Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

'Sobig' virus traced to Canadian computer
Ottawa Citizen ^ | August 23, 2003 | Brian Krebs and Joseph Menn, with files from Jason Fekete

Posted on 08/23/2003 5:38:47 PM PDT by gitmo

The fastest spreading Internet virus in history, one that experts feared would paralyse the Internet in an attack scheduled for yesterday afternoon, originated on the personal computer of an unwitting user in B.C., authorities said last night.

The "Sobig" worm, which fizzled yesterday when the 'trojan horse'-type program did nothing more than direct users to an Internet porn site, has bombarded computers with almost 100 million junk messages since Tuesday.

The worm ordered infected Windows machines to download a mysterious program yesterday at 3 p.m.

Even at the cusp of the hour, experts remained in the dark as to the purpose of that unknown program.

But rather than erase files, pilfer passwords or create rogue e-mail servers to spread junk messages -- as experts feared -- the virus made an unexpected turn and download an address for an adult Web site.

"There is nothing malicious, just a standard sex site," said Vincent Weaver, security director with Symantec Security Response, an anti-virus software maker.

Still, experts stress there may be other Sobig variants that harbour other more insidious instructions.

Security experts contained the virus by identifying and blocking as many as 19 out of 20 home computers located mainly in Canada and the U.S. that hundreds of thousands of infected PCs were told to contact, said Symantec representatives. The computers were to provide the infected PCs with an address where new and possibly dangerous software could be downloaded.

One of the 20 computers that remained online passed on the porn site address that experts believed to be benign, said Symantec senior director Stephen Trilling. Sobig instructed computers to keep trying to reach the computers every Friday and Sunday until its expiration Sept. 10, Mr. Trilling said.

Meanwhile, the FBI yesterday served a grand jury subpoena on Easynews.com, a Phoenix-based Internet service provider whose network may have been used to disseminate Sobig. The virus is believed to have been released onto Usenet, a kind of Internet bulletin board, by someone with an account at the service provider, according to Michael Minor, the company's co-owner. A stolen credit card number was used to create the account minutes before the virus was unleashed on Monday, Minor said. His company is co-operating with the FBI, he added.

A computer in British Columbia was apparently used to create the account. Experts said the computer belongs to an innocent home user who was hit by a previous version of the virus that allowed the clandestine programmer to seize control of the computer. That makes catching the writer of the virus more difficult, experts said.

The New York Times said computers at its offices in New York City were shut down when they "experienced difficulties" shortly after noon yesterday, but the company wouldn't say for certain that Sobig was the cause but did stress that it would publish today's edition.

The Sobig virus was part of an onslaught of rogue computer programs -- including a form of the Blaster worm which appeared last week -- that have snarled computer networks and disrupted commercial infrastructure over the past two weeks.

Sobig and two other viruses tried to attack the City of Ottawa's 8,000 computer systems yesterday, overwhelming computers and producing customer service interruptions at the city's seven client centres.

The Welchia and Blaster worm viruses, which have been targeting hundreds of thousands of computers around the world, are having the most impact by interrupting the city's services.

The crawlers discreetly use a person's computer to launch Internet-based attacks against other systems or can automatically download massive files, snarling Internet traffic and creating system failures.

System interruptions at the city were first noticed yesterday around 9 a.m. and continued throughout the day, said Michelle Grégoire, manager of the service centres.

"Clients who had bills and tickets with them were able to pay them. We could still do marriage licenses and general employment information," she said. "What we weren't able to do was look up inquiries into the tax system, water system or parking ticket system. We couldn't access that data, so those questions couldn't be answered."

Customers were also unable to access building permits due to system failures, she said.

The city's technical staff said it will likely take most of the weekend to eradicate the viruses, but expect systems will be fully operational by Monday.


TOPICS: Breaking News; Business/Economy; Canada; Crime/Corruption; Culture/Society; Miscellaneous; News/Current Events; Technical
KEYWORDS: porn; sobig; worm
Navigation: use the links below to view more comments.
first previous 1-2021-4041-53 last
To: b4its2late
Computers probably rejected the day's propaganda.. "ERROR - ERROR - DOES NOT COMPUTE"
41 posted on 08/24/2003 9:34:34 AM PDT by thoughtomator (Are we conservatives, or are we Republicans?)
[ Post Reply | Private Reply | To 40 | View Replies]

To: gitmo
This just in...

