[88321] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

CME-24 (BlackWorm) Users' FAQ

daemon@ATHENA.MIT.EDU (Gadi Evron)
Mon Jan 30 15:02:43 2006

Date: Mon, 30 Jan 2006 22:00:58 +0200
From: Gadi Evron <ge@linuxbox.org>
To: nanog list <nanog@merit.edu>
Errors-To: owner-nanog@merit.edu


This FAQ was authored by members of the TISF BlackWorm task force 
(specifically the MWP / DA groups and the SANS ISC handlers).

The purpose is both to provide with a resource for concerned users and 
network administrators, as well as to be a level-headed myth-free source 
on the subject.

There seems to be excessive media hype as well as some 
"end-of-the-world" type predictions. The end of the world is not coming 
and most of us will still be here after February 3rd, but this is a 
serious issue for those who *are* infected and we didn't manage to get to.

The FAQ can be found at:
http://isc.sans.org/blackworm
http://blogs.securiteam.org

--

"300,000 infected users worldwide is not a terribly large amount when 
compared to previous worms like Sober or Mydoom. However, with this worm 
it isn't the quantity of infected users, it is the destructive payload 
which is most concerning."
-- Joe Stewart, LURHQ (http://www.lurhq.com/blackworm-stats.html)

	Gadi.

home help back first fref pref prev next nref lref last post