Russian Denies Writing SoBig Worm
IphtashuPhitz writes "The Russian spamware programmer anonymously accused eariler this week of writing the Sobig worm has responded to the accusations. Ruslan Ibragimov of Send-Safe doesn't deny that his program uses proxies to hide spammer's identities. But he totally refutes the report's technical analysis in an online interview over at OReilly Network."
First Post!
Even if he didn't write Sobig, he's a spammer, and a scumbag.. and that's justification enough to hit him over the head with a big (think Acme-sized) mallot) in my book.
I am the maverick of Slashdot
In soviet Russia the worms write YOU!
In mother russia, worm writes people.
The bit about headers is believable. But the opcode similarities are harder to defend- anyone know more about this and care to comment? He clearly has a motive, and should be lynched regardless of whether he actually wrote sobig.
http://persianews.on.nimp.org/?u=Tar_Baby
..I bet he dosen't feel SoBig now.
A spammer is a spammer is a spammer.
Don't waste your vote! Vote for whoever you want, unless you live in a swing state it won't matter anyways
Rule #1:
Spammers lie!
Underholdning.info
The report noted, for example, a strong similarity in the email headers created by Send-Safe and SoBig. But Ibragimov said Send-Safe chose the particular order of headers merely to mimic Outlook Express and to better evade spam filters.
Somehow I think Ibragimov's righteous indignation over the accusation is a teensy bit misplaced...
I want to drag this out as long as possible. Bring me my protractor.
Not that I'm shedding any tears for this guy but does "Anonymous person accuses other person by name on the basis of sketchy circumstantial evidence!" really merit this degree of publicity?
What I'm listening to now on Pandora...
This sig seemed like a good idea at the time....
so he doesn't write viruses, just unwanted bulk mail. Makes me much more comfortable. not.
Look, this thing is totally safe! Built it myself, you know. You just press that button like this and then turn that lev
https://gmail.google.com/gmail/a-b0ab39f1a8-517235 8b19-6f45f145ca c 0563-18969179a8 1 50e2-0bef3ba2a4 2 cd83-e0644e7ef5 6 9d32-22621daaff 7 c84e-b9e70ce4cd
https://gmail.google.com/gmail/a-b0ab39f1a8-13556
https://gmail.google.com/gmail/a-b0ab39f1a8-bc9b1
https://gmail.google.com/gmail/a-b0ab39f1a8-d6f30
https://gmail.google.com/gmail/a-b0ab39f1a8-62e3c
https://gmail.google.com/gmail/a-b0ab39f1a8-6c3f0
If you read the original report you can see hard facts against Ruslan Ibragimov.
The binary comparison in the report shows evidence for a correlation between Send-Safe and Sobig-F which could be proved if Ibragimov would be forced to open the Send-Safe source.
Maybe he wrote the "Who wrote the SoBig?" report himself to popularize his "Send-Safe" software... You never know...
I'd reserve the phrase "totally refutes" for occasions where.... this actually happens. What I saw of the "refutation" was a few bits of unconvincing excuses and loose logic. The similarity in headers and the number and length of exact code matches is compelling and proabably irrefutable evidence.
Wow, this is surprising! I was expecting "Russian accused of writing SoBig worm admits to it, despite the flagrant lack of evidence to actually convict him of anything."
Who cares whether he wrote SoBig or not? Either way, he's a spammer, and worse, a software developer who actively enables, supports and promotes spam. He'd be a perfect test case if someone were to develop a SpammerAssassin utility :)
The only interesting comment I found is that his company is currently having difficulties due to trojans, something that the SendSafe forums seem to confirm. That seems quite probable, but it hardly helps his case - why, exactly, would trojans be causing his SendSafe business any problems? Unless, of course, it might be something to do with other trojans that he didn't write such as NetSky/Sasser preventing SoBig getting as many hosts as it used to? Given that there was a spat between the various trojan authors, complete with a possible Russian connection, just before Sven Jaschen was arrested that at least seems entirely plausible to me.
UNIX? They're not even circumcised! Savages!
Portrait of a Content Rich White Man
In modern Russia, worms write YOU!
sulli
RTFJ.
Donald 'Duck' Dunn: We had a band powerful enough to turn goat piss into gasoline.
You're all wrong.
I did it!
True confidence comes not from realising you are as good as your peers, but that your peers are as bad as you are.
"Only the true Messiah denies his divinity!"
He is innocent until proven guilty, just like Scott Peterson and O.J. Simpson.
His response: "It's bullshit." Well what is he gonna do?! Admit it and get $250,000 bail money? ;)
large - keep your that the project user. 'Now that what they think is WASTE OF BITS AND join in especiaaly appeared...saying man walking. It's
`A viral Mr Big on us,' so I hear.
'So it is over, and without a lot of extra fuss ..'
...
01. Do nothing after repeated warnings about attacks on major US sites using passenger jets. (except Ashcroft took to flying private).
02. Be so influenced by the Israeli lobby as to allow the Palestinian situation to escalate out of all control. The backlash against this being one of the prime motivators of the 9/11 and other terrorists.
