Beta Notice: We've just completed a major update to our content management system. While we hope you don't encounter any errors, new software could cause new errors. If you encounter an error (or see anything in the body of an article in the form "ERROR:xxx"), please contact the editors. If possible, please include details and a screen shot. Thanks!
 Email:   
Home
In This Issue
EasyPrint
Click here for the RSS feed's XML code. This is not a browser URL.
How the SoBig.F virus works (continued)

Remember that the "From" address on all the SoBig.F messages is actually an address taken from the worm's target list. Many mail anti-virus products are configured to bounce any worm laden messages they get back to the sender, in this case, the spoofed address. Even worse, some of these bounces include the original attachment. The anti-virus software can actually end up sending the worm to users who hadn't yet received it, further propagating SoBig.F. This is the equivalent of a DDoS attack (Distributed Denial of Service), where servers you have never communicated with are sending you hundreds of bounced email messages.

Third wave: angry accusations
The last consequence of SoBig that you should be on guard for is the angry responses you will inevitably get from people you may never have heard of. This goes back to the spoofed "From" address SoBig uses. SoBig recipients that have either been infected or had a virus scanner warn them a message from you contained a virus (when you never really sent it), will start complaining. Be prepared and be polite. Inform your users that they may get angry messages of this nature. Refer the authors of these complaints to resources explaining the nature of SoBig.F (for example http://www.symantec.com/avcenter/venc/data/w32.sobig.f@mm.html) and explain that while the message may appear to have come from one of your users, it in fact did not.

The SoBig.F worm is programmed to stop replicating itself as of September 10, 2003. Similar auto-deactivation features were found in previous versions of SoBig and this probably means that we can expect most of the damage from SoBig to be over as of that date, but the next variation may be even worse.

Daniel Koffler is an R6 CLP and works as a Domino consultant for major organizations in North America and Europe, specializing in network design, security analysis and knowledge management, he is also the author of several OpenSource projects. Daniel can be reached at dkoffler@users.sourceforge.net




[ Prev ]

ZATZ Home  ·  News  ·  Back Issues  ·  Credits/Trademarks ·  Link To Us
-- Advertisement --

ONLINE GROUP CALENDAR - FOR UP TO 100 OF YOUR CLOSEST FRIENDS
Stay organized and in control with 24/7 access to all of your important events, projects and files --whether you're at work, at home or on the road.

You can share your calendar, projects and files so everyone in your office is up to date. Plus, search your entire group to find times when everyone is available to meet, manage company resources and much more.

Organize your entire team for as low as $9.95 per year (and yes, that's where the decimal place is supposed to be!)

Tap here to get started right away.

-- Advertisement --

BECOME CONFIDENT AND PRODUCTIVE WITH OUTLOOK 2007 IN SIX WEEKS
You can become a confident, productive user of Outlook 2007 in six weeks.

The Introduction to Outlook 2007 online course makes it happen in just twelve short lessons. The course features an instructor-led online discussion forum, regular assignments and quizzes, printable class notes, and a certificate of completion.

Learn more, then register today, at http://www.ed2go.com/courses/io7.
The Power Magazine for Microsoft Outlook and Exchange Users at OutlookPower.com
Copyright © 1998-2008, ZATZ Publishing. All rights reserved worldwide.
Outlook is a trademark of Microsoft Corporation.