Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity

    De-Worming Mail Servers

    Written by

    Dennis Fisher
    Published August 25, 2003
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Welcome to the summer of the Worm. Just eight days after Blaster began chewing its way through the Internet, another variant of the SoBig worm appeared last week, further burdening already-overworked IT and security staffs. As annoying and potentially dangerous as Blaster is, mass-mailing worms such as SoBig are perhaps worse from an enterprise perspective, thanks to their propensity for clogging mail servers and flooding users in-boxes with electronic flotsam.

      Worm food

      Recent outbreaks and their effects

      Virus

      Effects

      MiMail

      342,000 copies seen

      Blaster

      Approximately 400,000 machines infected

      SoBig.F

      380,000-plus copies

      Sources: MessageLabs, Symantec

      Known as SoBig.F, the new variant behaves much like its older siblings, infecting Windows machines via e-mail and sending out dozens of copies of itself.

      The variant began spreading on the morning of Aug. 19, and by noon, MessageLabs Inc. had stopped more than 100,000 copies. The virus size is approximately 73KB, and the attachment that actually contains the malicious code can carry any one of a number of names, according to iDefense Inc., a security company based in Reston, Va. To evade anti-virus scanners, SoBig.F has a few bytes of garbage at the end of the file, which changes the files size and characteristics.

      This is the sixth version of SoBig to be released. Anti-virus experts say one of the main reasons virus writers continue to modify and re-release this particular piece of malware is that it downloads a Trojan horse to infected computers, which are then used to send spam. Spammers are constantly in need of new machines through which to route their garbage e-mail, and a virus makes a perfect delivery mechanism for the engine they use for their mass mailings.

      The other reason that SoBig seems to be so popular with virus writers is that it works. Plain and simple, users continue to open attachments from people they dont know, even after repeated warnings not to do so.

      “Six times a charm when it comes to SoBig, which certainly calls into question why these fairly simple malware attacks continue to successfully propagate,” said Ian Hameroff, eTrust security strategist at Computer Associates International Inc., based in Islandia, N.Y.

      SoBig.Fs arrival comes just eight days after the initial onset of the Blaster worm, which has infected several hundred thousand Windows PCs. Blaster, which exploits a flaw in the Remote Procedure Call Distributed Component Object Model interface on Windows 2000 and Windows XP machines, also spawned an imitator last week. A worm known as Blaster.D, or Nachi, began spreading Aug. 18, using the same flaw to compromise systems. Nachi, however, also removed the original Blaster worm from infected PCs and attempted to download and install the patch from Microsoft Corp. for the DCOM vulnerability.

      Dennis Fisher
      Dennis Fisher

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×