FBI tracks worm writers

1

FBI tracks worm writers

offline
  • Puky  Male
  • Scottish rebel
  • Pridružio: 18 Apr 2003
  • Poruke: 5815
  • Gde živiš: u Zmajevom gnjezdu

Robert Lemos
CNET News.com
August 27, 2003, 08:35 BST


The FBI is "confident" that it will capture those who are responsible for creating and spreading the MSBlast worm and the Sobig.F virus, the bureau said on Tuesday.

Companies and home computer users have had to deal with the MSBlast worm -- also known as W32/Blaster and W32.Lovsan -- which started spreading on 11 August; a worm that attempted to plug the hole exploited by the MSBlast worm; and the Sobig.F virus, which spread through email attachments opened by unsuspecting people.

"We are working with the Department of Homeland Security and with state and local law enforcement on our Cyber Task Forces to track down the perpetrators of Sobig and the recent W32/Blaster worm," FBI Director Robert Mueller said in a statement. "We employ the latest technology and code analysis to direct us to potential sources, and I am confident that we will find the culprits."

The FBI subpoenaed Arizona Internet provider Easynews.com a week ago, looking for more information about a person who posted the Sobig.F virus to several za-odrasle- newsgroups. Easynews didn't answer interview requests but released a statement last Friday.

"It appears the account was created with a stolen credit card for the sole purpose of uploading the virus to the Usenet network," Michael Minor, chief technology officer of Easynews, said in the statement.

The FBI has its work cut out for it.

The agency has caught only a handful of suspected virus writers, usually because the suspects left a digital trail back to their PCs or talked about the attack after the fact. The person who wrote the Melissa virus, David L. Smith, was nabbed because he released the virus using a stolen America Online account that he connected to using his home computer. The author of the Anna Kournikova virus admitted to releasing that program after creating it with a point-and-click toolkit.

While finding clues on the Internet may be more difficult than finding a needle in the proverbial haystack, high-profile cases may generate their own leads because of the amount of scrutiny that the Internet security community brings to bear, said Steve Trilling, senior director of research for security firm Symantec.

"Historically, we have seen that the cases that have done the most damage have received the most scrutiny," he said. Sobig has caused a great deal of damage.

Sobig.F hit the Internet hard last week, clogging email systems with messages that bear copies of the virus. The Sobig.F virus spreads by harvesting emails from Web pages and from an infected computer's address book. It sends a copy of itself to the addresses in an email message with subject lines such as "Your Details," "Re: Approved" and "Thank you!" The virus also spreads by copying itself to shared network hard drives that are accessible to the infected computer.

Sobig.F has spread aggressively, sending far more emails with copies of the virus than any such program to date. The latest Sobig virus uses an email address other than the victim's as the apparent source of email messages that it sends to spread itself. Many antivirus systems send alerts to the apparent senders of viral email messages, notifying them that they are infected -- even when the malicious program is known to forge the source's email address. The result is more clogging of in-boxes and more confusion, as users have to deal with additional messages that accuse them of being infected.

Despite the hunt, many security experts believe that the author of the Sobig virus will strike again. That's because the Sobig viruses -- the first of which was created in January -- are thought to be created as a moneymaker. The viruses turn every infected PC into an "open proxy," or a system that can be used to send spam. Security experts believe that the programmers of Sobig sell the list of open proxies to underground bulk emailers that need to send anonymous email.

The FBI requested that anyone with any clues to the origins of Sobig or the MSBlast worm contact the bureau immediately.



Registruj se da bi učestvovao u diskusiji. Registrovanim korisnicima se NE prikazuju reklame unutar poruka.
offline
  • Puky  Male
  • Scottish rebel
  • Pridružio: 18 Apr 2003
  • Poruke: 5815
  • Gde živiš: u Zmajevom gnjezdu

Zamislite situaciju da banka drzi sirom otvoreba vrata od sefa i vi kao prolaznik koji voli uvek nesto novo da vidi, udjete u sef i "pozajmite" nesto kesha.
Po ovome ce vas vijati policija a banku nece ni pitati zasto i kako se to desilo.

Da li sam u pravu sa ovim primerom???
Dajte i vase komentare...



offline
  • Vlada
  • Pridružio: 20 Apr 2003
  • Poruke: 3360
  • Gde živiš: Beograd

Pa ukoliko je banka osigurana, osiguganje ce ih pitati, i pitati, i pitati, veruj mi , kod njih te vise juri osiguranje nego policija, jer treba da nadoknadi kes. A procitao sam negde na mrezi da npr. francuska policija ima software koji iz mase ljudi razdvaja likove (koriste za demonstracije) i uporedjuje ih sa zadatom bazom podataka. A to im je jedan od nacina i da prebroje koliko je ljudi boli na demonstracijama, dok nasa policija jos uvek koristi jednu od najbrzih metoda, takozvanu "jed prema od'oka"!

offline
  • Pridružio: 26 Apr 2003
  • Poruke: 1947
  • Gde živiš: Srbija

Nasa policija koristi rnd funkciju kad bije...

offline
  • Goran 
  • Prof.Mr.Dr.Sci. Traumatologije
  • Pridružio: 05 Maj 2003
  • Poruke: 9977
  • Gde živiš: Singidunum

A, šta beše "rnd" funkcija?

offline
  • Pridružio: 26 Apr 2003
  • Poruke: 1947
  • Gde živiš: Srbija

random Smile

offline
  • Goran 
  • Prof.Mr.Dr.Sci. Traumatologije
  • Pridružio: 05 Maj 2003
  • Poruke: 9977
  • Gde živiš: Singidunum

Nije ni čudo što imamo naj efikasniju Policiju! Laughing

offline
  • Puky  Male
  • Scottish rebel
  • Pridružio: 18 Apr 2003
  • Poruke: 5815
  • Gde živiš: u Zmajevom gnjezdu

GoranK ::A, šta beše "rnd" funkcija?
RajiNikadDosta ???

offline
  • Vlada
  • Pridružio: 20 Apr 2003
  • Poruke: 3360
  • Gde živiš: Beograd

Necemo se vredjati, ima u toj policiji normalnih ljudi, koji rade ono sto im je STVARNO posao ! Eto neme su bar hapsili dosta puta, znas kako ti je nekad fino kad pe privede, pa ponudi kafom, pa popricate po jednu . ..

offline
  • Puky  Male
  • Scottish rebel
  • Pridružio: 18 Apr 2003
  • Poruke: 5815
  • Gde živiš: u Zmajevom gnjezdu

Ne vredjam ja nikoga ... znam da ima onih koji korektno rade posao ali ima i onih koji stalno ustaju na levu nogu i jedva cekaju da ih malo cudnije pogledas.

"Dobro vece."
"Dobro vece.
"Vase isprave."
"Izvolite."

ni ne pogleda papire kad

"Da li ste konzumirali alkohol veceras?"
"Nisam."
"Mozemo li to da proverimo?"
"Moze, ali ne preko dregera vec vadjenjem krvi."
"A STO?"
"Zato sto ne verujem u taj aparat."
"A ti si mi neki pametan. AAA?"

... i posle 5 min objasnjavanja panduru da ne verujem u to cudo pustio me je dalje da idem.

Ko je trenutno na forumu
 

Ukupno su 1170 korisnika na forumu :: 38 registrovanih, 6 sakrivenih i 1126 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: Apok, Brana01, debeli, Denaya, Dimitrise93, FOX, Gargantua, goxin, hatman, hologram, HrcAk47, ikan, Istman, Karla, kunktator, laganini123, laki_bb, Libertas, lord sir giga, Mcdado, mercedesamg, Mi lao shu, Milos ZA, milutin134, Mixelotti, mkukoleca, nemkea71, panzerwaffe, S2M, Srle993, tomigun, vathra, VP6919, vukovi, zbazin, zeo, žeks62, 1107