Advertisement
Promo

Security threats Toolkit

SCO.com emerges from virus battle

Munir Kotadia ZDNet.co.uk

Published: 08 Mar 2004 17:40 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The SCO.com Web site returned to the Internet last week after suffering a denial of service attack that lasted for more than a month.

The SCO Group Web site was the main target of the MyDoom worm, which is a variant of the Mimail virus and was first discovered towards the end of January. The worm installed a back-door program that allowed infected PCs to be controlled remotely. The worm was designed to launch an attack on SCO's Web servers between 1 February and 12 February. However, because of incorrectly set PC clocks, the attack continued until the end of last week.

SCO has roused the ire of many in the software community because of a series of lawsuits related to its Unix intellectual property, and for attempts to force companies using Linux to pay licence fees to SCO.

The sheer ferocity of the attack caught SCO and security analysts by surprise and SCO's initial confidence in surviving the attack quickly diminished. Within hours, the SCO site was completely inaccessible, forcing the company to launch an alternative site to maintain its Web presence.

According to Finnish security company F-Secure, SCO attempted to revive the site on 27 Feb at 6:15 a.m. (GMT), but had to take it down again after 30 minutes.

Web site monitoring company Netcraft claims SCO.com was returned to the Internet on Friday evening and over the weekend -- it did experience two short breaks in service, but apart from that it has been performing well.

A spokesman at antivirus company BitDefender told ZDNet UK that although SCO's site was back, it could easily be sent down by another MyDoom-type worm: "Yes, at this moment, there is no attack on the SCO Web site anymore. To restart the attack it is simple: another version of the virus... It's just that," he said.

With virus authors apparently conducting a war of words through their worms' source code, F-Secure said a new attack would not be surprising: "As the new versions emerge -- three or even four in a day -- [a new attack] wouldn't be so difficult," he said.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
65 out of 152 people found this useful



Company/Topic Alerts

Create a new alert from the list below:









Video icon

Video

Sentry Posts Blog

Official Organizations Losing Data

How does this article from earlier today make you feel? How many more government, health service, or military officials are going to lose pen drives, DVDs, USB hard disks and even entire... More

2 comments

Twitter hack was DNS redirect

Twitter has said an attack on Thursday which took the site offline for many users was the result of a DNS redirect. A group calling itself the Iranian Cyber Army redirected users... More

1 comment

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters