Search:  

 
 
   News
newer
story category ISPs Battle Sober-Z
Also: 16,000 new viruses in 2005, threats up 48%
(old news - 06:50PM Tuesday Dec 06 2005)
tags: security · stats · software
A user writes: "So far, the Sober-Z worm has directly or indirectly disrupted email service for millions of subscribers at MSN, Hotmail, Comcast, Cogeco, and probably, Telewest. Email Battles notes that Telstra and Webcentral customers cannot be counted among the victims, as those ISPs have found other ways to deny service." Another user sends in stats from Sophos that say computer threats are up 48%, and there were 16,000 new viruses this year.

Related:
  1. Skype Could Hide Zombies
  2. Symantec: Apple Security Risk Rising
  3. Update Your Browser, Dummy
  4. Tuesday Evening Links
  5. Wednesday Evening Links
  6. FoxNews.com Serving Up Infected Ads?
  7. Android Climbs, But iPhone Remains King
  8. Uh, Mom? The Air Force Just Attacked Our PC
Forums » ISPs Battle Sober-Z
view: topics flat text 
Post a:

packetscan
Premium
join:2004-10-19
Bridgeport, CT
clubs:
·Optimum Online

Downtime

I know people on charter that haven't been able to hit MSN or hotmail in days.
(I'm not their tech, nor will I , I'm going word of mouth).

Time to Find a Mail server that doesn't have a TARGET on them.
--
Who do you want to pay off today?

a

@qwest.net

Re: Downtime

i remember the time when i was not literate and had to fight the virus issues.
B
Premium,MVM
join:2000-10-28

Fix Headline...

HotMail Servers Thwart Sober-Z
Did you mean "thwarted by"? "suffer"?

-- B
--
In a realm outside causality and function

Karl Bode
News Guy
join:2000-03-02

Re: Fix Headline...

Submittor had pulled it from e-mail battles. Changed it. Thanks.

trip

@netexpress.net

I think the Email Battles headline was intended to playfully imply that these ISPs had thwarted Sober by downing their servers with their own incompetence.

Gotta love the grammar police, but it'd be nice if they'd read the linked article before throwing stones.
B
Premium,MVM
join:2000-10-28

Re: Fix Headline...

trip, that's an awfully long stretch to interpret a headline, particularly when the word "thwart" was not placed in ironic quotes and the supposed sarcasm/playfulness you've pulled out of nowhere isn't supported in the body of the article.

Grammar police? You're an idiot. The headline just didn't make sense, and the news manager here agreed.

-- B
--
In a realm outside causality and function

Slowcook



Re: Fix Headline...

B, the EB headline ("Hot Mail Servers Thwart Sober-Z") is obtuse, especially if read "Hotmail," instead of "Hot Mail." I believe the idea is that Webcentral's data center was trashed by heat, not Sober. It's a play on words.

Of course, I had to read the full article in order to understand the headline.

GOLFnSUN
Enjoy the sun
Premium
join:2002-03-03
Avalon, NJ
·Sprint Mobile Broa..
·Comcast


1 edit

Clueless users still weak point in security

»www.pcpro.co.uk/news/81079/nearl···hos.html
Cluley is full of praise for Microsoft however - particularly for the success of Windows Service Pack 2. 'Microsoft should be applauded for improving its operating system, because it has made the Internet a safer place,' he said.

Two-thirds of Microsoft's own customers are not getting the message and shoring up the systems against the viral tide. No wonder it's bringing out its own OneCare antivirus solution for Windows users.

In fact, he thinks Microsoft is now doing such a good job on the security front that attackers will increasingly turn to applications and tools such as Google's Desktop Search as the vector for the next wave of attacks. 'They'll be looking for the add-ons and plug-ins that are popular, and used by lots of people, to find holes in and exploit,' he said.
Users are still their own worst enemy by running old out of date software; connecting to a broadband connection without a router/firewall; and not having an automatically updating antivirus program(even when there are good free ones available).
--
--
Join Red Room Forum
My Web Page

sdgthy

@optonline.net

Re: Clueless users still weak point in security

Far more so from simply running unknown attachments.

