This is an article from ABCNews.com (actually from MrShowbiz.com):
Seinfeld 'Bubbleboy' Virus Hits E-mail
Seinfeld, the TV series, lives on in more ways than one. The now-dead NBC
sitcom has received a left-handed homage with a new e-mail virus dubbed
"Bubbleboy" after an episode in which Jerry (Jerry Seinfeld) and George
Costanza (Jason Alexander) accidentally burst the protective plastic bubble
of a boy born without an immune system.
"Unfortunately, this virus is not very funny," says Sal Viveros, a marketing
manager at Network Associates.
Researchers believe this to be the first e-mail-borne computer infection
that doesn't require a user to open an e-mail or e-mail attachment for it to
wreak havoc. The virus is known as a worm because it is self-propagating.
Researchers at antivirus software firm Network Associates Inc. received the
computer infection anonymously Monday night at about 10 p.m. local time,
reports Reuters.
"Historically, as long as you don't open e-mail attachments you're safe from
virus infection, but this changes all that," said Viveros. "We've finally
come to the point where if you're using e-mail, specifically Microsoft
Outlook, you need to have some sort of virus protection or you shouldn't
read e-mail."
Although the Bubbleboy virus that researchers received last night didn't
cause harm such as deleting files or stealing passwords, it won't be long
before variants crop up that are indeed destructive, Viveros says.
"In this case, it's just sending itself all over the place but it could
fairly easily delete files or steal passwords," Viveros says.
Bubbleboy appears as an e-mail with "Bubbleboy is Back!" in the subject line
and includes pictures and sounds from the Seinfeld episode that gave it its
name.
Bubbleboy follows other e-mail-borne viruses that have already swept the
Internet such as the "ExploreZip worm," which can erase files from a user's
computer, and the Melissa virus, which gained notoriety for its ability to
spread quickly but not because it destroyed any data.
Network Associates gave Bubbleboy a "low risk" classification for now
because customers haven't yet notified it that the virus has appeared on
their computers.
What makes this worm particularly nefarious is that if a user is running
Outlook Express and has the preview pane enabled, the worm can infect the
computer without the user even opening the e-mail.
The preview pane in Outlook Express lets users scan e-mails to see their
contents without having to open them first. Other e-mail programs such as
Exchange and Lotus Notes are also vulnerable, Viveros says.
"Now just by reading an e-mail you can be infected, and if you're using
Outlook Express, you don't even need to read it," Viveros says. The worm
will then send itself to everyone listed in that e-mail program's address
book.
Reuters contributed to this story
So is the threat real? No, and Yes. Are the anti-virus companies honest in
their press releases? Absolutely not. Is the media responsible in their
reporting of virus threats? Absolutely not. Does this help consumers?
Absolutely not. Should you ignore reports of virus threats in the media? Not
completely, but you need to learn to read between the lines and absolutely
distrust anything coming from the mouths of PR flaks at the anti-virus
houses. Their history is nothing short of disgusting. You can read a lot of
the sordid details here:
http://kumite.com/myths/
The author is a true virus expert, and his credentials are there on his web
site. Here is his reaction to Bubbleboy:
http://kumite.com/myths/opinion/thoughts/#991110
--
Tom Koch (MS MVP)
Awareness is free.
"Steve Horne" <hor...@tomahawks.org> wrote in message
news:ugizVBQL$GA.241@cppssbbsa04...
Tom C. Koch <tomko...@hotmail.com> wrote in message
news:OWt2VRQL$GA....@cppssbbsa02.microsoft.com...
[snip]
> Bubbleboy is nothing new; it exploits a security hole for which Microsoft
> released a security patch on 31 August, a fact which I notice was not
> mentioned in your article. Of course, if it had been mentioned, no one
would
> be running out to buy Network Associates software, now would they?
> http://www.microsoft.com/security/Bulletins/ms99-032.asp
>
> So is the threat real? No, and Yes. Are the anti-virus companies honest in
> their press releases? Absolutely not
[snip]
> "Steve Horne" <hor...@tomahawks.org> wrote in message
> news:ugizVBQL$GA.241@cppssbbsa04...
[snip]
> > "Unfortunately, this virus is not very funny," says Sal Viveros, a
> marketing
> > manager at Network Associates.
[snip]
You're right of course. We should always wait until large numbers of people
have lost data to the sadistic and entirely predictable virus writers before
we react. And the press shouldn't "play up" the danger until they can first
document the number of gigabytes already lost.
Bruce.
> > So is the threat real? No, and Yes. Are the anti-virus companies honest
in
> > their press releases? Absolutely not. Is the media responsible in their
> > reporting of virus threats? Absolutely not. Does this help consumers?
