Free Republic
Browse · Search
News/Activism
Topics · Post Article

To: Nick Danger
For example, the supposed DDOS attack on Microsoft was not in the original worm; it was added yesterday by sending out a new worm that scans for old worms, and tells them to update themselves with this, where "this" is whatever the guy wants to add.

It's my understanding that W32.Mydoom.B (the one that includes DoS's against both SCO AND Microsoft)is a whole new variation of W32.NovargA (the original MyDoom SCO worm)and is not, to my knowledge, "updating" the original package in the wild. If you have information to the contrary, I'd be interested in seeing it.

42 posted on 01/29/2004 3:32:02 PM PST by Leroy S. Mort
[ Post Reply | Private Reply | To 36 | View Replies ]


To: Leroy S. Mort
is not, to my knowledge, "updating" the original package in the wild. If you have information to the contrary, I'd be interested in seeing it.

From the discussion of Novarg.B on Symantec Security Response (see #11):

The worm also contains functionality which allows it to install itself on systems which may have been infected by W32.Novarg.A@mm. This is accomplished as follows:

So basically this guy can send out a new worm at any time to modify the behavior of the old worms. I think it's against the law in the United States to invade someone else's computer, but perhaps a "white hat" in some other country could send out an update that kills this thing, and then deletes itself.

46 posted on 01/29/2004 4:00:05 PM PST by Nick Danger ( With sufficient thrust, pigs fly just fine.)
[ Post Reply | Private Reply | To 42 | View Replies ]

Free Republic
Browse · Search
News/Activism
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson