Go Back   Velocity Reviews > Newsgroups > Computer Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

Computer Security - more on the mass mailing

 
Thread Tools Search this Thread
Old 09-19-2003, 04:37 PM   #1
Default more on the mass mailing


WOW! Whoever/whatever is really pounding out those MS looking messages. I
got about 200 yesterday, and that many in just a few hours this morning.
Today, I noted a few variants of the purported sender, and the subject topic
lines. It's like the sender figured after awhile, with enough people
getting those, they would start to put filter rules into place. So,
changing those parameters would defeat the filter rules.

What are the mechanics of this thing? What kind of setup does it take to
reach out to millions of email addresses with repeat messages with munged
originator addresses on them?

Also, the creator of this attack is no amateur. Whoever's behind this one
has the ability to make the message presented appear professional. Matter
of fact, it is a complex one in that it has options you can choose,
reinforcing its realistic look.




RB
  Reply With Quote
Old 09-19-2003, 09:12 PM   #2
donut
 
Posts: n/a
Default Re: more on the mass mailing
"RB" <> wrote in news:bkf7rb$hjh$:

>
> What are the mechanics of this thing? What kind of setup does it take to
> reach out to millions of email addresses with repeat messages with munged
> originator addresses on them?


Why don't you learn something about viruses before you pop off in a
newsgroup like this and show everybody just how ignorant you are?


donut
  Reply With Quote
Old 09-21-2003, 12:14 PM   #3
=?ISO-8859-1?Q?Andr=E9_Franke?=
 
Posts: n/a
Default Re: more on the mass mailing
"RB" <> wrote before:


>What are the mechanics of this thing? What kind of setup does it take to
>reach out to millions of email addresses with repeat messages with munged
>originator addresses on them?


It's rather simple:
http://www.trendmicro.com/vinfo/viru...SWEN.A&VSect=T

The worm just scans files on the infected system which may contain
e-mail addresses and also your browsers cache (since nearly every web
document nowadays contains at least one valid address).
That way it gathers some 200 to 300 addresses on one system.
Also it propagates through your LAN using network shares and through
mIRC. And it scans some 150 or so newsservers for e-mail adresses (we
seem to have figured out that it ignores addresses containing the
string "spam").
Well now it has some 500 addresses or so to send a copy of itself to.
Let's just calculate:
|1System->500Mails->(500x500)25,000Mails->(25,000x500)1,250,000Mails
Well let's say it only gathers 200 addresses and is only able to
infect 25% of the addressed systems:
|1System->200Mails->(50x200)10,000Mails->(2,500x200)50,000Mails
Previous worms only scanned the addressbooks and/or brought an own
(static/dynamic) database. If we do assume that only 25% get infected
thats rather ineffective.
Addressbooks:
|1System->10Mails->(2x10)20Mails->(5x10)50Mails
Static DB of 300 adresses:
|1System->300Mails->(75x300)22,500Mails->(75x300)22,500Mails
/
/
From that point on the number of hosts spreading the worm is
decreasing, since the users will notice the infection and remove it,
while the still uninfected hosts stay protected. No new adresses are
added to the static DB and no new hosts will be infected.
That's why the programmer of worms always used a combination aof
addressbook scans and a dynamic DB, but it kept being ineffective due
to the small number of addresses gathered on each infected system.

regards
André


=?ISO-8859-1?Q?Andr=E9_Franke?=
  Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
PETITION TO STOP BUSH'S DRAFT jasmine DVD Video 148 11-23-2004 07:05 AM
DVD Verdict reviews: RUSTLER'S RHAPSODY, ANTHRAX: MUSIC OF MASS DESTRUCTION, and more! DVD Verdict DVD Video 4 06-11-2004 02:35 AM
Re: Weapons of Mass Destruction - FOUND! - Faulty DVD? Dr. Speedbyrd:> DVD Video 0 06-29-2003 05:09 AM
Re: Weapons of Mass Destruction - FOUND! - Faulty DVD? DarkMatter DVD Video 0 06-28-2003 11:26 PM
Re: Weapons of Mass Destruction - FOUND! - Faulty DVD? Max Volume DVD Video 0 06-28-2003 10:52 PM




SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46