> > Absolutely not.
>
> You're right of course. We should always wait until large numbers of
people
> have lost data to the sadistic and entirely predictable virus writers
before
> we react. And the press shouldn't "play up" the danger until they can
first
> document the number of gigabytes already lost.
>
What a bizarre interpretation of my message. But I notice that you are
unable to refute even one point that I made.
--
Tom Koch
Awareness is free.
What an odd interpretation of my message. In fact I did, on all counts.
Bruce.
Or in this case: The first byte lost. -- John H
>Tom C. Koch <tomko...@hotmail.com> wrote in message
>news:OWt2VRQL$GA....@cppssbbsa02.microsoft.com...
>> So is the threat real? No, and Yes. Are the anti-virus companies
>> honest in their press releases? Absolutely not. Is the media
>> responsible in their reporting of virus threats? Absolutely not. Does
>> this help consumers? Absolutely not.
>
>You're right of course. We should always wait until large numbers of
>people have lost data to the sadistic and entirely predictable virus
>writers before we react. And the press shouldn't "play up" the danger
>until they can first document the number of gigabytes already lost.
The press could have mentioned that a patch that prevents thisexploit was
released in August, and that the virus hasn't been seen "in the wild" yet.
Of course, a story about a 10 week old patch is much less news-worthy than
a sexy new virus.
Reporting "threats" without bothering to mention that the immediate fix is
available is irresponsible.
>Bruce.
A
Larry Suddarth
A <AM...@hotmail.com> wrote in message
news:36476.831038546B7...@12.78.213.223...
>A,
>I spent the better part of the day sorting out the Security Bulletins
>from Microsoft. If you follow them in sequence from oldest to newest, I
>think that they did a pretty good job with the problem. Some problems do
>still exist as Microsoft has indicated. As best I can tell, you should
>now disable active scripting and put trusted sites in the "Trusted
>Zone." The reason that I feel that Microsoft is right on target, is that
>Bugnet gave the web address of Gorgi Guninski, a 27 year old man from
>Bulgaria. Microsoft gave him credit for finding several of the security
>holes. I ran some tests that Gorogie had on his web page at:
>http://www.nat.bg/~joro/index.html I feel like the test support
>Microsoft's advice, if you follow the Security Bulletins from oldest to
>newest. I would be interested in your comments. You are one of my
>favorite people to read due to your knowledge of computers.
Thanks for the compliment, Larry.
I'm afraid I have to admit that I don't set the best example when it comes
to "good digital hygiene". I tend to be lackadaisical about applying
patches and security updates.
I do think that the MS Security site is intimidating, and not as helpful as
it could be. It would be nice if they created a page like the Windows
Update site that would check which patches you have installed, and allow
you the option of installing all critical security updates for your system,
or, if a patch works by disabling some functionality, giving you the choice
of installing it or not.
There are times when I'd rather pretend that I didn't know about sites like
Gorogies :-)
A
Larry Suddarth
A <AM...@hotmail.com> wrote in message
news:36476.892432996EE...@12.78.213.223...
However, I do agree with you that the anti-virus companies stand to gain the
most from Microsoft's mistakes in this case--probably big time if, as I
suspect, we have a series of nasty outbreaks over the next week or two. You
can't buy that kind of publicity. And I wouldn't be surprised if the real
creator of the worm was an employee/stockoptionholder of one of those
companies. And a smart cookie, too, since he released it to several of them
at the same time--if his own company had been visibly the first to have it,
that would be a big pointy finger.
--
.a/ssig
Stupidity isn't a crime, even when it comes to spamnuts. So how about theft
of service, false advertising, chain scams...
Please don't misunderstand me. There is a threat from this type of worm,
though not from BubbleBoy itself, just like there are real threats from real
viruses out there. What I object to very strongly is the media hype
surrounding the entire area of security. This latest was obviously nothing
more than a press release from an AV company masquerading as news. An
article about a scripting issue for which a patch was released 10 weeks ago
just would not be newsworthy, and would not result in frightened users
rushing out to buy more AV software.
I would again urge all those concerned about the security of their computer
to read this web site. There is a huge amount of information there that you
will *not* find at the AV web sites. And the author is a recognized expert
in the field, not a PR flak for McAfee or Norton pretending to know
something.
--
Tom Koch
Awareness is free.
"Shannon Jacobs" <sha...@my-dejanews.com> wrote in message
news:exOsaEeL$GA....@cppssbbsa02.microsoft.com...
I concur that the Microsoft security people seem to have recognized the
significance of the problem and addressed it very promptly. However, this
patch badly NEEDS to be on the Windows Update page, and as of my last check,
it still wasn't. In fact, I think this one is so serious it almost calls for
an email campaign to all of the registered users of Windows 98/OE5--but
Microsoft is VERY unlikely to do that. Bad publicity. They'd rather keep
their fingers crossed--and it isn't their data at risk, anyway.
Then again, in the worst case I can imagine--and unfortunately I have a very
vivid imagination--we are about to see a lot of people get hit very hard,
and that may give Microsoft even more bad publicity than if they came out
and sent the email showing just how closely they track us... Imagine some
diabolical moron using the available source code of this thing, adding a
really nasty payload, and then using a spambot to do the initial
distribution before enough of the SMTP hosts are protected. This could be a
very ugly week.
--
.a/ssig
Perhaps my punishment by evil spam email is due to evil karma from a past
life? But there sure seems to be a sudden large increase in my karmic
debts.
--
Gerald Jones
Thames Valley, England:
(remove No in e mail address)
Tom C. Koch <tomko...@hotmail.com> wrote in message
news:eEGKlESL$GA.250@cppssbbsa04...
> Bruce -
>
> > > So is the threat real? No, and Yes. Are the anti-virus companies
honest
> in
> > > their press releases? Absolutely not. Is the media responsible in
their
> > > reporting of virus threats? Absolutely not. Does this help consumers?
> > > Absolutely not.
> >
> > You're right of course. We should always wait until large numbers of
> people
> > have lost data to the sadistic and entirely predictable virus writers
> before
> > we react. And the press shouldn't "play up" the danger until they can
> first
> > document the number of gigabytes already lost.
> >
>
> What a bizarre interpretation of my message. But I notice that you are
> unable to refute even one point that I made.
>
> Please don't misunderstand me. There is a threat from this type of
worm,
> though not from BubbleBoy itself, just like there are real threats
from real
> viruses out there. What I object to very strongly is the media hype
> surrounding the entire area of security. This latest was obviously
nothing
> more than a press release from an AV company masquerading as news.
An
> article about a scripting issue for which a patch was released 10
weeks ago
> just would not be newsworthy, and would not result in frightened
users
> rushing out to buy more AV software.
It's worth to point out that this worm, like many others, can be
avoided just having a %windir% name different than the default. It
looks strange to me that nobody even suggests this easy, harmless,
useful security measure.
+++
This changes nothing in Microsoft's responsability, in my opinion.
I'm not a programmer, but I could easily figure that allowing active
content as _default_ setting, with no info to the costumer
about the implicit risk of that choice, it's shamely unresponsable.
An exploit about how to format a drive with a vbscript was available
on bugtraq before the patch was released. Please think how
many times you needed to run ActiveX in e-mail (I never did, in 1353
mail + ~50000 news messages), then compare cost vs. benefits.
--
Bye,
Francesco
Remove Bindi to reply in e-mail
Yep, they should always wait for users to loose data.
Bruce.
That is not easy unless you want to re-install Windows and all applications.
Also, a script could simply reference the variable name, %windir%, even
though this particular script may not do that.
The fix was posted in August, Bruce.
I didn't say they shouldn't report virus threats. I said that reporting
them without telling people that there was a fix already available is
irresponsible.
You're not a journalist, by any chance?
>Bruce.
A
"Bruce Chastain" <bcha...@XNOSPAMXhyperfeed.com> wrote in message news:#X91yO3L$GA....@cppssbbsa02.microsoft.com...
A <AM...@hotmail.com> wrote in message
news:36476.831038546B7...@12.78.213.223...
> Reporting "threats" without bothering to mention that the immediate fix is
> available is irresponsible.
Yep, they should always wait for users to loose data.
Bruce.
Since virus writers are pathologically compelled to exploit each and every
weakness in the system, and as such are entirely predicable, there's no such
thing as a virus or potential virus that's not a big deal. It's not a
matter of whether customer data will be destroyed, but when. Since it takes
time for the news to disseminate, the sooner they get started, the better.
I hope the journalists will continue to responsibly inform us of both
present threats and the entirely predictable future threats, whether they
have knowledge of a fix at the time of writing or not.
I agree that informing us of a fix is also important, but silence will never
be an acceptable alternative when they aren't yet aware a fix. If they are
unable to quickly find information about a fix, then I say run the story as
is. I'd rather get the story in bits and pieces instead of a reported
censoring themselves because of the inability to find details which may not
even exist yet.
I found the reporting of Bubble Boy to be entirely appropriate and timely.
Not every report included every possible detail, but that's perfectly
acceptable since it helps alerts us even sooner. The possibility of a virus
that could infect without even launching an attached file is a really big
story, and deserved as much coverage as it could get. Even if no one has
been injured by it yet, the timely coverage will help reduce future
injuries, and will help bring pressure on MS to stop producing such
outrageous security holes in their programs.
Bruce.
I know, but apparently not everyone else did. That's unfortunate, but
entirely expected.
> You're not a journalist, by any chance?
Nope, just a virus target.
Bruce.
>A <AM...@hotmail.com> wrote in message
>news:8E7F663A3AML...@207.46.180.23...
>> The fix was posted in August, Bruce.
>
>I know, but apparently not everyone else did.
Because the "responsible" media didn't bother to tell them. I don't recall
hearing any mention of a fix in the mainstream media, yet I heard many
reports of a threat that was not yet known "in the wild" (they didn't
mention that little nugget either).
If the mainstream media had said - "Don't even open your e-mail package
until we broadcast details of the fix", they would at least have been part
of the solution, instead of being part of the problem
A
Since it isn't in the wild yet, there isn't any problem for them to be part
of. All they did was raise awareness as early as possible which I view as a
good, beneficial, and responsible act.
Bruce.
--
Tom Koch (MS MVP)
Awareness is free.
"Bruce Chastain" <bcha...@XNOSPAMXhyperfeed.com> wrote in message
news:u4CDmIFM$GA.241@cppssbbsa04...
If they knew about it and failed to report it, yes. Otherwise no.
Bruce.
"Bruce Chastain" <bcha...@XNOSPAMXhyperfeed.com> wrote in message news:#HA20OFM$GA.251@cppssbbsa05...
It's safe to say that 99% of reporters are not "real reporters of Internet
news", so what does that leave us with? Virtually no Internet news at all?
Can non-farmers report farming news? Can non-auto workers report stories on
cars? Does the source of each news story have to talk with EVERY reporter
at EVERY paper in EVERY country just to make sure everyone has the right
information, and first hand?
The situation you suggest is totally unworkable. In order for us to get
news on a zillion different topics, it's guaranteed that 99% of the time the
reporter really doesn't know the topic very well and must trust the text
they get from other news services. No doubt they try to verify the details
for the stories they can grasp the details of, but as I noted above, that's
almost always impossible.
Just as it's virtually impossible for the reporter to be an expert in every
field they report on, especially in the computer industry.
While I agree with your goals and ideals, they aren't realizable in this
world.
Bruce.
"Bruce Chastain" <bcha...@XNOSPAMXhyperfeed.com> wrote in message news:e6PqywHM$GA....@cppssbbsa02.microsoft.com...
Bruce.
Spaceman <spac...@realspaceman.com> wrote in message
news:eT4JxqJM$GA.275@cppssbbsa04...
"Bruce Chastain" <bcha...@XNOSPAMXhyperfeed.com> wrote in message news:uVdVwTRM$GA....@cppssbbsa02.microsoft.com...
Sorry, but there's 4 gazillion topics out there and just a relatively few
reporters and sources of news. Your "solution" may work in an extremely
limited case, but it totally impractical for 99% of the news out there.
And as I pointed out earlier, the sources of the news story can't possibly
handle ALL the reporters in the world and their efforts to verity stories,
so reporters MUST take a large portion of what they report from other
reports.
And even if you limited yourself to just the very rare knowledgeable
reporter, I find it amazing how often the supposed "experts" get it wrong
too. So they can't really be trusted either.
Nope. Your suggestion is totally unworkable.
Bruce.
"Bruce Chastain" <bcha...@XNOSPAMXhyperfeed.com> wrote in message news:#bgN55UM$GA....@cppssbbsa02.microsoft.com...
--
Tom Koch (MS MVP)
Awareness is free.
"Bruce Chastain" <bcha...@XNOSPAMXhyperfeed.com> wrote in message
news:#bgN55UM$GA....@cppssbbsa02.microsoft.com...
> Spaceman <spac...@realspaceman.com> wrote in message
> news:#MOOJ#RM$GA....@cppssbbsa02.microsoft.com...
> >don't listen to internet reporters unless you want news on internet
> reporters....
> >and not actual Internet news...
> >since any person that really did any investigation ....(part of
> reporting.....)
> >would have been considered a real reporter and not an Internet
reporter...
>
So maybe it's only if you're flying, hence the "bubble", they do float, that
you could possbily get the virus.
I'm still trying to fiigure what the hey Lockheed was a reliable source for.
These so called reporters can't make up their minds what they want to do
except cause a panic situation then put a retraction about it way way way in
the back in small print that 99.99999999999999999% of the times overlooked
and then only those that do see it didn't see the story to begin with and
have no clue as to what the retraction was about.
