Kama Sutra (warning)

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • peloquin
    Till I Come!
    • Jun 2004
    • 8643

    Kama Sutra (warning)

    Kama Sutra Worm Set for Attack on Feb. 3

    Security analysts are warning computer users about a new and potentially destructive Internet worm that can obliterate important documents. The worm, called Kama Sutra, is making the rounds now, but is scheduled to execute its first massive attack on February 3.

    The malicious worm targets computers running Windows and spreads primarily by copying itself to shared network locations and then sending itself to e-mail addresses found on afflicted computers. With subject lines that read "the best videoclip ever," "give me a kiss," and "school girl fantasies gone bad," the worm entices computer users to open the attached file.

    "This worm feeds on people's willingness to receive salacious content on their desktop computer, but they could be putting their entire company's data at risk," said Graham Cluley, senior technology consultant at Sophos.

    According to Sophos, on the third of each month, the worm will attempt to disable existing antivirus and firewall software and also will delete specific files, such as Microsoft Office documents.

    Waxing or Waning Threat

    The worm is also known as Blackworm, Nyxem-D, and W32.Blackmail.E, among others. There are disagreements in the security industry about the severity of the worm, with Symantec and F-Secure taking different positions on the issue.

    Controversy stems from interpreting one of the worm's most intriguing features: a Web counter. Once the worm infects a new computer, it accesses a Web page on which there is a counter. The counter number increases whenever the Web page is accessed.

    Andrew Jaquith, a Yankee Group senior analyst, said that most reports indicate that the counter had risen already to 700,000, which could indicate that nearly a million computers are infected.

    Much of the speculation in the industry about the potential for damage done by the Kama Sutra worm centers on the counter number -- which might represent unique machines or accesses to the counter page by the same machine more than once. One of the things that is "sorely lacking" with mass outbreak malware like the Kama Sutra worm, Jaquith said, is any real sense of how many machines are compromised.

    "We still don't know, for example, how many machines were really affected by the WMF vulnerability," he explained. "The antivirus vendors don't seem to know either, or are unwilling to divulge much -- possibly because it would expose gaps in their signature coverage."

    Back to Old-School

    To address what is so far the most expansive malware attack in 2006, speculation among security vendors and researchers has focused on the destructive nature of the worm. Unlike most viruses currently in the wild, the Kama Sutra code is not intended to reap the code writer a windfall of ill-gotten gains. The hacker designed the worm to create mayhem by destroying documents.

    "The reason why experts at Sophos believe the worm is likely to have been written by an old-school hacker rather than an organized criminal is its destructive payload," Cluley explained. "That kind of destructive behavior is not typical of financially motivated worms because the damage is too obvious to the end user."

    Frost & Sullivan analyst Rob Ayoub said he is not convinced that the worm represents the work of an old-school hacker, but did suggest it is unusual. "This is just something we haven't seen in a while. It's not a botnet or a zombie. It's a throwback to malware that only seeks to create havoc."

    ActiveX Controls

    Of greater concern, said Ayoub, is the worm's ability to deceive Windows into receiving a malicious ActiveX control by providing a phony digital signature. Discovered originally by Fortinet, the worm apparently adds some 18 entries to the Windows Registry, allowing it to insert an ActiveX control that can circumvent Windows' defense mechanisms.

    The development is interesting, Ayoub said, because, heretofore, the assumption has been that if a piece of software has a digital signature, then it is safe. Ayoub said Microsoft will need to take a serious look at digital-signature technologies.

    "In the past, it has always been if the company signs it, then it must be authentic," Ayoub said. "Microsoft needs to look at the digital signing process or else we will see more things like this, and that is pretty dangerous because it gets around some of the safeguards that are supposed to keep these things out."

    Analysts are urging computer users, especially home users, to make sure that they have up-to-date antivirus software installed on their machines. "There should be no excuse for any data being lost on February 3 by this worm, but there is always the danger that some home users will not have heard that warning," Cluley said.


    from yahoo
  • asdf_admin
    i use to be important
    • Jun 2004
    • 12798

    #2
    Re: Kama Sutra (warning)

    yes. sex with my computer files. i fucking love it!
    dead, yet alive.

    Comment

    • hulkhuss
      Are you Kidding me??
      • Jun 2004
      • 3699

      #3
      Re: Kama Sutra (warning)

      die hackers die!!!!!!
      http://www.mixcloud.com/RMasie/

      http://soundcloud.com/r-masie

      https://www.facebook.com/R-Masie-117851198318029/

      Comment

      • FM
        Wooooooo!
        • Jun 2004
        • 5361

        #4
        Re: Kama Sutra (warning)

        it never ends
        FM

        "Nowadays everyone is a fucking DJ." - Jack Dangers

        What record did you loose your virginity to?
        "I don't like having sex with music on- I find it distracting. And if it's a mix cd- forget it. I'm stopping to check the beat mixing in between tracks." - Tom Stephan

        Download/Listen To My Mixes
        Facebook!
        A Journey Into Sound On MCast

        Satisfaction guaranteed, or double your music back.

        Comment

        • miketpoto
          Shabisquik The Ghetto Queen
          • Jan 2005
          • 4223

          #5
          Re: Kama Sutra (warning)

          The malicious worm targets computers running Windows
          worms

          Comment

          • nicomax
            Gold Gabber
            • Jun 2004
            • 667

            #6
            Re: Kama Sutra (warning)

            So, no attachment openings? Is that all? Any other way we can get nailed?
            Nicomax

            Comment

            • picklemonkey
              Double hoodie beer monster
              • Jun 2004
              • 15373

              #7
              Re: Kama Sutra (warning)

              I love viruses. I think I might have contracted one last night.

              Comment

              • Balanc3
                Platinum Poster
                • Jun 2004
                • 1278

                #8
                Re: Kama Sutra (warning)

                In addition to the email upgrades network solutions if performing, the release of IE7 beta, and the superbowl.... this could get interesting!

                Here's the cut and paste from a document I sent to our reps:

                From: HQ Helpdesk Alert
                Sent: Thursday, February 02, 2006 9:13 AM
                Subject: **** Possible Virus Threat - 02/02/06 ****
                Importance: High


                This email is Blind Copied to ALL Associates

                Attention All Associates:

                In an effort to protect the integrity and security of our associates and network, we would like to make you all aware of a potential security threat.
                It has come to our attention that a new variant of the Nyxem.A computer virus dubbed Nyxem.E is spreading via email. The virus re-activates on the 3rd of each month and is expected to reactivate this Friday 02/03/06.

                To help prevent the propagation of this virus please avoid opening emails containing the following Subject Lines: Hot Movie” or “The Best Video Clip Ever” or any emails of a sexuality explicit nature. The User community should report any instances of these emails to the HD immediately for action. Any emails that appear suspect should also be reported to the HD-NOC and unexpected loss of files is no exception and should be reported.

                The virus typically spreads in email messages with empty subject lines and body texts.

                If you receive these emails DO NOT OPEN THEM; Please delete the email from your Inbox and Deleted Items and notify the Internal Helpdesk immediately for further assistance.
                JourneyDeep .into the sound

                Comment

                • thesightless
                  Someone will marry me. Hell Yeah!
                  • Jun 2004
                  • 13567

                  #9
                  Re: Kama Sutra (warning)

                  Originally posted by nicomax
                  So, no attachment openings? Is that all? Any other way we can get nailed?
                  oral, anal, normal, doggystyle, rape, S&M, bondage, many many more.
                  your life is an occasion, rise to it.

                  Join My Chant. new mix. april 09. dirty fuck house.
                  download that. deep shit listed there

                  my dick is its own superhero.

                  Comment

                  • hulkhuss
                    Are you Kidding me??
                    • Jun 2004
                    • 3699

                    #10
                    Re: Kama Sutra (warning)

                    Originally posted by thesightless
                    oral, anal, normal, doggystyle, rape, S&M, bondage, many many more.
                    :ROFLMAO:
                    http://www.mixcloud.com/RMasie/

                    http://soundcloud.com/r-masie

                    https://www.facebook.com/R-Masie-117851198318029/

                    Comment

                    • toasty
                      Sir Toastiness
                      • Jun 2004
                      • 6585

                      #11
                      Re: Kama Sutra (warning)

                      anyone have this pop up yet? I normally get tons of virus type emails at work when there is something circulating, but I haven't seen anything all day...

                      Probably best -- I could easily see some of my coworkers opening the damn thing...

                      Comment

                      • Lrn
                        Are you Kidding me??
                        • Jan 2005
                        • 3233

                        #12
                        Re: Kama Sutra (warning)

                        yea nothing here yet

                        Comment

                        • peloquin
                          Till I Come!
                          • Jun 2004
                          • 8643

                          #13
                          Re: Kama Sutra (warning)

                          nothing here either...

                          Comment

                          • hulkhuss
                            Are you Kidding me??
                            • Jun 2004
                            • 3699

                            #14
                            Re: Kama Sutra (warning)

                            3,2,1.....nothing
                            http://www.mixcloud.com/RMasie/

                            http://soundcloud.com/r-masie

                            https://www.facebook.com/R-Masie-117851198318029/

                            Comment

                            • Yao
                              DUDERZ get a life!!!
                              • Jun 2004
                              • 8167

                              #15
                              Re: Kama Sutra (warning)

                              Blowkick visual & graphic design - No Civilization. Now With Broadband.

                              There are but three true sports -- bullfighting, mountain climbing, and motor-racing. The rest are merely games. -Hemingway

                              Comment

                              Working...