Amiga.org

Amiga News and Community Announcements => Amiga News and Community Announcements => General Internet News => Topic started by: vortexau on February 11, 2004, 02:39:02 PM

Title: New version of MyDoom worm hits Microsoft's Web site.
Post by: vortexau on February 11, 2004, 02:39:02 PM
Seems that there's yet another version of MyDoom; MyDoom.C, and that its been harrasing Microsoft's own servers!


From eWeek news, MyDoom.C Slams Into Microsoft.com (http://www.eweek.com/article2/0,4149,1522236,00.asp), where they say that the attacks could[/i] have caused some disruption Sunday night and Monday morning!

The NEWS goes on to say that this third variant spreads by "scanning for machines that are already infected with one of the other variants of the worm."
Title: Re: New version of MyDoom worm hits Microsoft's Web sit
Post by: whabang on February 11, 2004, 05:28:19 PM
FFS! This virus menace is too much!!!
I re-installed Windows on one of my machines a few days ago. The computer got infected by four (!) viruses during the time it took to update the virus definitions! :-x
Title: Re: New version of MyDoom worm hits Microsoft's Web sit
Post by: mikeymike on February 11, 2004, 05:57:51 PM
When will people learn how to install Windows (or pretty much any OS for that matter) properly...
Title: Re: New version of MyDoom worm hits Microsoft's Web sit
Post by: whabang on February 11, 2004, 06:54:21 PM
Properly how? :-)
Title: Re: New version of MyDoom worm hits Microsoft's Web sit
Post by: lempkee on February 11, 2004, 07:18:45 PM
when will people realize that windows is crap?

use amiga and u wont get any windows problems, not for now anyway..

minority machines shows how computers should be :)
Title: Re: New version of MyDoom worm hits Microsoft's Web sit
Post by: whabang on February 11, 2004, 07:44:11 PM
Nå er de jo lett for en norman, med alle oliepengere dere, att kjøpe allt det udstyr I har bruk for.
Her i den tredje verden så må vi spare på pengene... :-P
Title: Re: New version of MyDoom worm hits Microsoft's Web sit
Post by: mikeymike on February 11, 2004, 08:23:34 PM
Quote
Properly how?

If you're installing an operating system:

* Use trusted-clean binaries to install it with.  Eg. a vendor CD, and known clean installation packages.

* Do not connect to an untrusted network or the  Internet until the OS is fully configured and patched up-to-date!

I have written some install guides:

http://www.legolas.com/wac/installguides.html (http://www.legolas.com/wac/installguides.html)

PS - this thread reminds me of a bonehead MCSE guy at a company I previously worked at.   He was installing Windows 2000 on a load of servers, and hadn't even spotted that each one had been compromised by the nimda work while he was installing it.  I had to point it out to him.
Title: Re: New version of MyDoom worm hits Microsoft's Web sit
Post by: whabang on February 11, 2004, 08:34:21 PM
Hehe! Standard procedure, in other words...
Problem is that I don't have any trusted network at home; I have to go directly out on the net to update the system.
I normally work around this by saving the latest virus definition file on a CD, and installing AVG and a firewall before I go on-line. This time Windows crashed on me, and I couldn't find the CD with the definitions from the last time. :-(
Anyway, once I got AVG updated, it took twenty seconds to wipe the system clear from viruses... :-D
Title: Re: New version of MyDoom worm hits Microsoft's Web sit
Post by: SilvrDrgn on February 11, 2004, 08:44:28 PM
Quote
* Do not connect to an untrusted network or the Internet until the OS is fully configured and patched up-to-date!

That's hard to do when you've only got one computer, and you don't have CD's to load patches from.
Title: Re: New version of MyDoom worm hits Microsoft's Web sit
Post by: AmigaHeretic on February 11, 2004, 11:33:48 PM
Quote
If you're installing an operating system:

* Use trusted-clean binaries to install it with. Eg. a vendor CD, and known clean installation packages.

* Do not connect to an untrusted network or the Internet until the OS is fully configured and patched up-to-date!


How does that keep you from getting infected with viruses?  Maybe some, but not most.  Unless there is a new way to patch the users themselves from opening an attachment in an email from someone they don't know.   :-)

I was under the impression that even if you have the latest Windows updates you can still get infected with things like MyDoom for example.
Title: Re: New version of MyDoom worm hits Microsoft's Web sit
Post by: mikeymike on February 12, 2004, 12:21:44 AM
Quote
Hehe! Standard procedure, in other words...
Problem is that I don't have any trusted network at home; I have to go directly out on the net to update the system.

Do what I do.  Download the patches manually, keep them for a reinstall.

I also have a VBS script to install them on the quiet.
Title: Re: New version of MyDoom worm hits Microsoft's Web sit
Post by: mikeymike on February 12, 2004, 12:23:12 AM
Quote
How does that keep you from getting infected with viruses? Maybe some, but not most. Unless there is a new way to patch the users themselves from opening an attachment in an email from someone they don't know.

Yes, avoiding viruses just requires a brain :-D

Quote
I was under the impression that even if you have the latest Windows updates you can still get infected with things like MyDoom for example.

Viruses are different from worms.  I'm not sure Mydoom is actually a worm, I don't think it exploits a vulnerability in Windows, but I'm not well-read up on it.
Title: Re: New version of MyDoom worm hits Microsoft's Web sit
Post by: DanDude on February 12, 2004, 02:42:29 AM
(in the voice of Nelson Munz)
Haw, haw!!

 :-D
Title: Re: New version of MyDoom worm hits Microsoft's Web sit
Post by: whabang on February 12, 2004, 12:04:46 PM
AFAIK, the only security flaw that MyDoom uses is the average stupidity of Windows users...
Title: Re: New version of MyDoom worm hits Microsoft's Web sit
Post by: vortexau on February 12, 2004, 04:23:22 PM
(http://alien.on.earth.free.fr/weblog/pictures/Index%20Keir%20Duella.jpg)
. . . . . . . . . . . . . . . . . . . . . . . . . . .
(David Bowman, EVA near HUGE Monolithic Win-PC in orbit around Jupiter)
"My God - its full of Worms!"
Title: Re: New version of MyDoom worm hits Microsoft's Web sit
Post by: mikeymike on February 12, 2004, 06:37:29 PM
Except of course he's in the HAL mainframe room, as you can see from the visor reflection :-P
Title: Re: New version of MyDoom worm hits Microsoft's Web sit
Post by: vortexau on February 13, 2004, 02:14:38 PM
Well, maybe he went precog . . . and had a bad feeling that more scary-stuff was to come?   :-o


From ZDNet Australia (http://www.zdnet.com.au/news/security/0,2000061744,39116051,00.htm)-
Quote
Two worms that take advantage of computers whose security has already been compromised started spreading on Monday, . . . --dubbed Doomjuice and Deadhat--threatened only those users still infected with a version of the MyDoom virus, and didn't pose a major problem for businesses, which had previously cleaned systems infected with the virus, the companies said.

The LAST LINE there says: "Deadhat also spreads through the peer-to-peer file sharing program SoulSeek.