can't imagine that it would be too hard to find a few dedicated coders who would be willing to work on such a fork.

    8. Re:Ugh... by Rob+Simpson · · Score: 5, Interesting
      Of course, and its a sad comment on the state of computing today that this is a unique case. Human viruses are thoughtfully provided with their source code - exceeding even the requirements of the GPL - so they can be compiled by your cells.

      Yay for Free Software! (Achoo!)

    9. Re:Ugh... by foobario · · Score: 5, Insightful

      >Maybe that's what grad school is for?

      No, but the remainder of your undergraduate education will benefit if you continue to hope that this is true.

      Every year in my EE and CS programs I figured that 'next year' would be the year I'd really learn something useful, but that day never arrived. Nonetheless I managed to graduate, get a high-paying job, and get laid off 20 months ago after 3 years of 15 hour days. Now I think about taking classes at the community college, welding maybe, but I just can't get up the energy to do it.

      You see, you are wrong in assuming that calculus is the only thing you've learned so far. You've also learned The Secret a year earlier than most people.

      You know those tests they do on rats, where they put them in a maze, and if they do the wrong thing they get an electric shock, but if they do the right thing they get the cheese?

      The Secret is this:

      You are the rat.
      The electric shock is *always* on.
      ***There Is No Cheese***.

    10. Re:Ugh... by mabinogi · · Score: 4, Funny

      You are correct, and I am a moron.

      Next time I'll read all of the comment, not just random words ;)

      --
      Advanced users are users too!
  2. I've had enough by KevinKnSC · · Score: 5, Funny

    Worm writers have got to start taking security more seriously.

    1. Re:I've had enough by iminplaya · · Score: 5, Funny

      Well, at least Microsoft worm writers. I'm sure Linux and Mac worms are much more secure. :-)

      --
      What?
  3. all new low by ResQuad · · Score: 5, Funny

    This is an all new low. Now virus programmers will have to make their virus's better so they dont get infected by another virus.

    I think everyone should go ultra secure, the best firewall ever... Disconnect from the net. It would make this all alot easier on us.

    1. Re:all new low by Anonymous Coward · · Score: 5, Funny

      Now virus programmers will have to make their virus's better so they dont get infected by another virus.

      Maybe they can just run Norton AntiVirus - oh wait...

  4. planned by name773 · · Score: 4, Interesting

    did the sasser writer make it expandable on purpose? this isn't the first time a thing like this has happened.

    1. Re:planned by wo1verin3 · · Score: 4, Funny

      sure it could have been planned...

      Coming soon....
      http://www.sasser-plugins.com

  5. This is why... by boffy_b · · Score: 5, Funny

    ...we need to stop relying on thrid-party worms, we need Micro-Soft certified worms to ensure our securtity....

    --
    Windows is only $500 if your time is worthless.
    1. Re:This is why... by duffel · · Score: 4, Funny
      ...we need to stop relying on thrid-party worms, we need Micro-Soft certified worms to ensure our securtity....
      You mean like IE? I've certainly had enough programs try to get me to install that on my computer..
      Wouldn't that be a trojan horse rather than a worm? Worms are more like those automatic updates, burrowing into your system... Although that program that downloads them would be more like a trojan horse, and the downloading of updates the payload...

      Yes, that's it! Windows is a trojan horse designed to sneek windows updates onto your computer!

      Tremble before my mighty logic!
    2. Re:This is why... by writermike · · Score: 5, Funny

      ...we need to stop relying on thrid-party worms, we need Micro-Soft certified worms to ensure our securtity....

      Heh.

      The Virus you're about to install has not passed Windows Logo testing to verify its compatibility with Windows XP.

      Continue Anyway.

      --
      If Nalgene water bottles are outlawed, only outlaws will have Nalgene water bottles.
  6. Spyware and others by r.jimenezz · · Score: 5, Interesting

    Just thought about this... With the huge number of machines out there "infected" by spyware, adware and similar programs (and many of them without their users even knowing), how long will it be until a worm is written that exploits a vulnerability in one of these programs?

    --
    The revolution will not be televised.
    1. Re:Spyware and others by MrRuslan · · Score: 5, Funny

      Something like a rear entry into bonzi buddies behind?

    2. Re:Spyware and others by clambake · · Score: 4, Funny

      Just thought about this... With the huge number of machines out there "infected" by spyware, adware and similar programs (and many of them without their users even knowing), how long will it be until a worm is written that exploits a vulnerability in one of these programs?

      Gimme a sec.

  7. Plug-in by StateOfTheUnion · · Score: 5, Funny

    So now worms come with hooks for third party plug-in's?

    1. Re:Plug-in by SharpFang · · Score: 4, Interesting

      Yes, for quite a while.

      Quite a bit of modern worms in this or that way provide just a generic backdoor to the infected machine without performing any extra malice. Some of them just open oprts, some trick firewalls and actively "call home", which usually happens to be some random IRC server on some compromised machine (IRC seems to be preferred method for the virii writers for controlling worms, which just act as bots on the channel). Then the virii can upload a spamming software, a DDoS attack plugin, a keystroke logger, a file transfer thing, a tunneling/relay program to mask an attack, or whatever the twisted minds come up with.

      --
      45 5F E1 04 22 CA 29 C4 93 3F 95 05 2B 79 2A B2
  8. So, naturalists observe, a flea... by jbuhler · · Score: 4, Insightful

    Hath smaller fleas that on him prey;
    And these have smaller still to bite 'em;
    And so proceed ad infinitum.

    - Swift

  9. um... by Anonymous Coward · · Score: 5, Funny

    Would that make the security flaw a ::cough:: "Wormhole"?

  10. what Microsoft is thinking by Anonymous Coward · · Score: 4, Insightful

    maybe we should make a virus that causes everyone to hit up Windows Update and maybe we'll be alright.

  11. It's ok... SP1 is coming soon by licamell · · Score: 5, Funny

    The author in response to the news announce that he will be releasing Service Pack 1 within the next week. Make sure to set up your computer to get updates automatically from update.sasser.com.

    1. Re:It's ok... SP1 is coming soon by int2str · · Score: 4, Informative

      Nope, the Sasser author is going to Jail (http://www.heise.de/newsticker/meldung/47205 - sorry, in german).
      SP1 will be a while ;)

  12. Just like the Anti-HIV Virus! by Cyberherbalist · · Score: 5, Insightful

    There was something on /. the other day about a team of biologists who built a virus based on HIV, that goes out to destroy HIV ability to turn to AIDS. Apparently, the Dabber developer took a page from that book --- in a twisted sort of way.

    --
    "The generation of random numbers is too important to be left to chance."
  13. MS is on it... by wo1verin3 · · Score: 5, Funny

    Microsoft Security Bulletin MS05-014
    Security Update for Microsoft Windows (93212)

    Issued: May 14, 2004
    Updated: May 14, 2004
    Version: 1.0

    Summary
    Who should read this document: Customers who use the Sasser worm

    Impact of vulnerability: Remote Code Execution

    Maximum Severity Rating: Critical

    Recommendation: Customers running the Sasser worm should apply the update immediately to be protected from Dabber.

    Security Update Replacement: This bulletin replaces several prior security updates. See the frequently asked questions (FAQ) section of this bulletin for the complete list.

    Caveats: The security update is for Windows 2000, XP Pro and Home, and Windows 2003 server platforms. As a prerequisite, the security update requires your system be infected with Sasser.

    To download the Sasser worm, please open Outlook Express or Outlook 2000/XP and execute any attachements you have recieved from unknown senders. If you are not using Sasser you do not need to install this update.

    Once installed your system will be immune from being infected with Dabber which exploits a flaw in the widely popular Sasser worm.

    Tested Software and Security Update Download Locations:

    Affected Software:

    Microsoft Windows 2000 Service Pack 2, Microsoft Windows 2000 Service Pack 3, and Microsoft Windows 2000 Service Pack 4 - Download the update

    Microsoft Windows XP and Microsoft Windows XP Service Pack 1 - Download the update

    Microsoft Windows XP 64-Bit Edition Service Pack 1 - Download the update

    Microsoft Windows XP 64-Bit Edition Version 2003 - Download the update

    Microsoft Windows Server(TM) 2003 - Download the update

    Microsoft Windows Server 2003 64-Bit Edition - Download the update

  14. This is *almost* a wonderful thing by Gribflex · · Score: 5, Insightful

    Dabber than installs itself and deletes the registry keys of Sasser and other viruses.

