Stories
Slash Boxes
Comments

News for nerds, stuff that matters

Another Nasty Outlook Virus Strikes

Posted by timothy on Sun Jul 22, 2001 11:32 PM
from the hide-the-children-get-the-gun dept.
Goldberg's Pants writes: "ZDNet and Wired are both reporting on a new virus that spreads via Outlook. Nothing particularly original there, except this virus is pretty unique both in how it operates, and what it does, such as emailing random documents from your harddrive to people in your address book, and hiding itself in the recycle bin which is rarely checked by virus scanners." I talked by phone with a user whose machine seemed determined to send me many megabytes of this virus 206k at a time; he was surprised to find that his machine was infected, as most people probably would be. The anti-virus makers have patches, if you are running an operating system which needs them.
This discussion has been archived. No new comments can be posted.
Another Nasty Outlook Virus Strikes | Log In/Create an Account | Top | 388 comments (Spill at 50!) | Index Only | Search Discussion
Display Options Threshold:
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
(1) | 2 | 3 | 4 | 5 | 6
  • Re:How long? by Anonymous Coward (Score:1) Sunday July 22 2001, @08:35PM
  • Re:solution: don't use outlook by Anonymous Coward (Score:1) Sunday July 22 2001, @09:39PM
  • Re:There was an old DOS virus like that by Anonymous Coward (Score:1) Monday July 23 2001, @12:04AM
  • Re:Sheesh... by Anonymous Coward (Score:1) Monday July 23 2001, @12:06AM
  • Re:It's the OS, stupid. by Anonymous Coward (Score:1) Monday July 23 2001, @12:14AM
  • Re:What does your post have to do with the OS? by Anonymous Coward (Score:1) Monday July 23 2001, @04:19AM
  • Re:What does your post have to do with the OS? by Anonymous Coward (Score:1) Monday July 23 2001, @09:09AM
  • Re:It's the culture, stupid. by Anonymous Coward (Score:2) Sunday July 22 2001, @08:07PM
  • Re:An observation... by Anonymous Coward (Score:2) Sunday July 22 2001, @08:47PM
  • Re:solution: don't use outlook by Anonymous Coward (Score:2) Sunday July 22 2001, @08:48PM
  • Re:solution: don't use outlook by mosch (Score:1) Sunday July 22 2001, @09:11PM
  • Re:unfortunately, by mosch (Score:2) Sunday July 22 2001, @09:41PM
  • Re:How long? by abischof (Score:2) Monday July 23 2001, @04:44AM
  • Re:These virus writers have no imagination... by Alan (Score:1) Monday July 23 2001, @07:39AM
  • by Alex Belits (437) on Sunday July 22 2001, @08:28PM (#68069) Homepage

    I have received the first email sent by that thing three days ago and reported some brief analysis to bugtraq, got a "rejected, send to incidents" response, sent to incidents [denver.co.us], and apparently there is still nothing in the archives -- I have no idea why, incidents list posts all kinds of "I have seen a big spider hanging over my keyboard, I think he tried to hack me" stuff.

    .

    For everyone interested, messages with virus and extracted infected documents are here [denver.co.us].

  • Re:documents by caferace (Score:1) Sunday July 22 2001, @08:48PM
  • by jbuhler (489) on Sunday July 22 2001, @09:13PM (#68071) Homepage
    > Why can't these virus writers do something cool?

    You don't want virus writers with imagination. You *really* don't. A truly imaginative virus writer would likely devote all sorts of creative energy toward thinking up nasty things to do to your computer.

    I'm still waiting for the trojan that silently installs itself, then once every day looks for spreadsheets on your system and randomly changes three numbers in every fifth file. Or perhaps it finds your Word documents and randomly removes the words "do not" from a few places. Or maybe it flips a few bits in your swap file, or munges your C++ compiler so that your programs randomly destroy the user's partition table one time out of a thousand. Maybe it sends death threats in your name to president@whitehouse.gov, or anonymously tells Microsoft that your company is pirating Windows.

    No, I'm quite happy with the current crop of dull, stolid, entirely *un*imaginative virus writers, thank you very much!
  • Re:MacOS (Score:3)

    by Chris Johnson (580) on Sunday July 22 2001, @11:15PM (#68072) Homepage
    Depends on how you look at it.

    I'm on MacOS using _eudora_ and all these sorts of files are dead inanimate matter to me.

    Almost a megabyte of dead inanimate matter over a 56K modem just since this afternoon alone...

    I am _so_ _pissed_ _off_ at this crap. I've taken to spamcopping the victims, using this note to their postmasters (where applicible):

    "Please suspend this user's account. They are propagating the SirCam worm, and that must stop directly.
    -postmaster@airwindows.com"

    I have it as a clipping ready to be dragged into the spamcop personalize box, which is what I do when I am so overloaded with spam that I can't get time to type, but not so overloaded that I just give up- which has been the case until recently and this is what brought me back into the fray. _I_ _hate_ _this_... can't we declare Outlook illegal or something? Classify it as a weapon for denial of service attacks.

  • Re:An observation... by shogun (Score:1) Sunday July 22 2001, @10:06PM
  • Re:This isn't really an Outlook worm! by Pinky (Score:1) Monday July 23 2001, @05:49PM
  • Re:solution: don't use outlook by drsoran (Score:1) Sunday July 22 2001, @07:50PM
  • Re:But Unix has been able to do this for 30+ years by extra88 (Score:2) Monday July 23 2001, @04:49AM
  • OK, so you've shown that if a friend emails you a suspicious .exe, you create a phony account with no permissions then run it from that account. This is also possible in Win2K and Windows XP. So what's your point?

    So why doesn't Outlook do this automatically? Seriously - Outlook could set up a dummy user account at installation time and whenever an attachment is to be executed it could use the previously created dummy user to execute it. To all the posters who wrote that setting up a dummy user to execute attachments is too hard for most users, too cumbersome, or too inconvenient, what's the problem if this is built into Outlook and transparent to the user?

  • there's a mushware version, too by hawk (Score:2) Monday July 23 2001, @08:55AM
  • good bloody luck . . . by hawk (Score:2) Monday July 23 2001, @09:03AM
  • by hawk (1151) <hawk@eyry.org> on Monday July 23 2001, @09:00AM (#68080) Journal
    > You don't want virus writers with imagination. You *really* don't.


    absolutely not. One of the things I learned practicing law is that the reason we're not in serious danger from the criminal element is because *criminals are stupid*. They don't draw the connection between crime and punishment. THeir planning is lousy. I actually had one where five of them stole 70,000 (using my client's mother'ss car as a getaway vehicle), and each took their $5,000 share. It took the police ten minutes to get it through to them that the ringleader ripped them off.


    Or the one that had to be rescued by the police after getting toasted, robbing a bar with a toy uzi, and then *going back in*, whereupon it was recognized and he was stabbed nearly to death . . .


    If they had what we generally think of as "Average intelligence," we'd be in serious trouble (of course, this would in many cases keep them from criminal behgavior, too).


    virus writers are just another kind of criminal . . .


    hawk, esq., etc.

  • But Unix has been able to do this for 30+ years! by Omega (Score:1) Monday July 23 2001, @04:21AM
  • Devil's Advocate (Score:5)

    by Outlyer (1767) on Sunday July 22 2001, @07:58PM (#68082) Homepage
    Ok, I have to respond to some of the folks here who believe that "Don't run Outlook" is an option. Well, pray tell, what should I do if I'm on a corporate Exchange server? With no other option? It's all well and good to suggest things, but the fact is, if the Exchange Admin won't use LDAP, you're out of luck, and quite stuck.

    That said, the SP2 release of Office/Outlook prevents anything from accessing your address book, and will pop up a confirmation. It doesn't prevent idiots from opening the attachments, but it does create some thought beforehand.

    I can appreciate the idealism of using Linux for everything (I'm a Debian developer for god's sake) but for my job, I have to use Outlook, so I do, because I like my job, and I'm not going to quit because of that minor inconvenience.

    I suppose this qualifies as a rant, and possibly will be modded to "Flamebait" or "Troll" but let's try and tolerate some dissent on this board for a change.
  • Re:Devil's Advocate by iabervon (Score:2) Monday July 23 2001, @06:30AM
  • Re:Devil's Advocate by iabervon (Score:2) Tuesday July 24 2001, @08:45AM
  • Serious Solutions? by vinod (Score:1) Sunday July 22 2001, @08:23PM
  • Re:Why continue using Outlook? by Eric E. Coe (Score:1) Sunday July 22 2001, @09:40PM
  • Re:Why continue using Outlook? by Eric E. Coe (Score:1) Monday July 23 2001, @06:31AM
  • Re:Yeah, I got a couple this evening by jonabbey (Score:1) Sunday July 22 2001, @08:34PM
  • Yeah, I got a couple this evening by jonabbey (Score:2) Sunday July 22 2001, @07:38PM
  • Someone did... by cirby (Score:1) Monday July 23 2001, @06:11AM
  • by sphealey (2855) on Monday July 23 2001, @04:20AM (#68091)
    >This isn't a problem with Outlook, it's a problem with idiot users clicking on every damn thing they're emailed.
    >>Furthermore, Outlook actually helps out the "idiot" users.

    There is a principle in the Toyota Production System that goes something like this: "If a worker makes a mistake once, it may be the workers fault. If a worker makes a mistake twice, it is the supervisors fault. If a worker makes a mistake three times, it is management's fault".

    Most human beings on the face of the earth are not technically minded and DO NOT WANT to understand the details of how the tools they use work. If every time Joe Homeowner flipped on a light switch there was a 1% chance of a nuclear power plant melting down, we wouldn't be using much electricity, now would we?

    While Microsoft is to blame for creating insecure tools (keeping in mind that larger market share means more attaraction for attackers), responses along the line of "stupid users don't understand how to use e-mail" are not acceptable, either.

    sPh
  • How 'bout several alternatives... by Svartalf (Score:2) Monday July 23 2001, @07:48AM
  • Win2k running idle IIS by default...yeah, but... by Tumbleweed (Score:2) Sunday July 22 2001, @10:47PM
  • Re:These virus writers have no imagination... by Joe Decker (Score:1) Sunday July 22 2001, @07:56PM
  • Re:The depressing thing about these worms... by Joe Decker (Score:1) Sunday July 22 2001, @08:31PM
  • Re:Exchange Calendar is BROKEN. by Joe Decker (Score:1) Monday July 23 2001, @05:38AM
  • Re:Exchange Calendar is BROKEN. by Joe Decker (Score:1) Monday July 23 2001, @09:10AM
  • Re:Why continue using Outlook? by Joe Decker (Score:2) Sunday July 22 2001, @07:49PM
  • Re:Sheesh... (Score:4)

    by Joe Decker (3806) on Sunday July 22 2001, @07:52PM (#68099) Homepage
    ...it's somewhat ironic that the Slashdot editors don't know the difference between a "Virus" and a "Trojan".

    Seems like folks using a "Trojan" should be safe from getting a "Virus". :-)

    --j

  • Re:What does your post have to do with the OS? by RelliK (Score:2) Monday July 23 2001, @11:17AM
  • Re:solution: don't use outlook by crisco (Score:2) Sunday July 22 2001, @09:19PM
  • File extension (Score:3)

    by crisco (4669) on Sunday July 22 2001, @09:16PM (#68102) Homepage
    The 2 copies I received had the extension .pif. Windows hid that extension from me, only displaying filename.doc. Pegasus Mail displays the entire filename.

    Windows also brought up a different right click context menu with the file.

    don't ask about accidently double clicking the thing...

    Chris Cothrun
    Curator of Chaos

  • Re:unfortunately, by johnnyb (Score:2) Monday July 23 2001, @05:09AM
  • Re:Unthinkable - Thinkable by Francis (Score:1) Sunday July 22 2001, @11:50PM
  • Re:The Microsoft Patch by Francis (Score:1) Monday July 23 2001, @09:54PM
  • The Microsoft Patch by Francis (Score:2) Sunday July 22 2001, @08:09PM
  • Re:Im sticking with Outlook by ZxCv (Score:1) Tuesday July 24 2001, @06:08PM
  • by ZxCv (6138) on Sunday July 22 2001, @08:45PM (#68108) Homepage
    I've been using Outlook for far too long and get far too much functionality out of it to switch to another app because macro viruses for it are spreading. I've got the ultimate in Outlook macro virus protection-- it's called a BRAIN.

    First off, the only way to make macro capabilities even worth a damned was to include functionality that could also possibly be used for - *gasp* - viruses! Oh no! Shit man, big deal. Why is it that I can look at the attachments on my emails and plainly see an attachment that ends with .vbs, yet somehow others cannot? These viruses are the tamest you could ask for-- don't run the damned script file and you won't be infected! Oh wow! True genius, I know!

    I certainly understand that these viruses are capable of creating better disguised files (such as spreadsheets with autorun macros), but every Office app has an option to NOT autorun macros. IIRC, this is the default option (at least on Office 2000-- havent touched XP). And beyond that, that virus started off at some point as a script file. It took some jackass who wasn't paying attention to get it going.

    As well, the only reason this is even an issue is because of the number of people that use Outlook. Say someone wrote a "macro virus" for some Linux GUI mail client which supported scripting of some kind (Python, for arguments sake). It could disguise itself into other files, send random files to random people and generally spread itself just like these Outlook ones do. The only reason we'd never see news about something like that is because there arent the numbers of people using such clients that are using Outlook clients and as such, I imagine there aren't very many virus kiddies out there looking to target the Linux geeks of the world.

    Now, don't get me wrong. I'm no GO MICROSOFT! guy or anything, but at the same time I realize that when it comes to them, many people on this site don't even give a second thought before finding them guilty of murder...
  • Re:CLUE Taken!!! by LinuxGeek (Score:1) Monday July 23 2001, @03:46AM
  • Why can't these virus writers do something cool? Like install the SETI@home client on every infected machine? Or install something to DOS the RIAA/MPAA/Bad-guy-of-the-week (how about having the DOS daemon check Slashdot to determine who the current bad guy is)?

    I'm sure that someone can come up with even more interesting things than this...


    --
  • Re:Im sticking with Outlook by Mongoose (Score:1) Sunday July 22 2001, @09:21PM
  • Re:These virus writers have no imagination... by ajm (Score:2) Monday July 23 2001, @04:44AM
  • Re:It's the OS, stupid. by TZA14a (Score:1) Monday July 23 2001, @03:01AM
  • Re:It's the culture, stupid. by Syberghost (Score:2) Monday July 23 2001, @03:49AM
  • Be that as it may by FreeUser (Score:2) Tuesday July 24 2001, @06:03AM
  • Unconscionable (Score:4)

    by FreeUser (11483) on Monday July 23 2001, @05:03AM (#68116) Homepage
    I'm sure a lot of people here are going to go out and blame Microsoft for the Outlook-virus-of-the-week. But the fact is, Microsoft is just giving the user what they want.

    Good Lord.

    This reminds me, almost word for word, of statements typically made by rapists and child molesters. While the situation is vastly different (thankfully), the behavior of the guilty party, Microsoft, is appallingly similar: refuse responsibility for one's own actions and blame the victim.

    The cause of these (now almost cliched) viruses is, quite simply, the appallingly lax security in the Microsoft Operating System and mail utilities, a lack of which is unequaled anywhere else in the computing world. Whether by design, negligence, or simple incompetence the fact remains: if you run any version of Windows, IIS, or Outlook, you are vulnerable to this sort of thing regardless of how savvy or cautious a user you are, and there is little or nothing you can do to protect yourself. Indeed, by the time you know of the exploit (assuming you are savvy enough to keep up on such things, which IMHO is asking far more of the user than simply learning a few basic commands a la GNU/Linux or DOS, much less a few GUI variations from with Windows paradigm a la Mac, KDE, or Gnome) chances are the malicious crackers have been exploiting it for weeks or even months.

    Contrast this with the rest of the computing world, in which exploits are published and fixed as soon as they are found (and usually found by the product developers and/or testers before they are exploited), and in which the basic security paradigms allow one to secure the system in as paranoid a fashion as the situation requires, and the mind truly boggles at Microsoft's inability to at least match the quality of competing products such as Mac OS/X, the various *BSD flavors, and GNU/Linux.

    It is bad enough that Microsoft appears incapable of building a secure system. It is even worse that they knowingly market an insecure and unstable system as though it were secure and stable (were there still any kind of "truth in advertising" requirements they would certainly be paying hefty fines for falsly marketing their products). It is unconscionable that they refuse to accept responsibility for their own engineering, choosing instead to blame the victims of its failure: their customers.
  • The depressing thing about these worms... by dwlemon (Score:1) Sunday July 22 2001, @08:13PM
  • Re:How long? by dwlemon (Score:1) Sunday July 22 2001, @08:18PM
  • Re:It's the culture, stupid. by Lumpy (Score:2) Monday July 23 2001, @04:37AM
  • Re:The Microsoft Patch by Aphelion (Score:2) Monday July 23 2001, @07:33AM
  • Re:These virus writers have no imagination... by SmittyTheBold (Score:1) Monday July 23 2001, @01:47AM
  • Re:How long? by SmittyTheBold (Score:1) Monday July 23 2001, @01:52AM
  • Re:Why continue using Outlook? by Zico (Score:1) Monday July 23 2001, @12:26AM
  • Re:Why continue using Outlook? by Zico (Score:1) Monday July 23 2001, @08:47AM
  • Re:It's the culture, stupid. by Sloppy (Score:2) Monday July 23 2001, @06:24AM
  • Re:How long? by Sloppy (Score:2) Monday July 23 2001, @06:48AM
  • Re:Not everyone escaped Code Red lightly by The_Sock (Score:1) Monday July 23 2001, @04:01AM
  • Re:Devil's Advocate by wirefarm (Score:2) Sunday July 22 2001, @08:23PM
  • Damn.. (Score:4)

    by BilldaCat (19181) on Sunday July 22 2001, @07:42PM (#68129) Homepage
    I've been getting this for about a week or so I think.. 4 copies today.. I thought it was just more porn spam at first..

