iEntry 10th Anniversary RSS Newsletter Advertising
Join the WebProWorld Forum!
Text: Decrease Font Size Increase Font Size | Print Print Article | Share: Delicious Digg StumbleUpon Post to Twitter Post to Facebook
CommentFriday, December 9, 2005

Sober Worm Algorithms Finnished

The scheme used by the virus writer behind the Sober worms to determine where it will connect on the Internet has been cracked by the Finnish security firm.

Another huge outbreak of the Sober worm has been scheduled to happen on January 6th, 2006. However, thanks to Mikko Hyppnen and Finnish security firm F-Secure, admins everywhere now have the information to take steps and block infected machines from hitting a URL where a new version of Sober can be obtained and installed.

F-Secure has had the information since May 2005. "(W)e informed the local police in Germany as well as the affected ISPs (in May). But we didn't want to talk about it publicly then - we didn't want to fill in the virus writer on this. But he must know this by now," Hyppnen wrote.

An algorithm in Sober generates pseudorandom URLs based on the date. 99 percent of the URLs created don't exist. The URLs, which point to free hosting servers in Germany and Austria, can be determined by Sober's creator ahead of time.

Then he can create the URL at the free hosting site at the right date to get the latest version of the worm onto any infected machine that can connect to the URL.

That list changes every 14 days, and a change has already been scheduled in existing versions of Sober on January 6th. Admins who block connections at the firewall to freenet.de, pages.at, and arcor.de should thwart any undetected Sober-infected machines on their networks, according to the report.

Previous outbreaks of Sober have delivered millions of Nazi propaganda messages to inboxes worldwide. Putting that to an end would be a tremendous benefit to users everywhere.

David Utter is a staff writer for WebProNews covering technology and business.

News Tags: Security, worm

Publish A Comment

The content of this field is kept private and will not be shown publicly.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.
6 + 4 =
Solve this simple math problem and enter the result. E.g. for 1+3, enter 4.
SEARCH












Subscribe to WebProNews


Send me relevant info