ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Experts unconcerned by imminent Sober attack

Tom Espiner ZDNet.co.uk

Published: 04 Jan 2006 14:15 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The Sober attack predicted to occur on 6 January should not be a problem for systems administrators, antivirus experts said on Wednesday.

As reported last month, machines that were infected by Sober in November have the potential to download malicious code from certain Web sites and then launch a new wave of viruses later this week.

But experts from antivirus companies F-Secure, Websense and MessageLabs all agreed that this Sober attack is unlikely to have a major effect, as systems administrators and antivirus companies have had time to prepare.

F-Secure raised the possibility that there may not even be an attack, as ISPs could block access to the malicious Web sites.

"There might be no attack at all. As everybody knows about the attack, the virus writer may lay low and attack at a later date," said Mikko Hyppönen, director of antivirus research at F-Secure. "The ISPs involved can actively block malicious postings. It's more likely the attacker will lay low or be blocked, rather than succeed."

Websense agreed that the Sober attack would not have a major effect.

"Sober has been mitigated pretty well. I would be really surprised if there's still a problem. I don't see it being a big issue," said Dan Hubbard, senior director of security and research at Websense.

Systems administrators should block the URLs of Web sites with malicious links (see the list at the end of this article) but not the domains hosting the Web sites, F-Secure recommended.

"We have listed URLs that we are recommending systems administrators block. We don't recommend blocking the whole domain, as 99 percent of the pages on these free Austrian and German domains are OK. You should just block the problem URLs," said Hyppönen.

Blocking the URLs should not cause any technical problems for system administrators, F-Secure said.

"If systems administrators block these URLs at their gateways, it's not going to break anything," said Hypponen.

Mark Toshack, manager of antivirus operations at MessageLabs, agreed with Hyppönen.

"Mikko's absolutely spot on. If just a few URLs are blocked, users can still browse the rest of those domains freely," Toshack said.

Antivirus vendors should be able to mitigate the effects of the potential attack, said MessageLabs.

"You'd hope everybody knows about the upcoming attack. All of the antivirus vendors know, and have updated their products to block signatures or detect malicious Web sites. Hopefully this will bottleneck the threat, and choke it off," said Toshack.

But some users may still be affected by an attack. "You will get a few people who aren't running any antivirus software on their desktop, and a percentage of people clicking on unknown Web sites," Toshack added.

MessageLabs advised systems administrators to acquaint themselves with information regarding Sober, and urged IT professionals to remind teleworkers to be cautious of emails that use social engineering to try to trick them.

"Systems administrators should make sure they've read up on all of the information on Sober coming from antivirus vendors — get well versed. Make sure your firewall is updated to block those specific URLs. Tell users to watch out for malicious links, especially those working from home who may be outside the firewall," Toshack said.

F-Secure advises systems administrators to block these URLs to prevent Sober from downloading anything on and after 6 January:

The list will change every 14 days. After 19th of January the list becomes:

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
104 out of 385 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Should a security professional have a...

My own experience and talking to colleagues has prompted me to wonder whether the day has arrived that security professionals will need a legal background. The information security... More

1 comment

Transys comment speculation

I've been pondering why it's so difficult to get any official comment out of any of the organisations involved when it comes to what is happening with Transys. Transys is the consortium... More

Post a comment

Wallet Phones Are Coming:Visa Should J...

Wallet Phones Are Coming:Visa Should Jump On Board Author: Eric Everson, Founder MyMobiSafe.com I have touched on the subject of wallet phones (a mobile handset capable of eliminating... More

Post a comment