    Cheers to mutt .. :)
  • by warpeightbot (19472) on Sunday July 22 2001, @08:39PM (#68130) Homepage
    Think about what would happen if one of your colleagues sent you a random Linux binary through email and claimed it was a greeting card - would you run it? Well, the drooling masses will run any .exe that a "known" source sends to them, and that is the crux of the problem.
    Sure, I'd run it.

    $ su
    Password:
    # useradd fred123
    # passwd fred123
    Changing password for user fred123
    New UNIX password:
    Retype new UNIX password:
    passwd: all authentication tokens updated successfully
    # cp suspicious.exe /home/fred123
    # chown fred123.fred123 /home/fred123/*
    # chmod 700 /home/fred123/*
    # exit
    $ su - fred123
    Password:
    fred123$ ./suspicious.exe
    suspicious.exe: /etc/shadow: permission denied

    Aha!

    fred123$ exit
    $ su
    Password:
    # userdel -r fred123
    # exit

    The problem here isn't even gullible users. It's the fact that under Win9x, you're running as god all the time, and can seriously hurt yourself. Under Linux, I can create a temporary user in about 30 seconds, go crap all over the resulting sandbox, and I *might* release a forkbomb or fill up /home... if I was being lazy. If I was really worried about it, I could ulimit the bejeezus out of the new userid, and whatever little surprises lay in that exe wouldn't get past first base.

    And it's not just Linux, or other Unixes... VMS, NOS, NOS/VE, VM/CMS... IS there another OS out there that DOESN'T have proper ACL's and CPU/process limits? BeOS, MAYBE?

    Yes, there are a lot of clueless Windows users. There is still no excuse for deliberate insecurity on the part of the OS. As for Microsoft "giving the users what they want"... As Norm Schwartzkopf would say, bovine scatology. See previous comment.

  • Re:How long? by Black Parrot (Score:1) Sunday July 22 2001, @11:28PM
  • Re:How long? by sunking (Score:2) Sunday July 22 2001, @09:07PM
  • Re:Sheesh... by AeiwiMaster (Score:1) Monday July 23 2001, @02:30AM
  • Re:Unthinkable - Thinkable by AstroJetson (Score:1) Monday July 23 2001, @05:23AM
  • Re:These virus writers have no imagination... by Maniac_Dervish (Score:1) Monday July 23 2001, @12:28AM
  • Re:Clear up some misinformation. by realkiwi (Score:1) Monday July 23 2001, @05:54AM
  • Re:IMNSHO by realkiwi (Score:1) Monday July 23 2001, @06:06AM
  • Re:GET A DAMN CLUE PEOPLE!!! by Grimwiz (Score:1) Monday July 23 2001, @01:52AM
  • Re:solution: don't use outlook by Grimwiz (Score:1) Monday July 23 2001, @01:59AM
  • Re:It's the OS, stupid. by NeoMage (Score:2) Monday July 23 2001, @02:22AM
  • Re:Why continue using Outlook? by PovRayMan (Score:1) Monday July 23 2001, @07:26AM
  • Re:Why continue using Outlook? by PovRayMan (Score:2) Sunday July 22 2001, @07:52PM
  • Re:How long? by Restil (Score:2) Sunday July 22 2001, @08:26PM
  • Re:This thing has it's own SMTP server... by odaiwai (Score:1) Sunday July 22 2001, @11:09PM
  • Re:procmail filter, anyone? by odaiwai (Score:1) Sunday July 22 2001, @11:17PM
  • News five days old... by EvilMagnus (Score:2) Sunday July 22 2001, @07:44PM
  • Re:Why continue using Outlook? by Kidder (Score:1) Sunday July 22 2001, @08:32PM
  • Re:These virus writers have no imagination... by Goblin (Score:2) Sunday July 22 2001, @10:54PM
  • Re:Sheesh... by mpe (Score:2) Sunday July 22 2001, @09:07PM
  • Re:This isn't really an Outlook worm by unapersson (Score:1) Sunday July 22 2001, @09:58PM
  • Re:How long? by csbruce (Score:2) Monday July 23 2001, @03:10AM
  • Re:documents by NettRom (Score:2) Sunday July 22 2001, @10:29PM
  • Re:What does your post have to do with the OS? by catfood (Score:1) Monday July 23 2001, @06:41AM
  • Re:Sheesh... by Malcontent (Score:2) Sunday July 22 2001, @09:20PM
  • Re:Sheesh... by Malcontent (Score:2) Monday July 23 2001, @08:36PM
  • Re:How long? by Mr. McGibby (Score:1) Monday July 23 2001, @06:47AM
  • Re:What does your post have to do with the OS? by Dr. Smeegee (Score:2) Monday July 23 2001, @04:14AM
  • Not that new by gizmo_mathboy (Score:2) Sunday July 22 2001, @07:39PM
  • Re:How long? by cyberdonny (Score:1) Monday July 23 2001, @08:47PM
  • Re:documents by cyberdonny (Score:2) Sunday July 22 2001, @08:54PM
  • Re:How long? by cyberdonny (Score:2) Monday July 23 2001, @12:05AM
  • Re:How long? (Score:4)

    by cyberdonny (46462) on Sunday July 22 2001, @08:37PM (#68162)
    > They can't do anything *too* malicious without calling enough attention to it that the spreading slows down.

    Actually, there is a simple cure to this, and it has even been used by Code Red: operate in two phases:

    • A spreading phase, where you don't do anything malicious, except infect other machines. Best if done as low-key as possible: only attempt to infect those people that use Outlook (analize headers of recently received mails), attach yourself to documents that the user sends, rather than making up documents of your own, etc.
    • An active phase, where the fun really starts: DOS the withehouse, mail out confidential .doc files, thrash the BIOS and hard disk, etc.
    The difficult part of course is timing. If the active phase starts too early, you may not have enough of an "installed base" to really wreak havoc. And if it starts too late, a cure may already exist by then.
  • Re:How long? (Score:5)

    by cyberdonny (46462) on Sunday July 22 2001, @09:17PM (#68163)
    > Simple solution - the virus should scan Wired for its name every hour. When it finds a match, the fun begins.

    Good idea... but who assigns virus names? It was my understanding that the names under which a virus is known is usually not chosen by the author, but by the anti-virus community once it is "discovered". Thus, it would be rather hard to scan for its name, as it will not be known at the time of writing...

  • Re:An observation... by dr bacardi (Score:1) Monday July 23 2001, @07:19AM
  • Re:Im sticking with Outlook by ElderKorean (Score:1) Monday July 23 2001, @11:57PM
  • Re:Devil's Advocate by RallyDriver (Score:2) Sunday July 22 2001, @08:26PM
  • MacOS by chrysalis (Score:2) Sunday July 22 2001, @09:48PM
  • Re:How long? by Leonel (Score:1) Monday July 23 2001, @05:08PM
  • Re:Sheesh... by Dwonis (Score:2) Monday July 23 2001, @08:55PM
  • Almost. by jcr (Score:2) Monday July 23 2001, @12:58AM
  • Exchange Calendar is BROKEN. by jcr (Score:2) Monday July 23 2001, @01:15AM
  • Re:These virus writers have no imagination... by 1010011010 (Score:2) Monday July 23 2001, @05:41AM
  • Sendmail Filter? by akiy (Score:1) Sunday July 22 2001, @09:10PM
  • Re:These virus writers have no imagination... by quonsar (Score:1) Monday July 23 2001, @11:16AM
  • Re:Why continue using Outlook? by norton_I (Score:2) Sunday July 22 2001, @09:51PM
  • Re:Why continue using Outlook? by The Musician (Score:1) Sunday July 22 2001, @07:56PM
  • Re:It's the OS, stupid. by dodobh (Score:2) Monday July 23 2001, @02:34AM
  • Re:File extension by dodobh (Score:2) Monday July 23 2001, @02:45AM
  • Re:Devil's Advocate by mewse (Score:1) Sunday July 22 2001, @10:54PM
  • Re:Once again I miss out on everything by rtaylor (Score:1) Monday July 23 2001, @03:32AM
  • Re:It's the culture, stupid. by Tsian (Score:1) Monday July 23 2001, @08:08AM
  • Re:Why continue using Outlook? by dimator (Score:2) Sunday July 22 2001, @07:49PM
  • Re:solution: don't use outlook by Jace of Fuse! (Score:1) Monday July 23 2001, @12:58AM
  • Re:Devil's Advocate by BlueUnderwear (Score:2) Sunday July 22 2001, @09:13PM
  • Re:How long? by BlueUnderwear (Score:2) Monday July 23 2001, @12:12AM
  • Re:These virus writers have no imagination... by BlueUnderwear (Score:2) Monday July 23 2001, @12:20AM
  • Re:Devil's Advocate by BlueUnderwear (Score:2) Monday July 23 2001, @07:09AM
  • This isn't really an Outlook worm by mabinogi (Score:1) Sunday July 22 2001, @08:04PM
  • Re:These virus writers have no imagination... by NReitzel (Score:2) Monday July 23 2001, @05:55AM
  • Re:Why continue using Outlook? by jesser (Score:1) Sunday July 22 2001, @10:33PM
  • by jesser (77961) on Sunday July 22 2001, @07:57PM (#68191) Homepage Journal
    This isn't a problem with Outlook, it's a problem with idiot users clicking on every damn thing they're emailed.

