With Valentine's just-around-the-corner, cyber crooks are again on a rampage, palming off their wares, disguised as Valentine's greetings and what not... Like every other year, this year too, security experts warn of worms coming as romantic messages in emails, and invading PCs belonging to unsuspecting users. . PandaLabs has already detected a worm, they've dubbed "Nurech.A", which hides in emails with subjects like "Together You and I," "Till the End of Time," and "Heart of Mine". The malware comes in an executable attached file with names such as flash postcard.exe or greeting postcard.exe. The link for this article located at Techtree is no longer available. . CyberGuard alerts users about the 'LoveBug.B' worm sneaking into Cupid-themed emails, propagating via affectionate notes.. Email Malware, Valentine's Day Threats, Nurech.A Worm. . LinuxSecurity.com Team
As I write this, yet another e-mail worm is spreading among non-Linux computers and incidentally filling my mailbox with "YOU HAVE A VIRUS" bounces from dumb software that somehow doesn't yet get the concept that worms forge mail. There's nothing like a worm attack that spares Linux to bring out the smug superiority in Linux users. . . .. As I write this, yet another e-mail worm is spreading among non-Linux computers and incidentally filling my mailbox with "YOU HAVE A VIRUS" bounces from dumb software that somehow doesn't yet get the concept that worms forge mail. There's nothing like a worm attack that spares Linux to bring out the smug superiority in Linux users. Cut it out. The attack path here is one step long. All that's keeping us safe is that most programs for Linux don't make it easy to run attachments from incoming mail. But combine the right vulnerability in a common desktop app with a little social engineering, and you've got a Linux worm. Last year, the not-so-dramatically-named CAN-2003-0434 vulnerability allowed humble PDF files to run arbitrary commands as you. Linux users and distributions dealt with it quickly enough that it didn't turn into a vector for spreading a worm. With today's larger Linux user base and more desktop standardization, the next vulnerability will be a bigger risk. The link for this article located at Linux Journal is no longer available. . Phishing scams endanger Windows users, but Linux stays relatively protected. Uncover defense tactics to mitigate possible threats.. Email Security, Linux Protection, Worm Defense. . LinuxSecurity.com Team
Conventional wisdom claims March comes in like a lion and goes out like a lamb. But with new versions of the Bagle e-mail worm and a virulent new form of Netsky virus, March's arrival is looking more wormy than leonine. As of Monday, five new versions of Bagle appeared over the weekend as well as a new version of Netsky that is spreading rapidly on the Internet and generating a huge volume of virus-infected e-mail messages. The new virus versions use a variety of so-called "social engineering" techniques to fool users. Some new variants also hide in ZIP files to slip past anti-virus filters and into users' e-mail boxes, said Graham Cluley, a senior technology consultant at Sophos. . . .. Conventional wisdom claims March comes in like a lion and goes out like a lamb. But with new versions of the Bagle e-mail worm and a virulent new form of Netsky virus, March's arrival is looking more wormy than leonine. As of Monday, five new versions of Bagle appeared over the weekend as well as a new version of Netsky that is spreading rapidly on the Internet and generating a huge volume of virus-infected e-mail messages. The new virus versions use a variety of so-called "social engineering" techniques to fool users. Some new variants also hide in ZIP files to slip past anti-virus filters and into users' e-mail boxes, said Graham Cluley, a senior technology consultant at Sophos. Netsky.D, a new version of the Netsky worm, is believed to be the biggest threat in the group. As of Monday, Netsky.D was spreading rapidly on the Internet and flooding e-mail servers with infected messages, according to Cluley. Some of Sophos' customers were receiving thousands of Netsky.D infected messages each hour. That number could increase on Monday as U.S. workers return to their desks after the weekend, he said. The original Netsky worm first appeared on Feb. 16. Since then, three more variants have been released on the Internet. Like its predecessors, Netsky.D scans an infected computer's hard drive for files containing e-mail addresses andthen sends copies of itself to those addresses, antivirus companies said. Like its predecessors, Netsky.D affects machines running Microsoft's Windows operating system and arrives in e-mail messages with randomly generated subject lines such as "Re: Document," "Re: Your picture" or "Re:approved." The Netsky.D worm disguises its payload as a Program Information File (PIF) attachment that also has a randomly generated name such as "my_details.pif" "document.pif" or "mp3music.pif." Unlike its predecessors, NetSky.D doesn't spread on peer-to-peer networks, and doesn't use a ZIP file to conceal its contents, according to anti-virus company Network Associates. The link for this article located at nwfusion.com is no longer available. . In March, the rise of the Bagle and Netsky worms significantly altered email security threats, spreading via deceptive attachments and links that tricked users. Worm Threats, Bagle Warnings, Netsky Spread, Email Viruses. . Anthony Pell
MyDoom-A is programmed to stop spreading today, marking the end of arguably the worst email-borne viral epidemic to date. MessageLabs, the email filtering firm, blocked the virus 43,979,281 times in the two weeks since its first appearance in late January. At the height of the epidemic, one in 12 emails the firm scanned were viral. . . .. MyDoom-A is programmed to stop spreading today, marking the end of arguably the worst email-borne viral epidemic to date. MessageLabs, the email filtering firm, blocked the virus 43,979,281 times in the two weeks since its first appearance in late January. At the height of the epidemic, one in 12 emails the firm scanned were viral. At the height of the Sobig-F pandemic last August one in 17 emails scanned by MessageLabs were viral. MessageLabs has blocked 33 million copies of SoBig-F, so MyDoom-A is the worst virus in terms of sheer weight of numbers too. MyDoom-A was programmed to launch a denial of service attack against / from infected machines. This - along with its spread - will cease today (see below for caveat*). However the back door component of the virus has no time limit; it is still running on pox-ridden PCs. Infected machines still need to be identified and decontaminated. This is doubly important because the recently-released Doomjuice worm uses this back door access to direct infected machines to packet Microsoft's Web site. MyDoom-A infected anything between 400,000 and one million PCs, according to sundry estimates from AV firms. On Tuesday, Feb 10, 67,000 IP addresses were actively scanning to and from port 3127, the back door left open by MyDoom-A, according to the SANS Institute's Internet Storm Center. This suggests many users have cleaned up their act. . MyDoom-A ceases its activity today, marking the end of one of the most severe email-related viral epidemics ever recorded. Remain alert!. MyDoom-A, Email Worm, Virus Outbreak, Malware Cleanup, Denial of Service. . Anthony Pell
This is exactly the type of thing that could happen to Linux. "The Anna Kournikova e-mail worm that whacked networks this week was not the work of a skilled cracker. It was created using one of the many virus-generating kits that . . . . This is exactly the type of thing that could happen to Linux. "The Anna Kournikova e-mail worm that whacked networks this week was not the work of a skilled cracker. It was created using one of the many virus-generating kits that are easily available on the Internet. The kits, which have names like Satanic Brain Virus Tools 1.0, Instant Virus Production Kit, and Ye Olde Funky Virus Generator, make writing a virus a straightforward and uncomplicated task. If you can install a program on a computer, you can also -- using one of these kits -- write and release a virus just like the authors of Cartman, Poppy and Kenny did. " The link at Wired is no longer available. . The rise of email worms like the Anna Kournikova worm underscores essential considerations for Linux systems' security and user practices against malware threats. Linux Threats, Email Worms, Malware Awareness. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.