    This is fantastic! It is a virus, that infects only virus infected machines, and then removes all other virii. What a great solution to rapidly spreading worms.

    If users are too lazy or ignorant (in the nice sense of the word) to patch their systems, then just relase another virus to do it for them.

    Except that...

    It [then] creates a backdoor on infected machines on TCP port 9898 allowing hackers to download additional code...

    They just couldn't stop at doing a good thing, could they...

    1. Re:This is *almost* a wonderful thing by Reivec · · Score: 4, Insightful

      You are missing a big point here. The worms effect us all in a much more annoying way. Internet traffic clogging up my connection speed. Why do I care if stupid people can't use their computer? If there was an "Anti-Worm" it would still cause tons of traffic scanning the networks and even if it helped infected people, I don't give a damn. They were too stupid and didn't protect their systems or use something besides windows, not my fault. So basically in my book, the cure would be just as bad as the problem.

    2. Re:This is *almost* a wonderful thing by alonsoac · · Score: 4, Interesting

      This was never about doing a good thing. It's plain competition. Any decent worm should be able to remove all other worms and viruses from the system in order to have complete control over it. I bet this will only get more common.

      Then again it should be easy to release this new work without the code that opens the backdoor so that it only does the removal part?

  15. Re:Is not the first time it happens by grunthos · · Score: 5, Informative
    No, they both exploited the same holes in IIS.

    Perhaps you are thinking of Welchia which exploited IIS but also removed Blaster.

    --

    My son's 5th grade teacher actually assigned them "write a limerick about a planet". I'm not kidding.
  16. Re:Same for my mac by gmuslera · · Score: 4, Funny

    In computing are the windows the ones with worms, not the apples.

  17. This is doubly ironic! by Cyno01 · · Score: 4, Informative
    --
    "Sic Semper Tyrannosaurus Rex."
  18. Not really surprising by cemaco · · Score: 5, Insightful

    In the last few years, the guys who write this stuff have become more and more like gangs. In the real world, gangs compete for terf. That includes undermining each other whenever possible.

  19. Remind Anyone of Blaster by erikharrison · · Score: 5, Interesting

    Gosh, this whole mess looks just like Blaster from down here in the trenches.

    I'm tech support for Tremendously Large ISP. From down here this looks just like Blaster did. Customers calling in complaining that their machine is restarting without their consent. And now someone has a follow up virus that attacks the virus - as some may recall there was a Blaster variant that patched systems AGAINST Blaster. This was terrible - if you got this variant inside a corporate network not only would your bandwidth use skyrocket, but since NAT tends to fubar Windows Update, the variant never managed to patch a system. God that was hell . . .

    It's almost enough to make you want to write a virus in revenge . . .

  20. Re:Clever by beakerMeep · · Score: 4, Funny
    oh the irony.

    a post with the title "clever" and the text "very clever" in a story about a "worm's worm" moderated as "redundant".

    It's like rain on a rainy day.

    --
    meep
  21. Re:geez by 0racle · · Score: 4, Funny

    You know, Blaster and Sasser seemed at first to be really creative. But think he/she is just riding on Windows coattails.

    --
    "I use a Mac because I'm just better than you are."
  22. Patch? by durtbag · · Score: 5, Funny

    So where do I doenload the patch so my Sasser isn't vulnerable?

    --
    itadakimasu
  23. Sigh... by ike6116 · · Score: 5, Funny

    I told you not to try Sasser, it's a gateway worm! IT LEADS TO HARDER, MORE DANGEROUS WORMS!

    --

    Are you secure enough in your masculinity to run 'man touch'?
  24. DMCA violation? by David+Hume · · Score: 4, Funny

    Jeez, they never fully test these worms before release. No wonder they'd have security issues.


    I wonder if the author of the author of Dabber has violated the DMCA by circumventing a copyright protection system -- i.e., the code to the Sasser worm.

    More specifically, I wonder if the author of Sasser can sue the author of Dabber for statutory damages of up to "$2,500 per act of circumvention." ;)

    1. Re:DMCA violation? by spectre_240sx · · Score: 5, Insightful

      You jest, but I wouldn't be surprised if it was possible. Don't forget, this is the country where a buglar can sue his victims if he breaks his leg while breaking into their house and win.

