SI
SI
discoversearch

We've detected that you're using an ad content blocking browser plug-in or feature. Ads provide a critical source of revenue to the continued operation of Silicon Investor.  We ask that you disable ad blocking while on Silicon Investor in the best interests of our community.  If you are not using an ad blocker but are still receiving this message, make sure your browser's tracking protection is set to the 'standard' level.
Pastimes : Computer Learning -- Ignore unavailable to you. Want to Upgrade?


To: Rick Faurot who wrote (23723)12/9/2001 10:21:18 AM
From: Rick Faurot  Respond to of 110655
 
Israeli youths confess to Internet attack
The Associated Press
JERUSALEM (AP) Four Israeli youths in police custody have admitted to creating and spreading the computer worm "Goner" by e-mail to attack hundreds of users around the world, police said Saturday.
Police arrested the high school students, ages 15 and 16, from the northern city of Nahariya on Friday, said Meir Zohar, the head of the police computer crime squad.
The Internet worm first spread early this month to computers in Europe, especially in France and Germany. American anti-virus companies have reported more than 400 cases of Goner attacks worldwide. An Internet worm can spread to other computers on its own.
The Goner worm appears as an apparently harmless e-mail, with a subject line of "Hi" and a note asking the recipient to open an attached screen saver, which affects the computer if downloaded. The worm then spreads to all addresses in the computer's e-mail system and through the instant messaging program ICQ and Internet chat tools.
Israeli police had been investigating the case for about a week, Zohar said. One of the youths had admitted creating the worm and the other three confessed to spreading it, he said.
Under Israeli law, the suspects could face between three and five years in jail if convicted, Zohar said.

abcnews.go.com



To: Rick Faurot who wrote (23723)12/9/2001 3:04:54 PM
From: thecow  Read Replies (1) | Respond to of 110655
 
Hey Rick

is ie an exe?
yes...it's name is IEXPLORE.EXE

renaming?
yes..several recent worms or viruses (put "sircam" in google and read how it works) now use this technique to bypass any safeguards employed to stop unauthorized outbound traffic. I don't see why a real programmer would ever need to do this but I'm not a programmer so maybe there are reasons but I think your statement about this only being for malicious purposes is correct. Opera is not immune to this tactic. From the info I have read all major browsers are part of the renaming script (or whatever the hacking tool is) that the hacker uses.

tc