ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

FBI tracks worm writers

Published: 27 Aug 2003 08:35 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The FBI is "confident" that it will capture those who are responsible for creating and spreading the MSBlast worm and the Sobig.F virus, the bureau said on Tuesday.

Companies and home computer users have had to deal with the MSBlast worm -- also known as W32/Blaster and W32.Lovsan -- which started spreading on 11 August; a worm that attempted to plug the hole exploited by the MSBlast worm; and the Sobig.F virus, which spread through email attachments opened by unsuspecting people.

"We are working with the Department of Homeland Security and with state and local law enforcement on our Cyber Task Forces to track down the perpetrators of Sobig and the recent W32/Blaster worm," FBI Director Robert Mueller said in a statement. "We employ the latest technology and code analysis to direct us to potential sources, and I am confident that we will find the culprits."

The FBI subpoenaed Arizona Internet provider Easynews.com a week ago, looking for more information about a person who posted the Sobig.F virus to several porn newsgroups. Easynews didn't answer interview requests but released a statement last Friday.

"It appears the account was created with a stolen credit card for the sole purpose of uploading the virus to the Usenet network," Michael Minor, chief technology officer of Easynews, said in the statement.

The FBI has its work cut out for it.

The agency has caught only a handful of suspected virus writers, usually because the suspects left a digital trail back to their PCs or talked about the attack after the fact. The person who wrote the Melissa virus, David L. Smith, was nabbed because he released the virus using a stolen America Online account that he connected to using his home computer. The author of the Anna Kournikova virus admitted to releasing that program after creating it with a point-and-click toolkit.

While finding clues on the Internet may be more difficult than finding a needle in the proverbial haystack, high-profile cases may generate their own leads because of the amount of scrutiny that the Internet security community brings to bear, said Steve Trilling, senior director of research for security firm Symantec.

"Historically, we have seen that the cases that have done the most damage have received the most scrutiny," he said. Sobig has caused a great deal of damage.

Sobig.F hit the Internet hard last week, clogging email systems with messages that bear copies of the virus. The Sobig.F virus spreads by harvesting emails from Web pages and from an infected computer's address book. It sends a copy of itself to the addresses in an email message with subject lines such as "Your Details," "Re: Approved" and "Thank you!" The virus also spreads by copying itself to shared network hard drives that are accessible to the infected computer.

Sobig.F has spread aggressively, sending far more emails with copies of the virus than any such program to date. The latest Sobig virus uses an email address other than the victim's as the apparent source of email messages that it sends to spread itself. Many antivirus systems send alerts to the apparent senders of viral email messages, notifying them that they are infected -- even when the malicious program is known to forge the source's email address. The result is more clogging of in-boxes and more confusion, as users have to deal with additional messages that accuse them of being infected.

Despite the hunt, many security experts believe that the author of the Sobig virus will strike again. That's because the Sobig viruses -- the first of which was created in January -- are thought to be created as a moneymaker. The viruses turn every infected PC into an "open proxy," or a system that can be used to send spam. Security experts believe that the programmers of Sobig sell the list of open proxies to underground bulk emailers that need to send anonymous email.

The FBI requested that anyone with any clues to the origins of Sobig or the MSBlast worm contact the bureau immediately.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
38 out of 91 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:



Related Jobs

DEPUTY REQUIREMENTS MANAGER, REQUIREMENTS ANALYSIS, SOUTH YORKS.

Your extensive experience of UML will enable you to look at Business Process models and draft Business Use cases which detail the flow within the ...

Senior Business Analyst - Up to 55k - London, UML, Agile, RUP

You must have the ability to develop evaluations, UML models, process data/class models, costing, test/implementation plans and test cases. KEY ...

45K Senior Java Developer role -J2SE/SPRING/HIBERNATE

45K Senior Java Developer role -J2SE/SPRING/HIBERNATE My client is a key player in the finincial spread betting industry, they are the innovators of ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment