Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

'Sobig' virus traced to Canadian computer
Ottawa Citizen ^ | August 23, 2003 | Brian Krebs and Joseph Menn, with files from Jason Fekete

Posted on 08/23/2003 5:38:47 PM PDT by gitmo

The fastest spreading Internet virus in history, one that experts feared would paralyse the Internet in an attack scheduled for yesterday afternoon, originated on the personal computer of an unwitting user in B.C., authorities said last night.

The "Sobig" worm, which fizzled yesterday when the 'trojan horse'-type program did nothing more than direct users to an Internet porn site, has bombarded computers with almost 100 million junk messages since Tuesday.

The worm ordered infected Windows machines to download a mysterious program yesterday at 3 p.m.

Even at the cusp of the hour, experts remained in the dark as to the purpose of that unknown program.

But rather than erase files, pilfer passwords or create rogue e-mail servers to spread junk messages -- as experts feared -- the virus made an unexpected turn and download an address for an adult Web site.

"There is nothing malicious, just a standard sex site," said Vincent Weaver, security director with Symantec Security Response, an anti-virus software maker.

Still, experts stress there may be other Sobig variants that harbour other more insidious instructions.

Security experts contained the virus by identifying and blocking as many as 19 out of 20 home computers located mainly in Canada and the U.S. that hundreds of thousands of infected PCs were told to contact, said Symantec representatives. The computers were to provide the infected PCs with an address where new and possibly dangerous software could be downloaded.

One of the 20 computers that remained online passed on the porn site address that experts believed to be benign, said Symantec senior director Stephen Trilling. Sobig instructed computers to keep trying to reach the computers every Friday and Sunday until its expiration Sept. 10, Mr. Trilling said.

Meanwhile, the FBI yesterday served a grand jury subpoena on Easynews.com, a Phoenix-based Internet service provider whose network may have been used to disseminate Sobig. The virus is believed to have been released onto Usenet, a kind of Internet bulletin board, by someone with an account at the service provider, according to Michael Minor, the company's co-owner. A stolen credit card number was used to create the account minutes before the virus was unleashed on Monday, Minor said. His company is co-operating with the FBI, he added.

A computer in British Columbia was apparently used to create the account. Experts said the computer belongs to an innocent home user who was hit by a previous version of the virus that allowed the clandestine programmer to seize control of the computer. That makes catching the writer of the virus more difficult, experts said.

The New York Times said computers at its offices in New York City were shut down when they "experienced difficulties" shortly after noon yesterday, but the company wouldn't say for certain that Sobig was the cause but did stress that it would publish today's edition.

The Sobig virus was part of an onslaught of rogue computer programs -- including a form of the Blaster worm which appeared last week -- that have snarled computer networks and disrupted commercial infrastructure over the past two weeks.

Sobig and two other viruses tried to attack the City of Ottawa's 8,000 computer systems yesterday, overwhelming computers and producing customer service interruptions at the city's seven client centres.

The Welchia and Blaster worm viruses, which have been targeting hundreds of thousands of computers around the world, are having the most impact by interrupting the city's services.

The crawlers discreetly use a person's computer to launch Internet-based attacks against other systems or can automatically download massive files, snarling Internet traffic and creating system failures.

System interruptions at the city were first noticed yesterday around 9 a.m. and continued throughout the day, said Michelle Grégoire, manager of the service centres.

"Clients who had bills and tickets with them were able to pay them. We could still do marriage licenses and general employment information," she said. "What we weren't able to do was look up inquiries into the tax system, water system or parking ticket system. We couldn't access that data, so those questions couldn't be answered."

Customers were also unable to access building permits due to system failures, she said.

The city's technical staff said it will likely take most of the weekend to eradicate the viruses, but expect systems will be fully operational by Monday.


TOPICS: Breaking News; Business/Economy; Canada; Crime/Corruption; Culture/Society; Miscellaneous; News/Current Events; Technical
KEYWORDS: porn; sobig; worm
Navigation: use the links below to view more comments.
first previous 1-2021-4041-53 next last
To: gitmo
Is it safe to get out of the shower now?
21 posted on 08/23/2003 6:26:20 PM PDT by Mad_Tom_Rackham
[ Post Reply | Private Reply | To 1 | View Replies]

To: Mad_Tom_Rackham
Are your fingers wrinkly?
22 posted on 08/23/2003 6:31:57 PM PDT by null and void (I learned all I needed to know when a møøselimb co-worker objected to my cubicle Flag. On 9/12!)
[ Post Reply | Private Reply | To 21 | View Replies]

To: PFKEY
"I wonder what it is the FBI looks for when executing this grad jury subpoena?"

I don't think I'd want a jury made up of grad students...

--Boris

23 posted on 08/23/2003 6:37:03 PM PDT by boris (Education is always painful; pain is always educational.)
[ Post Reply | Private Reply | To 14 | View Replies]

To: boris
I don't know Boris. Having seen a few jury pools of 'peers' I think I might just take one of grad students.
24 posted on 08/23/2003 6:41:55 PM PDT by PFKEY
[ Post Reply | Private Reply | To 23 | View Replies]

To: livius
Several articles I've read indicated that the infamous 20 computers were in the US, Canada and South Korea.

I wonder whether SoBig.F will attempt to access the same IPs on the second/third/fourth runs or whether the code is self modifying and it will look for different ones. Also, IIRC, terrorists have been known to communicate through messages hidden in porn images. I don't necessarily see anything comforting in the fact that SoBig.F pointed to a porn site.

25 posted on 08/23/2003 6:45:34 PM PDT by FourPeas
[ Post Reply | Private Reply | To 16 | View Replies]

To: Jim Robinson
sooo... this was just a trial run perhaps?
26 posted on 08/23/2003 7:00:47 PM PDT by Robert_Paulson2
[ Post Reply | Private Reply | To 5 | View Replies]

To: gitmo
Today alone I've rec'd over 65 emails with Sobig Worm in the subject line. I've been bouncing and deleting ASAP. Yesterday, I contended with about 17.
27 posted on 08/23/2003 7:09:04 PM PDT by lilylangtree
[ Post Reply | Private Reply | To 1 | View Replies]

To: I still care
Can you say "Class Action Suit" boys and girls?

I knew you could (providing the FBI catches and prosecutes someone).

By the way, Macs don't get this virus.
28 posted on 08/23/2003 7:15:27 PM PDT by Coyoteman
[ Post Reply | Private Reply | To 8 | View Replies]

To: Coyoteman
****By the way, Macs don't get this virus.****

SHHHHHHHHHH! We Mackers don't want them to know. They just get jealous and say mean things.
29 posted on 08/23/2003 8:01:01 PM PDT by kitkat
[ Post Reply | Private Reply | To 28 | View Replies]

Comment #30 Removed by Moderator

To: Coyoteman
By the way, Macs don't get this virus.

No -- but we still have to cope with receiving dozens of copies of these emails on a daily basis. And if you're on a slow dial-up connection, it's a real pain.

31 posted on 08/24/2003 12:05:45 AM PDT by Brandon
[ Post Reply | Private Reply | To 28 | View Replies]

To: Yehuda
"The New York Times said computers at its offices in New York City were shut down when they "experienced difficulties"
TFB

Well, you know what they say: every cloud has a silver lining!

32 posted on 08/24/2003 12:07:03 AM PDT by Brandon
[ Post Reply | Private Reply | To 30 | View Replies]

To: All
http://www.freerepublic.com/focus/f-news/969366/posts
Worm and Virus Wars- the August Edition
various FR links & posts | 08-23-03 | The Heavy Equipment Guy
33 posted on 08/24/2003 12:28:19 AM PDT by backhoe
[ Post Reply | Private Reply | To 1 | View Replies]

To: livius
Yep, I agree. And they arrested a group of 19 terrorist suspects in Canada on Friday as well. If anyone has NOT read that thread, you should.

The 19 guys who were arrested in Canada lived together in groups of 4's and 5's... and when one group of them moved out of their apartments suddenly, they left everything behind except the hard drives of their computers. They even left the shells of the computers. Other groups of them had only a mattress on the floor and computers... One of them was taking flight lessons (for 3 years, when the average student takes only 1 year to complete the courses). The flight line for the school was over a nuclear power plant. The student pilot always took an unknown friend with him (so he could ride in the back and take notes on the nuclear power plant??). Oh, and let's not forget two of their friends who were caught by police at the front gate of the nuclear power plant, asking if they could get inside so they could "take a walk on the beach."

34 posted on 08/24/2003 12:29:10 AM PDT by BagCamAddict
[ Post Reply | Private Reply | To 16 | View Replies]

To: All; piasa; backhoe; HAL9000; JohnHuang2; kattracks; sarcasm; Marine Inspector; JohnathanRGalt; ...
FYI Links...


SEPTEMBER 11, 2001: "ATTACK ON AMERICA!" (updated)

An Interesting Discussion on FREEREPUBLIC.com regarding an ABCnews.go.com article by Alexandra Salomon: "Terrorists' Twin Tower Images, Secret Porn Messages" (May 8, 2003)

35 posted on 08/24/2003 1:51:40 AM PDT by Cindy
[ Post Reply | Private Reply | To 1 | View Replies]

To: Cindy; All
There are some different resources listed here:

http://www.freedominion.ca/phpBB2/viewtopic.php?t=13655
Has anyone HERE been hit with one of these WORMS...???
36 posted on 08/24/2003 2:05:36 AM PDT by backhoe (Earth First! ( We'll strip-mine the other planets later...))
[ Post Reply | Private Reply | To 35 | View Replies]

To: gitmo
Canada sends SoBig, Canada's power grid goes out, ladida?
37 posted on 08/24/2003 3:08:09 AM PDT by JustPiper (The Free Republic of America! "W" is our President !!!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: backhoe
Has anyone HERE been hit with one of these WORMS...???

Penguins don't get worms.

(Heh, heh, heh, heh...)

38 posted on 08/24/2003 6:13:16 AM PDT by Redcloak (All work and no FReep makes Jack a dull boy. All work and no FReep make s Jack a dul boy. Allwork an)
[ Post Reply | Private Reply | To 36 | View Replies]

To: JustPiper
Why do you think the first variant was called "SoBig dot ehhh"? :)
39 posted on 08/24/2003 7:44:47 AM PDT by lelio
[ Post Reply | Private Reply | To 37 | View Replies]

To: Yehuda
"The New York Times said computers at its offices in New York City were shut down when they "experienced difficulties"

Yeah, right. Probably all the writers, editors and higher ups at the Times were using "the e-mail directed me" excuse to view porn sites at work........

40 posted on 08/24/2003 8:20:59 AM PDT by b4its2late (All true wisdom is found on T-shirts.)
[ Post Reply | Private Reply | To 30 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-53 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson