Search DominoPower's 11,422 Lotus-related article archive 
Home
EasyPrint
News details Click here for the RSS feed's XML code. This is not a browser URL.
Articles-only Click here for the RSS feed's XML code. This is not a browser URL.
Twitter Feed Click here for the Twitter feed.
How the SoBig.F virus works (continued)

Remember that the "From" address on all the SoBig.F messages is actually an address taken from the worm's target list. Many mail anti-virus products are configured to bounce any worm laden messages they get back to the sender, in this case, the spoofed address. Even worse, some of these bounces include the original attachment. The anti-virus software can actually end up sending the worm to users who hadn't yet received it, further propagating SoBig.F. This is the equivalent of a DDoS attack (Distributed Denial of Service), where servers you have never communicated with are sending you hundreds of bounced email messages.

Third wave: angry accusations
The last consequence of SoBig that you should be on guard for is the angry responses you will inevitably get from people you may never have heard of. This goes back to the spoofed "From" address SoBig uses. SoBig recipients that have either been infected or had a virus scanner warn them a message from you contained a virus (when you never really sent it), will start complaining. Be prepared and be polite. Inform your users that they may get angry messages of this nature. Refer the authors of these complaints to resources explaining the nature of SoBig.F (for example http://www.symantec.com/avcenter/venc/data/w32.sobig.f@mm.html) and explain that while the message may appear to have come from one of your users, it in fact did not.

The SoBig.F worm is programmed to stop replicating itself as of September 10, 2003. Similar auto-deactivation features were found in previous versions of SoBig and this probably means that we can expect most of the damage from SoBig to be over as of that date, but the next variation may be even worse.

Daniel Koffler is an R6 CLP and works as a Domino consultant for major organizations in North America and Europe, specializing in network design, security analysis and knowledge management, he is also the author of several OpenSource projects. Daniel can be reached at dkoffler@users.sourceforge.net


« Previous  ·  1  ·  2
Other articles you might like
Home > Strategies > Email Management (60 articles)
   Using the Notes Client with Gmail
   Using the Notes client with Hotmail (or not)
   Is English-only a viable mail management strategy?
Get Weekly Email Updates
Subscribe to our regular weekly email newsletter. It's packed with tips, reviews, deep analysis, and the latest news.
 
Recent DominoPower Articles
Application development, William Shatner, and the origin of the universe
Learn Domino Designer 8.5 for free
The (near) future of Sametime, Quickr, Connections, and Symphony
Inside the IBM Innovations lab
Lotusphere 2010: Hot fixes and cool news for Notes, Domino, and LotusLive
Lotusphere 2010: mobility and collaboration
2010: A Lotusphere of change
Latest Lotus Headlines
New Notes/Domino Technotes published about Chile's extended daylight saving time
SnnT: How to prevent Google from listing your Sametime Server
How to send someone an email that shows your calendar availability
"The collection has become invalid"
More XPages onclick event weirdness...
Domino 8.5.1 Fix Pack 1 Interim Fix 1 (8.5.1 FP1 IF1) - DAOS Fixes
Domino Designer 8.5 Tip: Where Working Sets Are Stored
>> Read all the news
More from the ZATZ journals
Computing Unplugged: The iPad defenders have spoken
David Gewirtz Online: CNN commentary and analysis
OutlookPower: More about disappearing text
-- Advertisement --

Find unused Lotus Notes groups and clean up your address book
Have you ever wanted to get rid of old Lotus Notes groups that were cluttering up your address book, but you weren't sure if they were used? Find Unused Groups can help.

Find Unused Groups will check your ACL, mail, multi purpose and server groups to help you determine if they are used, and who uses them.

Learn how to easily clean up your address book.

-- Advertisement --

Mark your calendar for in-depth Lotus training, May 12-14, Boston
Join experts and peers May 12-14 in Boston for educational and networking events that deliver real-world Lotus training so you can increase productivity and efficiency in your company, advance your skills, and squeeze the most from your current environment. One registration gets you into THE VIEW's Admin2010 and Lotus Developer2010.

Register by April 10 to save $200.
ZATZ Home  ·  News  ·  Back Issues  ·  Credits/Trademarks ·  Link To Us
Copyright © 1998-2010, ZATZ Publishing. All rights reserved worldwide.
Editor's Login