April 6, 2004 8:51 AM PDT

Kazaa, eDonkey brace for attack

File-sharing Web sites Kazaa and eDonkey are steeling themselves for a distributed denial-of-service attack expected Wednesday from a clutch of new variants of the NetSky worm.

NetSky.Q, which first appeared last week, is designed to attack various Web sites that distribute either file-sharing clients or hacking and cracking tools. Kazaa and eDonkey are its best-known targets, and the attack is scheduled to last for six days. However, they will get only a short break. NetSky.T, which was discovered Tuesday, is set to launch a new distributed denial-of-service (DDoS) attack on April 14. This attack is scheduled to last for 10 days.

Mikko Hypponen, director of antivirus research at F-Secure, said he expects the targets to fare badly, because they are relatively small companies that will not have the necessary infrastructure to survive a large DDoS attack. "NetSky is widespread, so I wouldn't be surprised if the sites collapse under the load," he said.

Because these versions of NetSky are engineered to attack only Kazaa and eDonkey's main Web sites, their actual file-sharing networks will not be affected. This means that people should be able to continue swapping files without disruption.

Marco Righetti, virus coordinator at Trend Labs, the research arm of antivirus firm Trend Micro, said the NetSky.Q variant may cause the targeted sites some problems but that the NetSky.T is not spreading very fast and does not look like a serious issue at the moment.

However, NetSky contains a "back door" that lets the worm be automatically transformed to a newer variant by the authors, so people who have not removed previous NetSky infections are likely to be "upgraded" to the latest version of NetSky so that their machines can join the attack.

Besides launching DDoS attacks, recent NetSky variants have also stopped trying to remove the Bagle worm from infected machines, which is a behavior exhibited by the previous 16 variants of the worm. This may indicate that a different group of programmers is writing the worm.

Messages hidden inside NetSky.Q claim that the authors do not have any "criminals inspirations," because they do not use the worm to relay spam. They also deny that they are "children" using virus toolkits and say they want to "prevent hacking, sharing of illegal stuff and similar illegal content."

But Trend Micro's Righetti dismissed this moral high ground, saying the NetSky authors are doing more damage than the sites they are attacking may be doing. "Kazaa spreads music, and the other sites spread passwords and key generators for cracking programs. The worm's authors are trying to do something they may think is morally right, but this is actually 10 times worse," he said.

Kevin Hogan, senior manager for Symantec's Security Response division, said the messages contained in NetSky should be ignored, because he suspects that the source code for NetSky is circulating within the hacker underground, such that anyone could be creating the new variants. "It's hard to tell if it is the same group of people that wrote the previous variants. The guys that are writing these worms could be pulling the wool over all our eyes," he said.

Munir Kotadia of ZDNet UK reported from London.

See more CNET content tagged:
Netsky virus, eDonkey, distributed denial of service, variant, worm

Add a Comment (Log in or register) 1 comment
New tactic
by Fray9 April 6, 2004 4:34 PM PDT
From the looks of things Id say someone working for (directly) or an employee of the RIAA found some neat virus source code and thought "Hey since we cant beat them legally lets try this".

A virus author thats against the free availability and distribution of information is a contradiction in terms. There has to be a more significant (and probably more devious) motive involved.
Reply to this comment
Powered by Jive Software
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right
  • News - Business Tech

    Samsung contemplating SanDisk acquisition

    South Korean consumer electronics giant is considering a buyout of the chipmaker to reduce its NAND flash memory costs, according to PaidContent.

  • Gallery

    Photos: Ron Paul's RNC alternative

    As the Republican convention took place just miles away, a crowd rallied for the former presidential candidate and his message of limited government, ensured civil liberties, lower taxes, and peace.

  • The Open Road

    Analysts as a lagging indicator of success

    Gartner, Forrester, and other analyst firms tend to be great predictors of the past, probably because that's where they get their money.

  • Beyond Binary

    Memo: Windows chief on new ads

    Windows business unit head Bill Veghte send a memo to troops late Thursday promising that the debut Seinfeld/Bill Gates ad was just an "icebreaker."

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Digital Media

    About time: Joost to launch browser-based player

    Company's desktop client failed to catch on with the public, so the Web video service is retooling, but is it too late to catch up to Hulu and Google's YouTube?

  • Video

    Political party playlists

    We know the Democrats and Republicans are split over policy issues, but does their musical taste fall down party lines too? And what kind of gadgets did they bring to the conventions to listen to their music? CNET reporter Kara Tsuboi finds out.

  • News - Politics and Law

    Google and 'Vanity Fair' party with the GOP

    Google and Vanity Fair hosted one of the most talked-about parties at the Republican convention.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Photos: The brains behind Google Chrome

    Here's a look at some of the engineers and executives who took the stage at the company's headquarters as they unveiled the new browser.

  • Gadgettes, the blog

    Gadgettes 105: The Sing, Sing a Song Episode

    We have music on the brain in today's episode of Gadgettes. Don't worry, we won't destroy your ear drums with ear-piercing renditions of your least favorite '80s tunes. Instead, we'll soften the blow with a slew of musical gadgets and accessories.

  • Green Tech

    Duke Energy to invest in mini solar power plants

    Can hundreds of rooftop solar panels collectively operate like a central power plant? Duke Energy launches $100 million distributed solar program to find out.