Advertisement
Promo

Online business Toolkit

ISP confirms bug's Filipino connection

Robert Lemos, ZDNet News ZDNet.co.uk

Published: 05 May 2000 10:49 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Sky Internet, the Quezon City, Philippines, Internet service provider that inadvertently hosted some of the "ILOVEYOU" worm code, said late Thursday that the company has tracked the bug to another hosting service, but its efforts have apparently stopped there.

"Our service was used as a gateway," said Ronald Eociario, a system administrator for the ISP. "We already have pinpointed the (suspected source)."

Eociario said he used log files to track the account's users to another ISP in the Philippines, but "we're not sure whether they're the (originating) host."

Instead, the worm writer could have obfuscated his identity by passing through several accounts before creating the four accounts that contained the code. That's a common practice among traditional network attackers.

The worm, which is officially called W95.ILOVEYOU.bin.worm and VBS_Loveletter-o, contacts one of four Web pages hosted on Sky Internet to download malicious code, in addition to its e-mail-spamming and infection components. Researchers have determined that the code copies system passwords and forwards them on to an email address based in the Philippines. Sky Internet has since taken the file -- called WIN-BUGSFIX.exe -- offline.

The four Web pages that acted as remote download sites for the worm have been shut down, Eociario said.

Early worm catches the user?

Sky Internet first noticed the effects of the worm when traffic spiked at 4 p.m. local time (1 a.m. PST) on Thursday, signalling that a large number of computers had been infected and were dialing in to be "updated."

The ILOVEYOU worm first hit companies in Asia early Thursday morning and moved through Europe and then the United States as workers opened their early morning email. The worm activates when users click on an attachment "LOVE-LETTER-FOR-YOU.TXT.vbs," replacing files with its code, mass mailing itself out and then attempting to connect to the servers in the Philippines.

Researchers confirmed that WIN-BUGSFIX.exe installs itself and then attempts to copy passwords. The passwords are then e-mailed to another account in the Philippines.

The National Infrastructure Protection Centre, an agency jointly run by the FBI and the Department of Justice, said they were investigating the issue, but would not give details.

What do you think? Tell the Mailroom. And read what others have said.

Go to our ILOVEYOU Special Report

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
43 out of 97 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:









Sentry Posts Blog

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment

Authentication risks all too human

Risks to successful online banking identification and authentication using smartcards involve a mixture of human and technological factors, according to the European Network and Information... More

1 comment

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

2 comments

Video icon

Video

Google Chrome

Roundup: Full coverage of Google Chrome

The search giant has launched a beta of its own open-source browser, sending a clear challenge to Microsoft in the way it lets users work with applications More

Blog: Google Chrome has Microsoft's code inside, says MS manager

And furthermore, he says, that's a good thing... More

Blog: Google Chrome — nine things we've found since launch

Google must be very happy with the coverage Chrome has gathered. But it's not all good news... More


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters