ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Saddam used as worm lure

Dawn Kawamoto CNET News.com

Published: 04 Feb 2005 09:25 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Photos of a "dead" Saddam Hussein are the lure for a new mass-mailing worm, Sophos warned on Thursday, in the latest instance of attackers using well-known figures as bait.

The Bobax.H worm purports to offer photos that show that the former Iraqi leader was killed while attempting to escape from custody, the antivirus company said.

"It's a brand new virus that converts users' PCs into spam factories," said Graham Cluley, a Sophos senior security consultant. "Although it hasn't reached epidemic proportions yet, it is spreading."

The worm can spread via email and by using the Microsoft LSASS vulnerability, the same flaw used by the Sasser worm to spread in record time. The vulnerability was reported 10 months ago, and a patch is available.

Bobax.H, which affects PCs running Microsoft Windows, propagates when people open an email attachment containing the virus, Sophos said in its advisory. It then attempts to forward itself to other email addresses and vulnerable computers. Bobax-H will also try to disable antivirus and security software, as well as install an email relay module to transform the PC into a spam factory.

The attachments in the Bobax.H emails carry a number of different file names, and the body of the message varies too, Sophos said. Examples of message bodies include: "Saddam Hussein - Attempted Escape, Shot dead. Attached some pics that i found" and "Osama Bin Laden Captured. Attached some pics that i found."

Cluely noted that virus writers rely on celebrities to entice people to open malicious email attachments. One example was the Anna Kournikova virus, a mass-mailing worm that posed as a photo of the popular Russian tennis player.

News junkies who receive emails purporting to include news should take measures to get information or photos without putting their computers at risk, Cluley said.

"A lot of people are using the Internet for the latest breaking news. But rather than open an attachment, they can go to a reputable news site like CNN or the BBC. They can look there for the information or photos," he said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
70 out of 144 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:











Related Jobs

IBM Websphere Message Broker- Flow Developer- ESQL JAVA

IBM Websphere Message Broker (WBIMB) Flow Developer (ESQL or JAVA) urgently required by my West Midlands client for a short term contract. You will ...

McAffee Anti Virus Rollout Engineer CRB Cleared

The role will require the following - - Experienced in field support - Windows 2000 / XP / Vista - Anti - Virus experience For an immediate telephone ...

McAffee Anti-Virus Rollout Engineer (Field Based)

My West Midlands based client has a requirement for 2 Engineers to rollout McAfee Anti-Virus on to 600+ desktops at multiple sites throughout the ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment