My Photo

Adsense


Add to Google Reader or Homepage

Subscribe in Bloglines

Subscribe in one go

  • Subscribe to RSS Feed

Your email address:


Powered by FeedBlitz

Google reader

Software worth checking out

  • ActiveWords
    Do everything without leaving the keyboard
  • Anagram
    Translates copied text into Contact, Calendar, Task, and Note items for Outlook, Palm etc
  • BlogJet
    Weblog client for Windows that allows you to manage your blog without opening a browser.
  • ConnectedText
    Intriguing Wiki-based organiser
  • Copernic Desktop Search
    Great alternative to Google's or Microsoft's offering for searching your PC. Simple and unobtrusive
  • Courier Email
    Great email program
  • DtSearch
    Text Retrieval / Full Text Search Engine
  • ExplorerPlus
    Organize and manage all your system files and folders
  • Gmail
    Webmail that really works. Great for catching spam too.
  • Google Deskbar
    Search with Google from any application without lifting your fingers from the keyboard.
  • Google Earth
    Zip around the planet and see things differently
  • Google Reader
    Best online RSS reader I think there is out there
  • Jot+
    store all of your notes and information in an easy-to-use outline
  • Local Cooling
  • Mindjet
    The mindmapper of choice.
  • MSGTAG - MessageTag
    Email receipt alert
  • MyInfo
    free-form information organizer
  • NoteStudio
  • NoteTab
    Great text and HTML editor
  • Omea Reader
    Good RSS feedreader
  • PersonalBrain
    If you've ever wanted to organise your information in a way that's different, try this. Worth spending time on mastering
  • Process Explorer
    Not too geeky way to figure out what software is slowing down your computer. Just keep it running for a while and the culprit will become obvious.
  • Safari
    Surprisingly fast browser -- and for Windows too.
  • Skype
    Dump those phone bills
  • SpaceMonger
    Keep track of the free space on your computer via treemaps
  • Stick
    Post-It note-like tabs to store text, folders etc that cling to the edge of your screen
  • SuperNotecard
    Great for authors and writers organizing their thoughts
  • TaskTracker
    Lists recent documents by type for easy access
  • Text Monkey
    Easily clean copied text
  • Trillian IM Clients
    Gathers all your instant messaging accounts in one window

« Blogging And Conferencing | Main | Is Plaxo A Namecard Spammer? »

January 28, 2004

MyDoom Is Smart, The Internet Is Dumb

The MyDoom virus appears to be bigger than SoBig.

But for me the problem has not been MyDoom, but the dumb traffic it has created. MyDoom spoofs the From field in the emails it creates to spread, so that anyone receiving a virus-laden email will not know, in most cases, who it comes from. This is not in itself new, but MyDoom (also called Mimail.R, or Novarg) does it better. As far as I can see it uses two tricks for this:

Smart, in some twisted sort of way. What is dumb is the way some webmasters handle this kind of problem.

Email spoofing -- or at least the first one, using real email addresses to send fake emails -- has been around long enough for it to no longer make much sense for servers receiving viruses to send a message to the apparent sender of the virus-ridden with some stern email notice 'YOU HAVE BEEN SENDING A VIRUS! NAUGHTY PERSON! PLEASE INSTALL A VIRUS SCANNER! DOLT!' Why? Because chances are the person had nothing to do with the email. Their email address has been used, but that could have come from anyone with it in their address book. Telling them they've send a virus is pointless: It just generates more web traffic.

The second bit of this -- the made-up email addresses -- is the new element (as far as I know). What's interesting about this is that it appears to be a deliberate ruse on the part of the virus writer to disseminate more virueses, and generate more traffic. If a virus creates a copy of itself with an email address that has a real domain (the billybraindead.com bit) behind it, it increases its chances of spreading. Either the recipient opens it or, if the recipient email address is not valid, it will bounce back to the sender. Now the sender's address may be fake, but because the domain is real, it may well end up in someone's inbox somewhere, especially if the domain is a personal one. That's because email servers on most such domains route all incoming mail, whatever the bit before the @ sign, to one mailbox. So anything for Bob, Tessa, Susie or Tim will end up in a mailbox somewhere.

In both cases, with either notifications of virus-infected accounts, or bounced emails, servers are just helping the virus to spread and to create more traffic. Webmasters have GOT to switch off their automatic 'YOU'VE GOT A VIRUS' responses because that stuff is old, real old. But we have also got to figure out a way to deal with these spoof, but real domain, email addresses. I have received more than a dozen of the latter from one o my domains, all of them with the virus still attached. I'm sure I'm going go receive a lot more before this whole thing is over.

In other words, I've received more copies of MyDoom from webmasters than I have from real, or even fake, people. Who's being dumb here?

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/t/trackback/10988/414315

Listed below are links to weblogs that reference MyDoom Is Smart, The Internet Is Dumb:

Comments

This virus hit my account and I thought it was some one inquiring about a photo and I opened it. Very,very unassuming email. Thank god I use a MAC.

This virus stinks

Post a comment

If you have a TypeKey or TypePad account, please Sign In

Loose Wire search

Eco-Safe

Rank

  • Wikio - Top Blogs - Technology
Blog powered by TypePad
Member since 12/2003

ten mov.es

tenminut.es