These reporters are getting to be like AOL, a joke.
Majik
"Tom C. Koch" <tomko...@hotmail.com> wrote in message
news:#RlRAWVM$GA.204@cppssbbsa05...
>It's safe to say that 99% of reporters are not "real reporters of Internet
news", so what does that leave us with? Virtually no Internet news at all?
Can non-farmers report farming news? Can non-auto workers report stories on
cars? Does the source of each news story have to talk with EVERY reporter
at EVERY paper in EVERY country just to make sure everyone has the right
information, and first hand?
Non-farmers do farming news all the time. Wake up early enough and get the
farm report and you'll see women (not running down the gender mind you)
doing the reporting and hell, I know they don't do any farming. I've seen
some that didn't know the different between a hay baler and combine. They
learned, but it took a while. I'm not knocking them for not knowing, I'm
saying they're non-famers reporting farm news. You'll find better farm info
at the local co-op.
Non-auto-workers reporting auto news. Sure maybe they can work on one a
little, but the possiblity of them being able to build or rebuild a car from
the ground up in very very low.
The reporter(s) should talk to reliable sources. They teach that part, I
know fo a fact. You have to have a reliable source within the industry or
whatever the story is about. You can't go over there and get Spaceman and
have him be a source on land reclamation from the coal industry.
One of the reports I read had as their source someone from Lockheed. The
last time I checked, Lockheed was making planes, not e-mail software or
operating systems for the personal computer. They may write software for
their planes, but when was the last time you ran any of it on your home
computer?
>The situation you suggest is totally unworkable. In order for us to get
news on a zillion different topics, it's guaranteed that 99% of the time the
reporter really doesn't know the topic very well and must trust the text
they get from other news services. No doubt they try to verify the details
for the stories they can grasp the details of, but as I noted above, that's
almost always impossible.
We agree upon somethign here, but their choice of a reliable source is what
will make or break the story and when it's broke, it's irresponsible
reporting.
>Just as it's virtually impossible for the reporter to be an expert in every
field they report on, especially in the computer industry.
>While I agree with your goals and ideals, they aren't realizable in this
world.
No, they never will work because people try to take shortcuts instead of
getting the real facts and using them.
Majik
Bruce.
> Just as it's virtually impossible for the reporter to be an expert
in every
> field they report on, especially in the computer industry.
It's a simple rule: to listen to both sides.
Got an information about a security problem in a MS program? Well,
contact Microsoft, _before_ printing the article. If this looks too
heavy to you (you=the reporter), then get another job.
Don't you think so?
If they did, they 'd have reported the correct story (a pity MS bug,
depending IMO on the original mistake to allow active content to run
by default). But they'd also said "A fix is available at the url: ..."
> While I agree with your goals and ideals, they aren't realizable in
this
> world.
Fortunately not all reporters think that check cross-check their
information is "not realizable in his world"
Tom,
That was not supposed to be an ultimate solution, of course.
It just adds a tad of security, at no cost, if done at first install.
Referencing to %windir% requires a further step of tecnical knowledge
to the script-writer (which is not so obvious he have) and mostly that
he thinks about this possibility.
As I told, my only reasonable solution is to disable active content in
e-mail, and that's exactly what I did long before the worm alert.
--
a( :[]={ DaffyD®
Life is a joke but we must all write our own punchline.
"Francesco Tessari" <texfr...@tiscalinet.it> wrote in message
news:814umm$1fm74$3...@fu-berlin.de...
In OE, click Tools|Options|Security and set OE to run in the Restricted
Sites Zone. Then in IE, click Tools|Options|Security, select Restricted
Sites, click Custom Level, and near the bottom under Scripting, disable (or
set to prompt) Active scripting, Allow paste operations via script, and
Scripting of Java applets. The combination of those 2 steps will cause any
scripting in HTML mail to fail.
Larry Suddarth
DaffyD <daf...@woohoo.com> wrote in message
news:#JHfX3NN$GA.252@cppssbbsa05...
> How do you disable active content in e-mail?
>
"Larry Suddarth" <sudd...@hal-pc.org> wrote in message
news:eGLH#YTN$GA.248@cppssbbsa05...
> I know that this off the subject, but I like your signature (Life is a
> joke...........)
>
> Larry Suddarth
>
> DaffyD <daf...@woohoo.com> wrote in message
> news:#JHfX3NN$GA.252@cppssbbsa05...
> > How do you disable active content in e-mail?
> >
Ditto.
Prevention is always better than cure! :-)
--
Robert.
Please keep replies within the newsgroup!
Roro's Download Palace: www.patten1.freeserve.co.uk