A certain Comcast user has been sending me the new Sober version virtually from the day it appeared. Even after I identified who it was, contacted them and provided a link to a removal tool. A week after the latter, they are still coming in.

Until ISP's start cutting off infected users, virii and worms will continue to cause issues like this.

Jafo232
You Can't Spell Democrat Without Rat.
Premium
join:2002-10-17
Boonville, NY

Hmm...

Hmm, no Gmail eh?

BeesTea
Network Janitor
Premium,VIP
join:2003-03-08
00000

16,000 new viruses

I wonder what percentage of these new viruses were just reconfigured/compiled variations of existing malware ?

It probably helps the bottom line to count every variant as a new virus if you're in the detection business, but I'd be interested in seeing some deeper data.
--
Captain of the ATU Tux Racer Clan.

toadlife
Premium
join:2004-05-03
Lemoore, CA
·AT&T Yahoo

Re: 16,000 new viruses

Yeah I think 15,320 of them are Sober variants. The Av companies have resorted to just attaching serial numbers to end end of each new version.

Sober-A156S53
Sober-A156S54
Sober....


--
Security is a process, not a Penquin.
ghost16825
Use security metrics
Premium
join:2003-08-26

said by BeesTea See Profile :

I wonder what percentage of these new viruses were just reconfigured/compiled variations of existing malware ?
It's really hard to give a short answer on this. If you're really interested check out F-secure's virus variant diagrams (through diary blog?). The first handful of variants are similar to the original virus, but you may be surprised to find out that that some Sober variants have more in common with Bagle variants and vice versa etc.

(Some of those wall charts look pretty funky too)
--
Admin of the Kerio 2x-like open source project:
http://sourceforge.net/projects/kerio/
http://kerio.sourceforge.net/
Pictor Guy

join:2004-06-21
Sammamish, WA

1 edit

eMail scans

So why aren't more ISPs being proactive and scan email for viruses like AOL and Google?
tbeckner

join:2004-03-20
Bend, OR

Re: eMail scans

said by Pictor Guy See Profile :

So why aren't more ISPs being proactive and scan email for viruses like AOL and Google?

You mean like MSN and Hotmail, which use TrendMicro.
-

jap
Premium
join:2003-08-10
038xx
·RoadRunner Cable

Re: eMail scans

said by tbeckner See Profile :

You mean like MSN and Hotmail, which use TrendMicro.
For real? That explains alot right there. I wouldda thought even MS was above TrendMicro.

sporkme
drop the crantini and move it, sister
Premium,MVM
join:2000-07-01
Morristown, NJ
·Optimum Online

...and the moron admins

The virus is bad enough, but that I can control.

One thing that really ticks me off are all the Exchange "Admins" that run some virus scanner that replies to each and every email with a "you sent and infected email" message. I get far more of that crap than the actual virus. In 1995 those messages were vaguely useful. In 2005 they are downright stupid as the "from" is always forged.

Anyone know of an RBL that targets servers that send AV bounces?
--
enjoy zesty ranch man-flavored baby tacos responsibly
tbeckner

join:2004-03-20
Bend, OR

Re: ...and the moron admins

said by sporkme See Profile :

One thing that really ticks me off are all the Exchange "Admins" that run some virus scanner that replies to each and every email with a "you sent and infected email" message.

Did you know that some of those "you sent an infected email" messages are virus generated and actually don't come from an AntiVirus program. The three Exchange servers I administer, only send notifications directly to me, but then again that is only if they get through the Anti-Spam and attachment filters first and do not come from an IP Address that has been identified as dynamic. [I sure wish the big e-mailers {COMCAST as an example} would be GOOD INTERNET CITIZENS and setup their SPF TXT records.]
-

rachelsfx

join:2004-09-27
Pensacola, FL

No worries here

I have AOL and ALL their protection. Boy, do I feel safe! ROFLMAO!
Forums » ISPs Battle Sober-Z


Sunday, 08-Nov 08:48:05 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.