Home > Security News > Super Bowl week spells doom for security
Security News:
EMAIL THIS

Super Bowl week spells doom for security

By Anne Saita and Shawna McAlearney, News Writers
29 Jan 2004 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

In what is becoming a Super Bowl tradition, another mass-mailing worm this week raced through computers worldwide thanks to clever social engineering and a Linux lover with a cause.

The velocity of the Mydoom-A worm outbreak, which surfaced Monday afternoon and by Tuesday morning had begun racking up superlatives within the worm world, is reminiscent of Slammer, malware that hit just before the Super Bowl last year and knocked out networks all over the country.

Also dubbed Novarg and Mimail-R by different antivirus vendors, the randomized e-mail and P2P worm, which copies itself in the KaZaA shared directory, spoofs addresses and includes subject lines that are either blank or "HELLO" and body text that suggests a previous message had errors. Clicking the e-mail attachment -- which includes body.zip, document.zip, message.zip, among other variations -- loads Notepad.exe and displays randomized characters on the screen, according to security vendor iDEFENSE.

"Mydoom is taking advantage of one of the most recent trends in the malicious code world, randomized e-mail worms that include a ZIP attachment to bypass traditional gateway filters," said iDEFENSE director of malicious code Ken Dunham in a statement. Because Mydoom's payload includes launching denial-of-service attacks against The SCO Group's Web site, antivirus experts believe the group's legal challenge of Linux code as proprietary motivated the authors.

"It appears to be a Linux advocate attacking the SCO Web site," explained Darwin Ammala, a security engineer with Harris Corp.'s STAT network security unit. "SCO can block the attack and probably won't be hurt as badly as the attacker would like."

Mydoom's success comes in part from end users' gullibility of opening attachments without seriously considering the source. Experts, however, agree that Mydoom's cleverly crafted message and file names make the malicious code more difficult to detect.

By Tuesday morning, e-mail managed security service provider MessageLabs was processing up to 60,000 copies of the worm an hour for its worldwide customers. Mydoom-A "has exceeded the infamous Sobig-F virus in terms of copies intercepted, and the number continues to rise," according to a company statement.

Postini, the fourth largest e-mail processor in the U.S., quarantined 8 million copies in a 24-hour period.

Experts recommend updating antivirus signatures and training users to be more vigilant about opening e-mail attachments -- even those that appear to be text files.

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts