Re: How could the Bavarian police know about Sober.T or V?



"Gabriela Salvisberg" <salvie@xxxxxxxxxxxx> schrieb im Newsbeitrag news:pdmin19u4a94mno9k3aa85sjjedu61ha1s@xxxxxxxxxx
How could the Bavarian police know, when they published this yesterday
(Monday)...
http://www.polizei.bayern.de/blka/aktuell/presse.htm
(or see http://www.f-secure.com/weblog/)

That this will happen today (Tuesday):
http://www.f-secure.com/v-descs/sober_t.shtml

What about this, does this sound reasonable?
The worm probably was out in the wild for several days in advance to its predefined attack date, to make sure it makes a bigger attack. So the police had something to experiment on, like this:
- Infect an otherwise virgin test computer with the worm.
- Advance the computer date by one day, two, three and so on and check at what date the worm goes to work and if it phones home.
- Try to get the home server disconnected and hope it is not in Korea, China or the former Soviet Union.
- Inform the anti-virus companies. If you/they are quick, the worm will be found after the next scanner update and before it becomes active.


Turan



.



Relevant Pages

  • Massive Internet Worm Attack Timed to Match Terrorist Bombing One Week Ago
    ... Massive Internet Worm Attack Timed to Match Terrorist Bombing One Week Ago ... corroborated on CERT and other security sites. ...
    (Incidents)
  • Linux Users Running Apache - Slapper Worm Spreading Rapidly
    ... CERTŪ Advisory CA-2002-27 Apache/mod_ssl Worm ... OpenSSL 0.9.6d or earlier on Intel x86 ... During the infection process, ... information on other infected systems as well as attack instructions. ...
    (comp.security.firewalls)
  • RE: help - can someone explain this to me?
    ... > every network that has Wintendo boxes in it. ... This worm cannot do any harm to your Linux box. ... >> perhaps a machine that the ISP hosts is infected with something ... Can anyone identify what sort of attack it was? ...
    (Security-Basics)
  • Re: help - can someone explain this to me?
    ... > every network that has Wintendo boxes in it. ... This worm cannot do any harm to your Linux box. ... >> perhaps a machine that the ISP hosts is infected with something ... Can anyone identify what sort of attack it was? ...
    (Security-Basics)
  • Re: Whats up with Zone Alarm?
    ... I was told and have to agree that anti virus software would not have stopped ... the Red Worm attack and it did not stop it. ... necessary measures to protect the machines with the security patches with MS ...
    (comp.security.firewalls)