Viruses and Porn Sites are linked.

Who would have thought?
42 posted on 08/24/2003 9:51:53 AM PDT by DannyTN (Note left on my door by a pack of neighborhood dogs.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: lilylangtree
When you say "bouncing", do you mean that you've been sending them back to the sender?

If so, that's not helping much. As I recall, this virus forges the sending address. It picks two random email addresses from those that it finds laying about in files on an infected PC, sending a copy of itself to one of the addresses, claiming to be sent from the other.

So sending complaints to the apparent sender is just more noise.

43 posted on 08/24/2003 12:53:28 PM PDT by ThePythonicCow (Mooo !!!!)
[ Post Reply | Private Reply | To 27 | View Replies]

To: Pharmboy
My EYESSSSSSSSSSSSSSSSSSSSSS!!!!!!!!!!!!!!!!
44 posted on 08/24/2003 3:57:33 PM PDT by alwaysconservative (Better living through denial)
[ Post Reply | Private Reply | To 19 | View Replies]

To: backhoe
I happen to be one of the poor schmucks whose email was plucked at random as the "sender" address for this thing. I've gotten about a dozen undeliverable/bouncebacks that I never sent, all with a fat worm enclosure file.
45 posted on 08/24/2003 6:04:58 PM PDT by ZviTheWise ("Everybody in this house needs to calm down and eat some fruit or something." -- Mel Gibson, "Signs")
[ Post Reply | Private Reply | To 36 | View Replies]

To: Pharmboy
Good God, man, that was obscene beyond my wildest imagination.

Have you no decency sir? At long last, have you no decency?

46 posted on 08/24/2003 6:16:00 PM PDT by Imal (The World According to Imal: http://imal.blogspot.com)
[ Post Reply | Private Reply | To 19 | View Replies]

To: kitkat
My grand daughter called me Monday and said her pc was crashing on bootup and she couldn't get on line long enough to download a fix. She (they) have cox.net with a linkys router to run a old iMac in another room. I told her to use the Mac to get the instructions for the fix so she could get the pc online long enough to download all the patches. It worked. If the mac had a floppy she could hve done it that way also. I LOVE MY MAC...
47 posted on 08/24/2003 7:12:56 PM PDT by tubebender (wait)
[ Post Reply | Private Reply | To 29 | View Replies]

To: tubebender
Oh, COOL!

I LOVE MY MAC, too. I used Windows for ten years , and recently switched. It's an OSX, and besides being dependable, it also takes up so much less space on my desk. I do admit that learning OSX is a challenge, but I'm getting there.

Bet your granddaughter was thrilled that you got her back on line.
48 posted on 08/24/2003 7:58:46 PM PDT by kitkat
[ Post Reply | Private Reply | To 47 | View Replies]

To: kitkat; tubebender
Bump.
49 posted on 08/24/2003 9:07:54 PM PDT by First_Salute
[ Post Reply | Private Reply | To 48 | View Replies]

To: gitmo
bump and thanks.
50 posted on 08/25/2003 6:07:15 AM PDT by wasp69 (Remember, Uday in Pig Latin is DU)
[ Post Reply | Private Reply | To 12 | View Replies]

the virus made an unexpected turn and download an address for an adult Web site.

The virus is quite possibly work for hire by a spammer. I assume law enforcement are investigating the site that received this traffic.

51 posted on 08/25/2003 7:06:48 AM PDT by D-fendr
[ Post Reply | Private Reply | To 50 | View Replies]

To: Cindy
Thanks for posting the links Cindy.

Got 'em bookmarked!
52 posted on 08/25/2003 10:50:43 AM PDT by appalachian_dweller (If we accept responsibility for our own actions, we are indeed worthy of our freedom. – Bill Whittle)
[ Post Reply | Private Reply | To 35 | View Replies]

To: appalachian_dweller
re post no. 52...You're welcome.
53 posted on 08/25/2003 1:48:34 PM PDT by Cindy
[ Post Reply | Private Reply | To 52 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-53 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson