MoMusings

Wednesday 14th June, 2006


Truth or Scare?

Filed under: All, Malware, Exploits

There seems to be a new ‘virus warning’ being sent around, clogging up mailboxes and generally causing lots of FUD [Fear, Uncertainty and Doubt].

So, is it a case of ‘yet-another-virus-hoax’ chain e-mail type of warning or is this a real threat? Should you worry, pass it on, put it in the bit-bucket, or what?

Read on and find out.

So you get an e-mail from someone you know, or even a complete stranger that looks like this:

“There is an email going around with the subject “New Graphics Site”. It is spreading fast as about 100 people I know have gotten it just today. If you get an email with that in the subject line delete it quickly and DO NOT OPEN IT! This is a new virus I have been told.”

The Facts:

  • There is a new mass-mailing worm that has the subject of “New Graphics Site”.
  • Opening it and or viewing the e-mail does make it spread.
  • There is no attachment, the viral code is part of the e-mail body.
  • This only [at this time] affects those that use Yahoo web-mail via a web browser.
  • Turning off JavaScript support in your browser should stop it functioning.
  • Most anti-virus products now detect this.
  • The worm cannot run on the newest version of Yahoo Mail Beta.

F-Secure state that:
“The Yamanner worm does not send itself as an attachment, it resides inside the e-mail body. The worm activates automatically by just opening an infected e-mail message with Internet Explorer. It uses a 0-day vulnerability in Yahoo! webmail system.”

And according to McAfee:
“There are reportedly two known variants of this threat. It appears to be under development/refinement and the initial variant contains a typo in the code”.

Furthermore, the worm targets e-mail addresses that are in the yahoo.com and yahoogroups.com domains only at this time. It replicates by running a JavaScript which sends copies of itself to other e-mail addresses harvested from infected users Yahoo Mail folders. It also, as part of its routine sends these harvested e-mail addresses to a remote server which is obviously collecting them for other nefarious purposes, such as to sell as a spam list.

I suspect this attack on the web mail service of Yahoo is the start of a trend in attacking web-based e-mail services. The Internet Storm Center had this to say on the current state of many web based applications: “After testing several popular web applications, we have found that several are in fact vulnerable to the very same type of exploit.”

Links:

Back to my question I asked at the start of this posting “Should you worry, pass it on, put it in the bit-bucket, or what?” The correct answer is firstly to confirm that such a problem/threat exists via ‘reliable sources’, and if real just be aware of the problem and how to avoid it or protect against it, apply this knowledge and any required patches or security updates [Anti-Virus, Anti-Spyware, Windows Update, etc.], then send the warning e-mail to the bit-bucket.


Please note that this blog has now moved to my own hosted domain here: http://momusings.com/momusings/.
A full RSS/ATOM feed can be found there.

All the data up to the end of December 2006 will be left here, however all postings from the 1st of January 2007 onwards will only be available at this blogs new home.
ALL future postings will only be available at the new site.

Comments »

The URI to TrackBack this entry is: http://momusings.blogsome.com/2006/06/14/truth-or-scare/trackback/

No comments yet.

RSS feed for comments on this post.

Leave a comment

Line and paragraph breaks automatic, e-mail address never displayed, HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong>


Get free blog up and running in minutes with Blogsome | Theme designs available here