    Outlook Express, at least, has a horrible user interface for attachments. First, *any* attachment with *any* extension will trigger the dialog, which means users will ignore the dialog after seeing it several times. Second, it conveys the possible threat from the file type only by displaying the extension, and many users haven't memorized what extensions are safe and which aren't. Third, it only asks that you "be certain that [the] file is from a trustworthy source", which doesn't help much if the "trustworthy source" is infected by the same attachment.
  • Re:What does your post have to do with the OS? by syates21 (Score:1) Monday July 23 2001, @12:11PM
  • Re:Devil's Advocate by Lxy (Score:2) Monday July 23 2001, @10:05AM
  • Re:Why continue using Outlook? by szcx (Score:2) Sunday July 22 2001, @07:50PM
  • Re:Sheesh... by szcx (Score:2) Sunday July 22 2001, @09:29PM
  • Re:Why continue using Outlook? by szcx (Score:2) Monday July 23 2001, @08:15AM
  • by szcx (81006) on Sunday July 22 2001, @08:06PM (#68197)
    No, they don't. They rely on the user executing the code. Have someone DCC the attachment or FTP it from somewhere. You have to run it, not the client. That's why it's a trojan, fool.

    This sort of trojan can theoretically be ported to any platform that has an email client and an address book.

  • Re:Sheesh... (Score:4)

    by szcx (81006) on Sunday July 22 2001, @09:26PM (#68198)
    Incorrect. This trojan is executed by the user not the email client. It arrives as a file attachment, just like any other attachment. It comes down to the user having sense enough not to choose to double-click everything they see.

    It is exactly the same as if the user downloaded the trojan from an FTP site or through Gnutella, it's strictly an application. It doesn't rely on being received via email, all it needs is for the user to choose to execute it. Now if that application (trojan) happens to be a Linux executable, it's going to run when the user tells it to run. It's going to go ahead and read whatever address book it can find and spam everyone with a copy of itself.

    It's naive to think this problem only affects Windows users. It's only a matter of time before someone creates a Mac or Linux port.

  • Sheesh... (Score:5)

    by szcx (81006) on Sunday July 22 2001, @07:46PM (#68199)
    You know, for all the bitching Slashdot does about the media confusing "Hacker" with "Cracker", it's somewhat ironic that the Slashdot editors don't know the difference between a "Virus" and a "Trojan".

    Of course, then the headline would have to be "Idiot Users Still Exist, Nobody Surprised" -- doesn't really have the same aire of panic though, does it?

    Joe emails a rogue application to Jane, Jane runs the code which then emails itself (and an arbitrary document) to people in Jane's address book. Sounds like something that could be implemented on any OS, doesn't it? You can't patch user stupidity.

    Anyhoo, let the Microsoft bashing begin! Everyone get your pitchforks and flaming torches, but leave your dictionaries at home.

  • Recycle bin by inf0c0m (Score:1) Sunday July 22 2001, @07:38PM
  • "Most human beings on the face of the earth are not technically minded and DO NOT WANT to understand the details of how the tools they use work."

    Right. They only have to understand how to use them, and that includes understanding possible consequences of using them incorrectly.

    Morale: "Messer, Schere, Gabel, Licht, ist für kleine Kinder nicht." Don't give someone who does not know how to use it, a tool that could become hazardous.

    Just as an example: Today's internet is swamped by users who want to send e-mail "cuz its c00l" but probably don't know what an attachment is. They don't need to know - as long as their email client does not support attachments.. As soon as they get the possibility to send attachments, they must learn

    • how to send and receive them (of course)
    • how not to trust them
    • why not to send 20MB files to unsuspecting modem users (what's a modem?)
    • why not to send binary files (what are those?) to Usenet newsgroups (what are those?)
    • etc.

    You don't give a 15-year old a 200mph racing car just because "everyone has one". Similarly, you don't give someone without training a gun. (Yes, I know it's different in the US. Does that make me wrong?)

    Use the tool that do the job. And make sure the user is educated. Simple tool: simple education. Powerful, complex tool - detailed education. Simple as that.

    (Yes, I know I'm dreaming. Please reply to slashdot at jensbenecke dot de if you are interested in serious discussion. I might miss you here.)

  • Re:solution: don't use outlook by Greyfox (Score:2) Monday July 23 2001, @04:57AM
  • Re:These virus writers have no imagination... by Greyfox (Score:2) Monday July 23 2001, @05:02AM
  • Re:The Microsoft Patch by Ronin441 (Score:1) Monday July 23 2001, @01:00AM
  • Re:Once again I miss out on everything by pompomtom (Score:1) Monday July 23 2001, @05:03AM
  • Re:Why continue using Outlook? by steelhawk (Score:1) Monday July 23 2001, @01:17AM
  • New Internet Law on the drawing board by Kwikymart (Score:1) Sunday July 22 2001, @07:41PM
  • Re:Devil's Advocate by frankie (Score:2) Monday July 23 2001, @08:50AM
  • Microsoft *DID* make a patch. by Christopher Biggs (Score:1) Sunday July 22 2001, @08:01PM
  • Re:solution: don't use outlook by rosewood (Score:1) Monday July 23 2001, @04:53AM
  • i don't think it's an "outlook" virus by jon_c (Score:1) Sunday July 22 2001, @08:21PM
  • Re:Why continue using Outlook? by jon_c (Score:1) Sunday July 22 2001, @08:23PM
  • *MOD UP* by jon_c (Score:1) Sunday July 22 2001, @08:26PM
  • procmail filter, anyone? by Jeppe Salvesen (Score:1) Sunday July 22 2001, @09:40PM
  • haha by Jeppe Salvesen (Score:1) Monday July 23 2001, @02:19AM
  • Re:What does your post have to do with the OS? by twitter (Score:2) Monday July 23 2001, @05:40AM
  • Re:shutupshutup! by twitter (Score:2) Monday July 23 2001, @08:14AM
  • Re:Devil's Advocate by twitter (Score:2) Monday July 23 2001, @08:33AM
  • I like em big and stupid. by twitter (Score:2) Monday July 23 2001, @11:03AM
  • Re:Devil's Advocate by Caspuh (Score:1) Monday July 23 2001, @07:40PM
  • Re:Media is now just as slow as about a decade ago by Caspuh (Score:1) Monday July 23 2001, @07:47PM
  • OK, so you've shown that if a friend emails you a suspicious .exe, you create a phony account with no permissions then run it from that account. This is also possible in Win2K and Windows XP. So what's your point?

    All you've shown is that you are an extremely paranoid person and not that your OS of choice is some fantastically secure manifestation of operating system design. Most Linux users I know would not go through all that trouble if mailed a perl script or executable (or heck, compiling some obsfucated source from someones .sig).

    And it's not just Linux, or other Unixes... VMS, NOS, NOS/VE, VM/CMS... IS there another OS out there that DOESN'T have proper ACL's and CPU/process limits?

    Windows' ACL support has been more mature than Linux's for a long time. Because you don't know about it doesn't mean it doesn't exist.

    --
  • Re:How long? by SimCash (Score:1) Tuesday July 24 2001, @06:40AM
  • spreads using the address book? by superpeach (Score:1) Sunday July 22 2001, @08:06PM
  • Re:spreads using the address book? - oops by superpeach (Score:1) Sunday July 22 2001, @08:15PM
  • Re:It's the culture, stupid. by AsbestosRush (Score:1) Sunday July 22 2001, @08:57PM
  • Re:solution: don't use outlook by -brazil- (Score:2) Sunday July 22 2001, @09:47PM
  • Re:An observation... by jred (Score:1) Sunday July 22 2001, @08:26PM
  • Re:Yet again, we see by zerocool^ (Score:1) Sunday July 22 2001, @08:51PM
  • by CaptainAvatar (113689) on Sunday July 22 2001, @09:47PM (#68230)
    Well ... now that you mention this idea, how do you know they aren't doing this already? Sounds like it could be causing half the win and macos problems I have to troubleshoot every week!
    --
  • Re:solution: don't use outlook by biohazard99 (Score:1) Monday July 23 2001, @12:06AM
  • What would be really nice... by brianboru (Score:1) Sunday July 22 2001, @07:49PM
  • An observation... (Score:5)

    by brianboru (117882) on Sunday July 22 2001, @08:04PM (#68233)

    One thing I've noticed is that it's always my work address that seems to get the viruses. In the 10+ years that I've had personal email addresses, I think I've only had maybe 2 even delivered to any account. (This includes free Outlook-enabled web accounts).

    There's only a couple conclusions I could draw from this:

    1) I am a supreme personal system administrator and do not let any common mundane virus issue affect the harmony of my smoothly oiled machine. (you do you oil computers, right?)
    2a) All of my personal friends are apparently not as stupid as they look (this one is hard to believe).
    2b) All of my work collegues are definately more stupid than they look (ok this one isn't so hard to believe). heh
    3) There is some kind of shield made up of impervious virus-fighting smurfs that protect my personal computer 24 hours a day.
    4) Karma (no not that kind)

    or most probable:

    5) Someone has been reading and deleting my personal email for years.

  • Re:It's the culture, stupid. by softsign (Score:2) Monday July 23 2001, @02:32PM
  • Re:It's the OS, stupid. by Belgarath52 (Score:1) Sunday July 22 2001, @09:56PM
  • Re:What does your post have to do with the OS? by mr3038 (Score:1) Monday July 23 2001, @03:01PM
  • by autechre (121980) on Sunday July 22 2001, @08:18PM (#68237) Homepage
    "It relies on the user executing the attachment, it doesn't execute itself."

    Unless, of course, it's something like Javascript code, or an unruly image tag. Exploits of this nature have been discussed on BUGTRAQ (more recently as an example of how poor PHP programming can cause security problems [duh!], so don't think I'm picking on Outlook here). Any mailer that displays even plain HTML as soon as you view the message can be attacked, and ones that do Javascript are INSANE.


    Sotto la panca, la capra crepa
  • by Fred Ferrigno (122319) on Monday July 23 2001, @04:24AM (#68238)
    If you think that's bad, take a look at this virus/trojan [chicane.net] that was floating around IRC a while back. The thing is indistinguishable from a text file at first glance, even if you're bright enough to check the extension. When it executes, it even opens a contained note in Notepad so you don't think anything is wrong.

    --
  • Re:This thing has it's own SMTP server... by SuiteSisterMary (Score:2) Monday July 23 2001, @05:16AM
  • Re:Praises to Pine.. Outlook? Would MS make a patc by SuiteSisterMary (Score:2) Monday July 23 2001, @05:34AM
  • Re:This thing has it's own SMTP server... by SuiteSisterMary (Score:2) Monday July 23 2001, @07:34AM
  • Re:This thing has it's own SMTP server... by SuiteSisterMary (Score:2) Tuesday July 24 2001, @03:16AM
  • Re:It's the culture, stupid. by neoThoth (Score:1) Sunday July 22 2001, @10:46PM
  • Except Win2K and WinXP are expensive! by yerricde (Score:1) Monday July 23 2001, @09:15AM
  • Re:Devil's Advocate by vex24 (Score:1) Tuesday July 24 2001, @02:47PM
  • Re:Devil's Advocate by vex24 (Score:2) Sunday July 22 2001, @08:10PM
  • The "Virus" by x-empt (Score:2) Sunday July 22 2001, @09:49PM
  • Re:documents by Dahan (Score:1) Monday July 23 2001, @12:40AM
  • Re:How long? by enneff (Score:1) Sunday July 22 2001, @11:09PM
  • Re:An observation... by enneff (Score:1) Sunday July 22 2001, @11:12PM
  • Re:Once again I miss out on everything by enneff (Score:1) Sunday July 22 2001, @11:14PM
  • Re:solution: don't use outlook by bellings (Score:1) Monday July 23 2001, @05:03AM
  • documents (Score:3)

    by rixdaffy (138224) on Sunday July 22 2001, @07:51PM (#68253) Homepage
    this virus has already been spreading actively since last thursday or something...

    anyway, one stupid thing is that all the reports call it "privacy" sensitive because it sends out personal documents from your drive... but from all the stuff I received over the weekend, I noticed it's just the name of the document it uses... the actual content is the virus itself; an executable disguised as a document...

    of course, since lots of windows users use 50% of the document contents in the name of the file, it could be quite emberassing if it picks the right document ;)

  • ...How long is it before the Chinese hackers sue eEye under the terms of the DMCA?

  • Re:Im sticking with Outlook by binford2k (Score:1) Monday July 23 2001, @10:34AM
  • Re:How long? by e_lehman (Score:2) Monday July 23 2001, @03:56AM
  • Re:Use Pine by drxyzzy (Score:1) Monday July 23 2001, @09:45AM
  • by cosmicaug (150534) on Sunday July 22 2001, @08:24PM (#68258)

    It seems just about every damn virus nowadays spreads via Outlook or Outlook Express which is too bad

    But has anybody (specially Timothy) actually paid any attention to the damn stories?

    Nowhere in these stories is it claimed that Sircam uses Outlook to spread! Maybe Timothy got the idea from reading this [cnn.com] CNN [cnn.com] article.

    Geez, people, do you believe everything that CNN says? It's not like I really expect CNN [cnn.com] to get this right, but /. [slashdot.org] readers are supposed to be better than that!

    In fact, the Wired news clearly says that the virus serves as it's own SMTP client. A lot about this virus in fact resembles how the Judge Disemboweler virus [symantec.com] operates.

    The only thing that can be interpreted as using Outlook to spread itself is the fact that it takes its e-mail addresses from Windows Address Book files; however it will also try to get addresses from some files in the 'Temporary Internet Files' folder. This means it should be able to spread without any need for Outlook (just some e-mail client and a user naive enough to run the attachment) and without Windows Address Files.

    All the usual sources of virus information seem to agree about this virus serving as its own SMTP client. Please check for yourselves:

    http://www.symantec.com/avcenter/venc/data/w32.sir cam.worm@mm.html [symantec.com]

    http://vil.mcafee.com/dispVirus.asp?virus_k=99141& [mcafee.com]

    http://www.antivirus.com/vinfo/virusencyclo/defaul t5.asp?VName=TROJ_SIRCAM.A [antivirus.com]

    http://www.antivirus.com/vinfo/virusencyclo/defaul t5.asp?VName=TROJ_SIRCAM.A [ca.com]

    http://www.sophos.com/virusinfo/analyses/w32sircam a.html [sophos.com]

    http://www.europe.f-secure.com/v-descs/sircam.shtm l [f-secure.com]

    http://service.pandasoftware.es/servlet/panda.pand aInternet.EntradaDatosInternet?operacion=FichaViru s&idVirusFicha=1911&pestanaFicha=1 [pandasoftware.es]

    http://support.centralcommand.com/cgi-bin/command. cfg/php/enduser/std_adp.php?p_refno=010718-000010 [centralcommand.com]

  • Ummm... by TVmisGuided (Score:1) Sunday July 22 2001, @07:42PM
  • by BigWhale (152820) on Sunday July 22 2001, @08:19PM (#68260)
    You know... maybe somebody should figure out how to send mail thru it. It could be used instead of MS Exchange... I bet this thing is smaller, qucker and uses much less resources than Exchange... ;>


    ---------------
    I never wanted to go anywhere. I'm happy here...
  • Re:solution: don't use outlook by Martin Blank (Score:1) Monday July 23 2001, @01:01PM
  • It affects Outlook Express also. by Cybrex (Score:1) Monday July 23 2001, @03:53AM
  • Re:solution: don't use outlook by sg_oneill (Score:1) Sunday July 22 2001, @08:24PM
  • Re:Why continue using Outlook? by sg_oneill (Score:1) Sunday July 22 2001, @08:27PM
  • Re:These virus writers have no imagination... by panum (Score:2) Monday July 23 2001, @01:37AM
  • Re:It's the culture, stupid. by IronChef (Score:2) Sunday July 22 2001, @08:55PM
  • Praises to Pine.. Outlook? Would MS make a patch? by Deal-a-Neil (Score:1) Sunday July 22 2001, @07:45PM
  • Re:Praises to Pine.. Outlook? Would MS make a patc by Deal-a-Neil (Score:1) Sunday July 22 2001, @07:50PM
  • Re:spreads using the address book? by codepunk (Score:1) Sunday July 22 2001, @08:15PM
  • IBM has a solution... by spike666 (Score:1) Sunday July 22 2001, @08:42PM
  • Re:This thing has it's own SMTP server... by loraksus (Score:1) Sunday July 22 2001, @11:53PM
  • Re:This thing has it's own SMTP server... by loraksus (Score:1) Monday July 23 2001, @11:14PM
  • Re:This thing has it's own SMTP server... by loraksus (Score:2) Sunday July 22 2001, @08:28PM
  • file blocking by Zzyzzx (Score:1) Monday July 23 2001, @09:48AM
  • Re:It's the OS, stupid. by maunleon (Score:1) Monday July 23 2001, @04:31AM
  • Re:Why continue using Outlook? by MrBogus (Score:1) Monday July 23 2001, @05:23PM
  • Re:Why continue using Outlook? by MrBogus (Score:2) Monday July 23 2001, @06:15AM
  • Re:It's the OS, stupid. by tshak (Score:2) Monday July 23 2001, @08:58AM
  • by G Neric (176742) on Monday July 23 2001, @02:38AM (#68279)
    computer darwinism. people who are stupid and inexperienced enough to click on dangerous attachments are not knowledgeable enough to maintain a working computer at home, they need a tech support and IT infrastructure to sustain them. this exists in the workplace.

    also, the number of emails processed increases the probability of infection, spread, etc. for the above class of people, they spend much more time at work on a computer than they do at home.

