Email:   
Home
In This Issue
Email a Friend
EasyPrint
News details Click here for the RSS feed's XML code. This is not a browser URL.
Articles-only Click here for the RSS feed's XML code. This is not a browser URL.
How the SoBig.F virus works (continued)

Remember that the "From" address on all the SoBig.F messages is actually an address taken from the worm's target list. Many mail anti-virus products are configured to bounce any worm laden messages they get back to the sender, in this case, the spoofed address. Even worse, some of these bounces include the original attachment. The anti-virus software can actually end up sending the worm to users who hadn't yet received it, further propagating SoBig.F. This is the equivalent of a DDoS attack (Distributed Denial of Service), where servers you have never communicated with are sending you hundreds of bounced email messages.

Third wave: angry accusations
The last consequence of SoBig that you should be on guard for is the angry responses you will inevitably get from people you may never have heard of. This goes back to the spoofed "From" address SoBig uses. SoBig recipients that have either been infected or had a virus scanner warn them a message from you contained a virus (when you never really sent it), will start complaining. Be prepared and be polite. Inform your users that they may get angry messages of this nature. Refer the authors of these complaints to resources explaining the nature of SoBig.F (for example http://www.symantec.com/avcenter/venc/data/w32.sobig.f@mm.html) and explain that while the message may appear to have come from one of your users, it in fact did not.

The SoBig.F worm is programmed to stop replicating itself as of September 10, 2003. Similar auto-deactivation features were found in previous versions of SoBig and this probably means that we can expect most of the damage from SoBig to be over as of that date, but the next variation may be even worse.

Daniel Koffler is an R6 CLP and works as a Domino consultant for major organizations in North America and Europe, specializing in network design, security analysis and knowledge management, he is also the author of several OpenSource projects. Daniel can be reached at dkoffler@users.sourceforge.net




[ Prev ]

ZATZ Home  ·  News  ·  Back Issues  ·  Credits/Trademarks ·  Link To Us
-- Advertisement --

AUTOMATE LOTUS NOTES USER ID MANAGEMENT
ID Manager 4.5 from HELP Software provides a new level of automaton for managing Lotus Notes IDs. ID Manager lets Lotus Notes administrators get out of the business of creating and managing user IDs. Use our ROI calculator to see how quickly ID Manager will pay for itself.

Learn more about HELP Software products
-- Advertisement --

DEPARTMENT CALENDAR - MANAGE AND SHARE A COMMON CALENDAR WITH YOUR TEAMS
Are you responsible for improving your organization's Group Calendaring tool? Have you been tasked to find a true group calendar tool with Itinerary, Time-Off, Sign In/Out and Bulletins/Events module that seamlessly integrates with Domino calendaring?

If so, Logic Springs Technologies will make answering these questions a whole lot easier!

Learn how by visiting us at www.departmentcalendar.com

Copyright © 1998-2008, ZATZ Publishing. All rights reserved worldwide.
Editor's Login