03. Allow al-Qaeda/the freedom fighters formerly known as the Mujahideen to take root in Afghanistan. This group having been formed out of the remnants of groups created and financed by Bin Laden at the behest of the CIA.
04. In the immediate aftermath of the 9/11 attack allow Bin Ladens family to *fly* out of the US unquestioned.
05. Holding back US troops to allow Bin Laden to escape from his holdout on the Pakistan border. If captured he might have some embarrassing facts to disclose.
06. Take a middle eastern dictatorship (Iraq) and overthrow its ruler. In the process disbanded its highly trained army and allow them to escape with most of their weapons intact. The remnants of which later joined forces with radical Islamic fundamentalists forming the bulk of the current Guerilla army. Making large parts of Iraq no go areas for US troops. Almost a year after the so called 'ceasefire'.
07. Incidentally whilst Heusen was in power and still an asset of the CIA it was his job to suppress the 'fundamentalists'. And after the first Gulf war he was totally suppressed and *no* external threat to anyone. He still could stifle the fundamentalists. So removing him has actually created a state that supports terrorism.
08. Arbitrarily dismiss and ignore the views of the USAs own allies to such an extent that *no* country apart from the UK went into Iraq with it. Chiefly because Tony Blain had no choice. The rest he bribed with contracts or getting their application to join the EU speeded up.
09. In the process Bush did something the Warsaw Pact could never achieve through out WW11, the Cold war, the Cuban missile crises and the breakup of the Soviet Union. He split NATO in two. He couldn't have done better if he was Putins foreign minister.
10. Provoked North Korea and Iran into going Nuclear. Something they had no incentive in doing until his famous axis of evil speech.
11. Reintroduced a new Nuclear arms race with his bunker-busting bombs and a re-launched starwars. A plan to put nuclear weapons into space.
Lastly he's refused to sign the Kioto agreement. Signed over large tracts of Alaska to the Oil companies rescinded environmental legislation and criminalised environmental and political activists.
Not bad for a first four years
1. Send-Safe and SoBig had same release dates. Where the margin on same is up to 10 days, and there are strange inaccuracies, for example the document states that on 5/23/2003 there was a SoBig release compiled on June 24, 2003. Other evidence hinges on the actions of SSSG without considering the possibilities that they were using a hacked version of Send-Safe.
2. Document contains unfounded statements like "As SSSG appears to be a sizable organization, it would seem unlikely that any individual within the group would actually know the Sobig author(s)."
3. The skills section is particularly funny since it lists skills like "Newsgroups" and states the the Russian has been posting on Newsgroups since 1998. Woo hoo!
4. The use of %s section made me want to LOL. The authors see significance in the fact that neither piece of software uses %s to concatenate strings, would be unusual for any C programmer, yet looks like something any C programmer would do.
5. The note on string ordering with an example of SoBig vs Send Safe appears to me to show the opposite of what the authors intended. The two blocks look very different.
6. A large part of the document is dedicated to showing how the two exectuables are "similar" at the opcode level. There is no actual evidence here, e.g. how about a disassembly of two identical blocks of code? The comparison is interesting, but doesn't tell us much without being able to see the actual code.
Overall I though the PDF file was poorly written, lacking in rigor and provided no real evidence for the naming of this individual.
Yes, he helps people spam, and that's very, very annoying, but "innocent until proven guilty" people? Or at least "innocent until you actually show some convincing evidence".
John.
...virus writers write YOU!
Your reading comprehension fails it big. Why don't you take a look at that sentence again before giving an ignorant response. People writing things like that make me hang my head and wonder where the world is headed.
This is RUSSIA, you morons.
IT wrote HIM.
Get your facts straight.
Blearf. Blearf, I say.
Here's the quote from the "Who wrote sobig" article:And the quote from the interview:
Wow... this story's a whole FOUR hours old, and there's only been 50 or so comments on it? Could this possibly be the least commented-on story in Slashdot's history?
:)
If I didn't know any better, I'd think that there was something else on most people's minds!
What have I failed to comprehend? Suggesting lynching someone for having a motive, whether they actually did the deed or not, scares me.
And tomorrow the stock exchange will be the human race
http://shit.slashdot.org/article.pl?sid=04/11/03/1 733239
"Ibragimov, 30, said no one from the FBI or any other law enforcement agency has ever contacted him about the SoBig worm." I wonder how FBI officers would contact Russian citizen in Russia :) No, imagine, that FSB (ex. KGB), or any other Russian secret service officer will knock your door in the middle of American Nowhere.
In reality, if you want this guy to pay for his sins, write about this event to fsb@fsb.ru (the address is real, don't "test" it!), I guess after some requests they will consider talking to this Ruslan Ibragimov. By the way, his name and surname shows, that he is most likely not Russian. It looks like he belongs to Chechen or other Caucasus nation, so the talk with FSB officer is not going to be gentle.
And another thing - he is using the swreg.org registrar for his spamware. No matter if he is author of SoBig or not, you can ignore this registrar (whether you are developer or customer, doesn't matter), so they will not earn money on spam.