    ----

  • by Kefabi (178403) on Sunday July 22 2001, @10:17PM (#68280) Journal
    Another Nasty Outlook Virus Strikes

    Score: -1 (Redundant =)

    -Kef
  • FYI, XP helps this scenario by Mr 44 (Score:1) Monday July 23 2001, @10:32AM
  • Re:Sheesh... by YKnot (Score:1) Monday July 23 2001, @01:11AM
  • Re:Sheesh... by YKnot (Score:1) Monday July 23 2001, @01:17AM
  • Re:Sheesh... by YKnot (Score:1) Monday July 23 2001, @03:16AM
  • What's that, again? by AaronStJ (Score:1) Sunday July 22 2001, @08:32PM
  • Re:What does your post have to do with the OS? by Erasmus Darwin (Score:2) Monday July 23 2001, @07:55PM
  • by Erasmus Darwin (183180) on Monday July 23 2001, @04:04AM (#68287)
    OK, so you've shown that if a friend emails you a suspicious .exe, you create a phony account with no permissions then run it from that account. This is also possible in Win2K and Windows XP.

    Can you do the following in Win2K/XP? (This is only half rhetorical -- I freely admit that I'm less than fully versed on Windows-based security. I suspect that at least some of these are doable in Windows.)

    • Run the program in a chroot jail
    • Run the program with ulimited resources
    • Set up a script to quickly and easily do the previous two items (and run it as a throwaway user account, as previously mentioned).

    The scripting issue is, I suspect, where it really wins. If a user can start something with 'saferun some_app' instead of just 'some_app', it's much less of a hassle, and it's that much more likely that a user won't do something stupid. It also limits damage to programs that're capable of breaking out of chrooted jails, when running as a user-level process. It's at least theoretically possible, but in the process, we've managed to cut out a lot of potential exploits.

  • Re:i don't think it's an "outlook" virus by Gordonjcp (Score:2) Sunday July 22 2001, @09:16PM
  • Re:What does your post have to do with the OS? by poot_rootbeer (Score:1) Monday July 23 2001, @02:10PM
  • Re:Why continue using Outlook? by Magic5Ball (Score:1) Monday July 23 2001, @10:03AM
  • Not everyone escaped Code Red lightly by jesterzog (Score:2) Sunday July 22 2001, @10:31PM
  • Re:Really Malicious Payloads by dbirchall (Score:2) Sunday July 22 2001, @11:18PM
  • Re:Once again I miss out on everything by cygnusx (Score:1) Monday July 23 2001, @12:21AM
  • Re:Once again I miss out on everything by cygnusx (Score:1) Monday July 23 2001, @08:48PM
  • Re:Clear up some misinformation. by overturf (Score:1) Monday July 23 2001, @03:14AM
  • Re:Better Solution:Don't click everything! by Asic Eng (Score:1) Monday July 23 2001, @03:07AM
  • Re:Im sticking with Outlook by Asic Eng (Score:2) Monday July 23 2001, @03:32AM
  • Re:Writing viruses != computer valdalism by netsharc (Score:1) Monday July 23 2001, @07:33AM
  • Re:Ummm... by netsharc (Score:1) Monday July 23 2001, @08:24AM
  • Re:These virus writers have no imagination... by OverCode@work (Score:1) Monday July 23 2001, @06:47AM
  • Re:Why continue using Outlook? by quintessent (Score:2) Sunday July 22 2001, @08:52PM
  • Re:File extension by quintessent (Score:2) Sunday July 22 2001, @09:27PM
  • Re:documents by linzeal (Score:1) Sunday July 22 2001, @08:47PM
  • Re:These virus writers have no imagination... by LoudMusic (Score:1) Monday July 23 2001, @06:45AM
  • Re:Devil's Advocate by sasha328 (Score:1) Sunday July 22 2001, @08:16PM
  • Re:Recycle bin by sasha328 (Score:2) Sunday July 22 2001, @07:58PM
  • Re:Devil's Advocate by BigTimOBrien (Score:1) Monday July 23 2001, @08:47AM
  • Why continue using Outlook? by guru_steve (Score:2) Sunday July 22 2001, @07:37PM
  • Re:Use Pine by FatOldGoth (Score:2) Sunday July 22 2001, @11:48PM
  • Better solution - update Outlook by tswinzig (Score:2) Monday July 23 2001, @05:51AM
  • Re:It's the culture, stupid. by tswinzig (Score:2) Monday July 23 2001, @05:55AM
  • Re:The Microsoft Patch by tswinzig (Score:2) Monday July 23 2001, @06:00AM
  • There was an old DOS virus like that by phr1 (Score:2) Sunday July 22 2001, @11:48PM
  • Re:It's the culture, stupid. by Mr_Silver (Score:2) Tuesday July 24 2001, @01:25AM
  • Re:Sheesh... by purplemonkeydan (Score:2) Sunday July 22 2001, @11:40PM
  • Re:An observation... by Da Web Guru (Score:1) Sunday July 22 2001, @09:43PM
  • Re:solution: don't use outlook by Grishnakh (Score:1) Sunday July 22 2001, @07:59PM
  • Re:Why continue using Outlook? by Grishnakh (Score:1) Sunday July 22 2001, @08:03PM
  • Re:Devil's Advocate by Grishnakh (Score:1) Monday July 23 2001, @06:41AM
  • by Chetmurray (216997) on Sunday July 22 2001, @09:32PM (#68320) Homepage
    I am a moron. I admit it - I caught this last wed. Even had Norton running. It didn't blink. The email came from a client during the day. The attachment was an excel spreadsheet that I had sent her earlier. Yes, I should have read the email and then I would have been suspicious, yes Norton should have caught it, but I open maybe 15 excel spreadsheets a day sometimes from this client. I don't read every email - or I didn't.

    My personal firewall blocked their smtp program from sending - but then it attached itself to ie and ran through IE's security area in my firewall. It is set to send thru the smtp server you have setup in your mail program. It sent thru my local email. The only reason I noticed was paranoia and running netstat.

    This virus can and does attack more than just outlook. I run Pegasus. If it infects an outlook machine it sends to emails in their address book, in my case it went thru the cache of IE. I had to send apologies to a bunch of tribes players. It doesn't parse emails very well as I got 10-20 obviously broken emails bounced back.

    Norton would not remove it and at that time their was no mention on any site or newsgroup so I was forced to remove it myself. Hiding in the recycle bin took me a second time to catch.

    If you read your email from a web client you can still get infected and it can still send out depending on your setup.

    If you run an email server - you can block this virus very easily as the text comes in two flavors an English and Spanish version. Here is the text:

    I send you this file in order to have your advice

    Espero me puedas ayudar con el archivo que te mando

    Pretty embarrassing, but don't just dismiss this as another love bug virus hitting outlook.

    Chet
  • Re:It's the culture, stupid. by BrynM (Score:1) Monday July 23 2001, @07:51AM
  • Re:Devil's Advocate by Pravada (Score:1) Sunday July 22 2001, @08:30PM
  • Re:Win2k running idle IIS by default...yeah, but.. by Philbert Desenex (Score:1) Monday July 23 2001, @05:52AM
  • Origins, Spread by o mandarin (Score:1) Sunday July 22 2001, @08:44PM
  • Re:Microsoft *DID* make a patch. by NoOneInParticular (Score:1) Monday July 23 2001, @03:39AM
  • Re:solution: don't use outlook by zip the pinhead (Score:1) Monday July 23 2001, @08:36AM
  • poor outlook by c4thy (Score:1) Sunday July 22 2001, @07:42PM
  • trashy virus by c4thy (Score:1) Sunday July 22 2001, @07:44PM
  • by Merkins (224523) on Sunday July 22 2001, @09:06PM (#68329) Homepage
    I've Been using Netscape Communicator's E-mail program for years, without a problem.

    Who would bother writing a virus that will affect 11 people ?

  • Better Solution:Don't click everything! by Schwarzchild (Score:1) Sunday July 22 2001, @08:04PM
  • Re:solution: don't use outlook by Kierthos (Score:1) Sunday July 22 2001, @09:07PM
  • Re:solution: don't use outlook by Kierthos (Score:1) Sunday July 22 2001, @09:13PM
  • Re:File extension by Jucius Maximus (Score:1) Monday July 23 2001, @04:17AM
  • Re:These virus writers have no imagination... by Jucius Maximus (Score:1) Monday July 23 2001, @04:25AM
  • Re:What does your post have to do with the OS? by Jucius Maximus (Score:1) Monday July 23 2001, @04:33AM
  • Re:The Microsoft Patch by Jucius Maximus (Score:1) Monday July 23 2001, @04:38AM
  • Re:solution: don't use outlook by Majik Sznak (Score:2) Monday July 23 2001, @05:07AM
  • Re:These virus writers have no imagination... by fallen1 (Score:1) Monday July 23 2001, @03:31AM
  • POP mail on Exchange by Fragmented_Datagram (Score:1) Monday July 23 2001, @09:38AM
  • It's not just the users. by DeadMeat (TM) (Score:2) Monday July 23 2001, @05:14AM
  • Of Course by user flynn (Score:1) Monday July 23 2001, @03:02AM
  • Really Malicious Payloads by hound3000 (Score:1) Sunday July 22 2001, @09:04PM
  • Re:solution: don't use outlook by einhverfr (Score:2) Sunday July 22 2001, @08:30PM
  • Re:solution: don't use outlook by einhverfr (Score:2) Sunday July 22 2001, @08:35PM
  • Another virus that doesn't affect web-based email (not to mention pine or MacOS or whatever). Seems pretty clear that Outlook will continue to be exploited in new ways for the forseeable future.

    I don't know enough about it to determine the extent to which it can affect non-Outlook clients. I do know that, according to CNET, it does try other means of spreading as well.

    Curiously, the virus resides in the recycle bin... If you don't run Windows, no worries ;)

    A little off-topic but:
    Now it would be harder to do, but imagine a worm written in C that would spread as source code and then recompile on various client computers, thereby appearing to be different viruses on different platforms...

    Sig: Tell all your friends NOT to download the Advanced Ebook Processor:

  • For the most part, writing viruses as proof of concept which are tested in controlled lab environments is perfectly legal... Intentionally releasing a virus you wrote onto the internet is not. I would imagine that if you attempted to hand infect a computer with someone else's virus, it would also be illegal. So the Bliss virus was probably not an issue of criminal law (I suppose one could sue for negligence) but it was hardly computer vandalism.

    For those unfamiliar with the Bliss Virus, it is/was a research virus written as a proof of concept (complete with all sorts of safety features, like an auto-removing feature) which eventually accidently was released on the net. ig the adminsitrator ran:
    bliss --disinfect-files-please
    the virus would remove itself from the system (good responsible code design-- it cleans up after itself).

    My point is that writing viruses != computer vandalism. They usually coincide but not always. This virus we are following is pretty clearly one covered under computer valdalism (who writes Outlook viruses as proof of concept anymore anyway-- it is too easy and would not do any good). ANY virus with a payload is malicious and probably a criminal offense in most countries. This worm carries a payload, so its intents are clear.

    Sig: Tell all your friends NOT to download the Advanced Ebook Processor:

  • if you are running by daniel2000 (Score:1) Sunday July 22 2001, @07:59PM
  • Re:What's that, again? by J'raxis (Score:2) Sunday July 22 2001, @09:02PM
  • Re:These virus writers have no imagination... by dasunt (Score:2) Monday July 23 2001, @04:49AM
  • Re:solution: don't use outlook by clone22 (Score:1) Monday July 23 2001, @03:23AM
  • Re:solution: don't use outlook by TheRealSlimShady (Score:1) Sunday July 22 2001, @08:11PM
  • Re:Why continue using Outlook? by Mr. Foogle (Score:2) Monday July 23 2001, @07:49AM
  • that remind me.... by jsse (Score:1) Sunday July 22 2001, @09:39PM
  • Re:These virus writers have no imagination... by jsse (Score:1) Sunday July 22 2001, @09:49PM
  • Re:Why continue using Outlook? by jsse (Score:1) Monday July 23 2001, @05:16PM
  • Re:Once again I miss out on everything by jsse (Score:2) Sunday July 22 2001, @09:55PM
  • Re:Why continue using Outlook? by jsse (Score:2) Monday July 23 2001, @01:31AM
  • Re:Why continue using Outlook? by imipak (Score:2) Sunday July 22 2001, @08:15PM
  • Re:Install Patch for Correcting Outlook Express by imipak (Score:2) Sunday July 22 2001, @08:23PM
  • Re:Almost. by imipak (Score:2) Monday July 23 2001, @02:15AM
  • Re:Exchange Calendar is BROKEN. by imipak (Score:2) Monday July 23 2001, @02:20AM
  • How long? (Score:5)

    by imipak (254310) on Sunday July 22 2001, @08:10PM (#68362) Journal
    How long can it be before one of these uber-worms carries a really malicious payload, or doesn't get reversed in time? We escaped Code Red (if you can call it 'escaping' when the security and network admins of half the world spend 12 hours on Friday working on it) largely because eEye reversed the worm , giving the Whitehouse.gov people enough time to blackhole the IP the worm author had hard-coded. If that hadn't happened - or if the IP was looked up in DNS - or the thing hadn't happened to be programmed to stop spreading itself on the 20th, the day after it exploded around the world (not that the author could have predicted that)... things could have got /really/ messy.

    How long before one of these reformats it's host after reproducing 500 times?

    Rhetorical questions - I hope.
    --
    "I'm not downloaded, I'm just loaded and down"

  • Re:What would be really nice... by k2r (Score:1) Monday July 23 2001, @02:27AM
  • Re:Better Solution:Don't click everything! by baptiste (Score:2) Monday July 23 2001, @03:33AM
  • Re:Why continue using Outlook? by baptiste (Score:2) Monday July 23 2001, @03:37AM
  • Re:Not that new by baptiste (Score:2) Monday July 23 2001, @03:40AM
  • Re:These virus writers have no imagination... by baptiste (Score:2) Monday July 23 2001, @03:45AM
  • Re:spreads using the address book? by morcego (Score:1) Sunday July 22 2001, @11:19PM
  • Re:solution: don't use outlook by morcego (Score:1) Monday July 23 2001, @05:56AM
  • Re:It's the OS, stupid. by morcego (Score:2) Sunday July 22 2001, @10:56PM
  • by morcego (260031) on Sunday July 22 2001, @10:23PM (#68371) Homepage
    Any mailer that displays even plain HTML as soon as you view the message can be attacked
    Errr, I'm still waiting to see any HTML attack agains my mutt+w3m reader.
    Now, be serious. The problem is not HTML nor JavaScript, but the bad programing skills used to create some mail readers.
    Or simply plain stupidity, like OutLook running lost of things by itself.
    The is that it is impossible (thanks God) to create a computer program that is smarted then a human being (at least, smarter then us /. reader). So, if someone create some kind of smart program that decides to do this or that on itself, you can be sure that someone will outwit the program and create a hell.

    ---
  • Re:Use Pine (Score:3)

    by morcego (260031) on Sunday July 22 2001, @10:43PM (#68372) Homepage
    I did. There was a buffer overflow in Pine a year or two ago.
    ---
  • Re:solution: don't use outlook by schof (Score:1) Monday July 23 2001, @02:29PM
  • Re:solution: don't use outlook by refactored (Score:2) Sunday July 22 2001, @08:21PM
  • Re:These virus writers have no imagination... by chuqui (Score:1) Sunday July 22 2001, @10:25PM
  • Re:Sheesh... by chuqui (Score:2) Sunday July 22 2001, @10:28PM
  • Re:Devil's Advocate by benspionage (Score:1) Monday July 23 2001, @07:50PM
  • Re:Install Patch for Correcting Outlook Express by RustyTaco (Score:1) Monday July 23 2001, @01:04PM
  • Re:These virus writers have no imagination... by anshil (Score:1) Monday July 23 2001, @04:30AM
  • comp virus == true viruses? by anshil (Score:2) Monday July 23 2001, @08:19AM
  • love your sig by imaginate (Score:1) Monday July 23 2001, @05:54AM
  • Re:How long? by MxTxL (Score:1) Monday July 23 2001, @08:56AM
  • Re:Why continue using Outlook? by Targetman (Score:1) Monday July 23 2001, @05:06AM
  • Re:solution: don't use outlook by tb3 (Score:2) Monday July 23 2001, @05:25AM
  • It's the software, stupid by SpeelingChekka (Score:1) Tuesday July 24 2001, @06:38AM
  • Mostly correct, but incorrect by SpeelingChekka (Score:1) Tuesday July 24 2001, @07:14AM
  • Incorrect! (not informative!) by SpeelingChekka (Score:1) Tuesday July 24 2001, @07:27AM
  • Re:if you are running by SpeelingChekka (Score:1) Tuesday July 24 2001, @07:36AM
  • No by SpeelingChekka (Score:1) Tuesday July 24 2001, @07:38AM
  • Re:solution: don't use outlook by angry_android (Score:1) Monday July 23 2001, @10:37AM
  • Incidentally by MacGod (Score:2) Sunday July 22 2001, @08:36PM
  • Re:An observation... by Regolith (Score:1) Sunday July 22 2001, @08:46PM
  • by flippety_gibbet (323926) on Sunday July 22 2001, @08:09PM (#68393)
    ...spread as source code and then recompile on various client computers, thereby appearing to be different viruses on different platforms...

    Is this how java got so damn popular?
  • Re:It's the OS, stupid. by OSgod (Score:2) Monday July 23 2001, @02:34AM
  • by flacco (324089) on Sunday July 22 2001, @08:22PM (#68395)
    To paraphrase an admin at our University during a mailing list discussion about Outlook:

    "Prior to MS Outlook, if you suggested to ANYONE that a mail client should be able to execute foreign code sent to you through e-mail, they'd have looked at you like you just grew an extra head."
  • Re:It's the OS, stupid. by Waffle Iron (Score:2) Sunday July 22 2001, @09:19PM
  • by uigrad_2000 (398500) on Monday July 23 2001, @04:48AM (#68397) Homepage Journal
    When it executes, it even opens a contained note in Notepad so you don't think anything is wrong.

    Hmm, it would make me suspicious. I'm used to all text files being opened in gvim.

  • SirCam info by Ballresin (Score:1) Sunday July 22 2001, @09:24PM
  • Re:These virus writers have no imagination... by _LFTL_ (Score:1) Monday July 23 2001, @10:03AM
  • Re:Praises to Pine.. Outlook? Would MS make a patc by TeraCo (Score:1) Sunday July 22 2001, @08:15PM
  • Re:Praises to Pine.. Outlook? Would MS make a patc by TeraCo (Score:1) Monday July 23 2001, @03:22PM
  • Use Pine by s20451 (Score:2) Sunday July 22 2001, @09:44PM
  • Re:How long? (Score:3)

    by s20451 (410424) on Sunday July 22 2001, @09:55PM (#68403) Journal

    where the fun really starts: DOS the withehouse [sic]

    Actually I think it would be fun to Linux [linux.org] the whitehouse. [whitehouse.gov]

    Whoops, too late [netcraft.com]: The site www.whitehouse.gov is running unknown on Linux.

    OK, I'll stop now.

  • Re:Why continue using Outlook? by sehryan (Score:1) Monday July 23 2001, @03:23AM
  • Re:documents by blb (Score:1) Sunday July 22 2001, @08:38PM
  • by MajrMeximelt (413119) on Sunday July 22 2001, @07:37PM (#68406)
    Another virus that doesn't affect web-based email (not to mention pine or MacOS or whatever). Seems pretty clear that Outlook will continue to be exploited in new ways for the forseeable future.

    This will not be the last time we see a Slashdot headline of this nature (and I seem to recall that it's not the first either...)

  • unfortunately, by EvilStein (Score:1) Sunday July 22 2001, @08:52PM
  • Re:GET A DAMN CLUE PEOPLE!!! by dinivin (Score:1) Monday July 23 2001, @02:38AM
  • Re:Devil's Advocate by cREW oNE (Score:1) Monday July 23 2001, @04:52AM
  • Re:Why continue using Outlook? by tundog (Score:1) Monday July 23 2001, @04:46AM
  • Yet again, we see by kypper (Score:2) Sunday July 22 2001, @07:40PM
  • Re:Praises to Pine.. Outlook? Would MS make a patc by NorthStar4 (Score:1) Sunday July 22 2001, @08:04PM
  • Re:i don't think it's an "outlook" virus by archen (Score:1) Monday July 23 2001, @04:14AM
  • Re:Sheesh... by archen (Score:1) Monday July 23 2001, @04:46AM
  • Re:This thing has it's own SMTP server... by archen (Score:1) Monday July 23 2001, @05:00AM
  • Re:GET A DAMN CLUE PEOPLE!!! by archen (Score:1) Monday July 23 2001, @05:06AM
  • Install Patch for Correcting Outlook Express by christoofar (Score:2) Sunday July 22 2001, @07:44PM
  • Re:Im sticking with Outlook by night_flyer (Score:1) Monday July 23 2001, @05:04AM
  • IMNSHO by sinserve (Score:1) Sunday July 22 2001, @08:23PM
  • Re:How long? by moncyb (Score:2) Sunday July 22 2001, @10:00PM
  • Re:These virus writers have no imagination... by mrm677 (Score:1) Monday July 23 2001, @10:08AM
  • Re:Why continue using Outlook? by Anonymous Brave Guy (Score:1) Monday July 23 2001, @02:44AM
  • Re:Why continue using Outlook? by Anonymous Brave Guy (Score:1) Monday July 23 2001, @01:39PM
  • Re:Praises to Pine.. Outlook? Would MS make a patc by All Dead Homiez (Score:1) Sunday July 22 2001, @07:59PM
  • by All Dead Homiez (461966) on Sunday July 22 2001, @07:45PM (#68425)
    I'm sure a lot of people here are going to go out and blame Microsoft for the Outlook-virus-of-the-week. But the fact is, Microsoft is just giving the user what they want. Users want the ability to double-click on executable attachments in order to open them, and email software needs to honor that request to stay competitive.

    The underlying problem here is that people have come to accept executable attachments as the norm. Years of silly Flash greeting cards, "snowball fight" games, and Joe Cartoon crap sent across offices since the mid-1990's have hooked Windows users on native-binary attachments. The only way that this sort of activity can be stopped is by making it socially unacceptable (improper netiquette) for anyone to send executables through email. Think about what would happen if one of your colleagues sent you a random Linux binary through email and claimed it was a greeting card - would you run it? Well, the drooling masses will run any .exe that a "known" source sends to them, and that is the crux of the problem.

    Unfortunately, it is in content producers' best monetary interest not to change their distribution strategy to use a format that requires less trust (such as .swf or even .html). That would artificially limit the quality of their goods, and closes the door to including "value-added features" (like spyware) to their attachments. Therefore, the situation shows few signs of changing anytime soon, and users will simple work around any stopgap measures in their email software so that they can continue to play their "frog in the blender games" in perpetuity.

    -all dead homiez

  • Re:unfortunately, by Unknown Bovine Group (Score:2) Monday July 23 2001, @04:33AM
  • Re:solution: don't use outlook by Unknown Bovine Group (Score:2) Monday July 23 2001, @04:37AM
  • Re:These virus writers have no imagination... by p_trinli (Score:1) Monday July 23 2001, @08:59AM
  • so what? by Tuxinatorium (Score:1) Sunday July 22 2001, @09:32PM
  • Re:solution: don't use outlook by Budster (Score:1) Sunday July 22 2001, @08:23PM
  • Re:Unthinkable - Thinkable by Budster (Score:1) Sunday July 22 2001, @09:22PM
  • Re:Better Solution:Don't click everything! by Budster (Score:2) Sunday July 22 2001, @08:17PM
  • Re:solution: don't use outlook by aarakawa2003 (Score:1) Sunday July 22 2001, @08:03PM
  • Oh Crap! (Score:4)

    by Nathdot (465087) on Sunday July 22 2001, @09:00PM (#68434)
    I've just realised it doesn't matter what mailer I use. The fact that this virus/worm/whatever even exists means I'm gonna suffer!

    With all this media attention my Mom's gonna start sending every freaking bogus virus warning on the planet (She scares very easily; The poor dear!).

    I'd rather get the virus.

    :)
  • by Nathdot (465087) on Sunday July 22 2001, @08:07PM (#68435)
    I wish I used Outlook...

    I completely missed out on that whole "Anna Kournikova" thing and now I can't even run this one...

    It's either buy Outlook or hope Lotus Notes releases a "Microsoft Virus Enabler" patch

    *sigh*
  • Re:These virus writers have no imagination... by wildlime (Score:1) Sunday July 22 2001, @10:33PM
  • Solution: Ban Stupidity! by redcliffe (Score:1) Sunday July 22 2001, @08:59PM
  • Re:solution: don't use outlook by Ridiculator (Score:1) Sunday July 22 2001, @11:40PM
  • Outlook Virus #23948842^99 (conservative estimate) by madman2002 (Score:1) Sunday July 22 2001, @08:18PM
  • Re:What does your post have to do with the OS? by idej_retsam (Score:1) Monday July 23 2001, @04:38AM
  • Actualy, it is a virus. by AnthraX101 (Score:1) Monday July 23 2001, @08:06AM
  • Re:Another Nasty Outlook Virus Strikes by Swaffs (Score:1) Monday July 23 2001, @12:07PM
(1) | 2 | 3 | 4 | 5 | 6