  25. Re:A Quick Fix by rjshields · · Score: 5, Funny

    if you have windows, type, "format C:"

    Why yes, I have windows. I even have doors too. I typed "format C:" like you said but I just got a message saying "the page cannot be displayed".

    --
    In this world nothing is certain but death, taxes and flawed car analogies.
  26. Exploit available on packetstorm by Anonymous Coward · · Score: 5, Informative

    The mentioned code, which is used in Dabber, can be found at http://packetstormsecurity.nl/0405-exploits/sasser ftpd.c

  27. Actually sounds like somebody trying to fix things by Ungrounded+Lightning · · Score: 5, Interesting

    This is an all new low. Now virus programmers will have to make their virus's better so they dont get infected by another virus.

    Actually, this sounds like somebody trying to make a disinfectant worm. Look at the description:

    - It only infects infected systems, using a flaw in the previous infection.

    - It cleans out the infection of the worm that it exploited, and several others.

    It does open a new backdoor. But while that might be preparation for some future malicious action, it might also have been the author leaving himself a way to fix things if his initial worm got out with a destructive bug. (Of course it could be the worm cleaning up signs of previous infections in order to hide itself and thus head off other cleanups.)

    I wouldn't be surprised to see, on further analysis, that it does other antimalware things (like fix the flaw the other worms used).

    (Not to say that it IS somebody trying to fight virus with virus. But it might be interesting if it turns out that it is.)

    I think everyone should go ultra secure, the best firewall ever... Disconnect from the net. It would make this all alot easier on us.

    Which is exactly what the military does with some of its really secure stuff.

    Now if we can just get the Microsoft users to emulate them. B-)

    --
    Bantam Dominique roosters crow a four-note song. Once you've heard it as "Happy BIRTHday" you can't NOT hear it that way
  28. OS Popularity? by One+Louder · · Score: 4, Interesting
    The tired argument is that Mac OS X and Linux are too unpopular to build worms and viruses for - but apparently it's worth writing worms just for Windows machines infected by a single strain of worm.

    Does this situation imply that the sum total of Sasser-infected machines outnumber Macs and Linux boxes?

  29. Add it to nmap! by JThundley · · Score: 5, Informative

    Add the sasser FTP server to your nmap-services file. I run Gentoo, mines in /usr/share/nmap.

    Add this line:
    sasser 5554/tcp # Sasser worm FTP server

    This way when you do a port scan of a host, you can tell if they've been infected with sasser :)

  30. Geek jokes by Tokerat · · Score: 5, Funny


    Program code so advanced it travels through worm holes!

    *rimshot*

    --
    CAn'T CompreHend SARcaSm?
  31. Fun! by Ketnar · · Score: 5, Interesting

    This sort of reminds me when I wrote a counter-bug to combat an email worm that had infested an office building I was contracting to. Worked through the ever-so-lovely 'You don't have to really click the attachment for it to go off on you' bug in an older version of outlook.

    It sat and watched a users inbox for the big bug at the time and pretty much acted like a counteragent, the instant they showed up, it nuked them off the machine (inbox and all) and undid whatver they managed to do.

    Send one copy to everybody in the office, and instantly watch outgoing network mail traffic DROP back down to normal levels and my phone stop ringing.

    I seem to recall distinctly 'forgetting' to mail it to key people, however.. *cough* :)

    Would be a real shame if some of the geek-prowess around the OSS world were to start doing such counter-bugs. Alot of these backdoors, trojans, and whatnot, have gaping flaws in them because..well, guess. :P

    Just think:
    Infect > Disinfect > Patch > Scan nearby machines (proceed life cycle)> Local Self-remove

    Could be the next revolution. Don't bother patching or downloading, we bring the cure to YOU.. :)

    --
    My new top secret key -> C>N|KB
  32. Phages? by Wtcher · · Score: 5, Insightful

    ...it reminds me of the phage/bacteriophage, actually. If I recall, those viruses kill bacteria(judging from the name...) by infecting them.

    This goes on to remind me of that recent anti-HIV virus that's been in the news.

    --
    ----- Wtcher Dragon, UDIC