MyDoom kocks down software company web site ( 2004-02-02 09:26) (Agencies)
The MyDoom Internet worm on
Sunday knocked down the Web site of a small software company by bombarding it
with a flood of data as Microsoft Corp. (Nasdaq:MSFT) prepared for a similar,
planned attack by the virus-like program this week.
The SCO Group Inc., (Nasdaq:SCOX) a software company that has drawn the ire
of Linux advocates for trying to collect license fees for the freely available
software system, confirmed MyDoom had knocked its Web site, http://www.sco.com,
out of commission.
After defending the site in the early stage of the attack, SCO shut its site
down entirely.
"Rather than try to continue to fight, we felt it was more advantageous to
bring the site down and make that bandwidth available or other users," said SCO
spokesman Blake Stowell, adding that the company would get the site up and
running again on Monday.
SCO and Microsoft, which is being targeted by a variant of the MyDoom worm,
have each offered a bounty of $250,000 for information leading to the capture of
the author of the malicious program.
The world's largest software maker said was it preparing for an attack by the
variant worm, called MyDoom.B, which security experts have said will happen on
Tuesday.
"Microsoft remains diligent," a company spokesman said.
The speed and severity of the attack surprised security officials, although
there were no other reports of outages or slowdowns elsewhere online due to the
worm.
But experts warned that the main threat remained to unsuspecting recipients
of the worm, which spreads by spamming itself to millions e-mail accounts around
the globe.
"At this particular point people shouldn't lose sight of the fact that the
virus is still spreading," said Vincent Gullotto, vice president of the
anti-virus emergency response team at Network Associates Inc. (NYSE:NET)
WILL IT GET WORSE?
MyDoom.A, also known as Novarg or Shimgapi, emerged nearly a week ago in the
form of a spam e-mail message that contained a well-disguised virus attachment
and has been described as the most-damaging attack since last summer's twin
Blaster and SoBig outbreaks.
MyDoom was programmed to take control of unsuspecting computer users' PCs
from which it launched a debilitating denial-of-service attack on SCO on Sunday.
SCO has drawn the ire of the so-called "open source" programming community
who object to the company's claim that it has copyright control over key pieces
of the Linux operating system.
The MyDoom attack trigger was set for 11:09 a.m. EST on Sunday. But with so
many computer clocks incorrectly set, the infected machines began firing off
data requests at SCO.com hours earlier, said Mikko Hypponen, research manager at
Finnish anti-virus firm F-Secure.
"It will only get worse for SCO as time goes on," Hypponen added.
The MyDoom.B variant, which is also programmed to attack SCO, has not spread
nearly as rapidly as MyDoom.A. MyDoom.A is believed to have infected more than
one million personal computers.
Security officials have warned computer users to delete suspicious e-mail
messages that appear to come from "Mail Administrator" and other
official-looking addresses that contains a file attachment.