2004 worms (well 4 anyway!)

Virus and Security News - 28 January 2004

FYI Symantec Issues Category 4 Security Alert for Novarg/MyDoom

http://enterprisesecurity.symantec.com/symes553.cfm?JID=11&PID=8545983

A new email virus called MyDoom is spreading rapidly across the Internet through UNIX mail servers, bringing with it a dangerous attachment that, when opened, can give attackers access to users' computers through an electronic backdoor.

The attachment targets Windows users, which account for roughly 96 percent of all computer users, and the rate at which this virus is spreading matches that of SoBig.F, previously the fastest-spreading worm of all time. As with earlier email viruses, MyDoom doesn't spread by means of any technical chicanery, relying instead on the ignorance of users who double-click any messages they see in their Inboxes. Email users are thus advised not to open attachments from sources they can't verify.

The sheer amount of traffic generated by the virus has already brought down many networks, and some security experts now believe that attackers originally launched the virus as a Denial of Service (DoS) attack on SCO Group, the UNIX copyright holder that's now suing various Linux companies for copyright infringement. However, this attack is having the most dramatic effect on end users, many of whom are still surprisingly uninformed when it comes to the dangers of opening attachments. When users open MyDoom-tainted email attachments, their systems become infected--with two side effects. First, their systems send infected email to all the users in their address books.

Second, the virus places a backdoor on their systems that attackers can later exploit.

MyDoom email is identified by text in the body of the email that reads, "The message contains Unicode characters and has been sent as a binary attachment." The subject lines and attachment names vary.

Typical subject lines on infected messages include "Mail Delivery System" and "Mail Transaction Failed." The attachments often appear as .zip files (e.g., document.zip, message.zip, readme.zip) but can have virtually any extension, including .exe, .cmd, or .pif.

MyDoom is also identified as Novarg, Shimgapi, and W32/Mydoom.A@mm, depending on the source.

 Printable Version

News
Virus and Security News
Atlantech recommends CounterSpy
eWeek says ""CounterSpy is the most affordable and richly featured product we reviewed... Sunbelt's CounterSpy Enterprise provides the best mix of management, reporting and cleaning capabilities we've seen, at the most affordable price. With its CounterSpy Enterprise solution, Sunbelt exhibits its experience in designing enterprise-class software. CounterSpy Enterprise has the best reporting tools we've seen by far, offering a wide array of high-level and heavily detailed reports that can be organized by date ranges."
Consulting >>
Introduction to Security
An information system with a weak security foundation will eventually experience a security breach. Examples of security breaches include data loss, data disclosure, loss of system availability, corruption of data, and so forth. Depending on the information system and the severity of the breach, the results could vary from embarrassment, to loss of revenue, to loss of life.
Consulting >>
More Internet Bank Account Fraud!
Fraudsters have developed phishing emails capable of automatically stealing bank log-in details
Consulting >>
IE cross-zone privilege escalation vulnerability
Active exploitation of a cross-zone privilege escalation vulnerability in Internet Explorer has been observed.
Consulting >>
Not-so-witty Worm Destroys System Data Through BlackIce Firewalls
A fast-spreading worm got loose on the Internet Saturday, crawled through a vulnerability in Internet Security Systems' BlackIce firewall, has infected between 10,000 and 50,000 systems worldwide, and can trash infected hard drives.
Support and Maintenance >>
2004 worms (well 4 anyway!)
Virus generates massive support traffic to helpdesks - confusion abounds....
Support and Maintenance >>
Apple Mac OS X vulnerability
Apple MacOS X DHCP Response Root Compromise
Consulting >>
Breaking into Microsoft - "Tougher than you think!"
Microsoft repels 2500 to 3000 electronic attacks every day--or almost 100,000 a month.
Consulting >>
Worm Alert
Don't be caught by the new "Credit Card Worm Scam"!
Support and Maintenance >>