republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » How Sober activates
Search Topic:
Uniqs:
433
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
My machine »
« Cisco Switch and Nat  
AuthorAll Replies


photobum

join:2005-11-04
Fairborn, OH
How Sober activates

»www.f-secure.com/weblog/archives···00000729


gracie
Geek Goddess
Premium
join:2003-07-15
confusion

interesting article; seems to be on target. i like sending these to newbies i'm trying to educate, as many enjoy seeing something that explains what to them is just dark mystery and makes them a bit more proactive in wanting to stay protected.
--
graciella! "not tonight dear, I have DSL."
Creating SuperOrganizations Worldwide
Creating & Hosting SuperSites Worldwide

B
Premium,MVM
join:2000-10-28

Great analysis by F-Secure...

They look like this. These are the download sites Sober.Y will start using on 5th of January. We're leaving out the filename of the actual executable, but this should be good enough list of addresses you might want to block at your corporate firewall, if you're a system administrator:

»people.freenet.de/gixcihnm/
»people.freenet.de/tobtrfjabzw/
»people.freenet.de/utzmfucaau/
»people.freenet.de/phyibrpkcpl/
»people.freenet.de/lhxrdryo/
»people.freenet.de/yediykdq/
»people.freenet.de/bjjhdkybpyaj/
»scifi.pages.at/agzytvfbybn/
»home.pages.at/bdalczxpctcb/
»free.pages.at/ftvuefbumebug/
»home.arcor.de/ijdsqkkxuwp/
»home.arcor.de/ldhdytdu/
»home.arcor.de/wdqodvdhwwese/
»home.arcor.de/frweemrecuvw/
»home.arcor.de/nulmjznomnt/

Right now, none of these URLs exist. If they are to be used, the virus writer will register them just before the activation.
So if someone (like, you know, a guy with a badge) persuades these web hosts to render those URLs harmless, Sober.Y is dead for this round?

-- B
--
In a realm outside causality and function

mysec
Premium
join:2005-11-29


1 edit
How would you prevent Sober from installing?

It has to be opened from an email attachment (which you would never do, of course) but what about others' home systems - how would you have them protect against Sober in case of the inadvertent "click on this"?

First image shows how SoberQ installs.

»rsjones.net/img/soberQ_1.gif

Second image shows one way of preventing installation.

»rsjones.net/img/soberQ_3.gif
Forums » Up and Running » Security » SecurityMy machine »
« Cisco Switch and Nat  


Saturday, 28-Nov 19:27:26 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [122] Time Warner Cable Fires Broadside At Broadcasters
· [112] New AT&T Ad Campaign Hits Back At Verizon
· [96] Apple Joins AT&T Verizon Snark Fest
· [87] New Bill Takes Aim At Higher Verizon ETFs
· [80] TiVo Sees Record Customer Losses
· [70] Verizon CEO: Hulu Will Be Dead Soon
· [69] In-Flight Internet Headed For Bumpy Landing?
· [66] Weekend Open Thread
· [62] Thanksgiving Open Thread
· [40] EFF Wages War On Fine Print
Most people now reading
· Windows 7 boot manager editing questions [Microsoft Help]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Digital Transport Adapter Unboxing Photos [Comcast Cable TV]
· [Newsgroups] Newzleech down? [Filesharing Software]
· how to use the 2nd line with phone hooked to the 1st line? [VOIP Tech Chat]
· [How to] Install Asterisk on an Asus WL-520GU router [VOIP Tech Chat]
· Gizmo5 has added a Google Voice section in its members area. [VOIP Tech Chat]
· [ Classes] Druid tanking: rotation and glyphs [World of Warcraft]
· sysguard2010.com [Security]
· ToC 4th boss - Preliminary Strategy for Twin Valkyr [World of Warcraft]