MyDoom downs SCO site

By Jeff Pelline, Special to ZDNet
02 February 2004 09:30 AM
Tags: pelline, mydoom, sco, unix, site, virus, worm, web
The MyDoom computer virus knocked out SCO Group's Web site on Sunday in the U.S., and the company expects the massive denial-of-service attack to continue until February 12.

SCO said an onslaught of data had made its Web site "completely unavailable." The attack began Saturday night in the U.S. and by Sunday morning the software firm's site was completely flooded with requests, Utah-based SCO said.

"This large scale attack, caused by the MyDoom computer virus that is estimated to have infected hundreds of thousands of computers around the world, is now overwhelming the Internet to requests www.sco.com," Jeff Carlon, SCO's director of information technology, said in a statement.

SCO had posted the statement on its Web site. But at 7 a.m. PST the site could not be accessed. SCO spokesman Blake Stowell read the firm's statement from his home in Utah.

While infected PCs were supposed to start inundating the main SCO Web site with data starting at 4:09 pm GMT (8:09 am PST), the site had been nearly inaccessible for a 16-hour period prior to the scheduled start of the attack, according to Internet performance measurement firm Netcraft. The outage could have been due to a large number of infected computers having their clocks set to the wrong time.

SCO confirmed that the site had been deluged with data hours earlier than the official start of the attack. "Internet traffic began building momentum on Saturday evening and by midnight eastern time the SCO Web site was flooded with requests beyond its capacity," the company said in its statement.

The speed and severity of the attack surprised security officials. "This is the biggest single (denial of service) attack ever," Mikko Hypponen, director of antivirus research at F-Secure, wrote in an update on the security company's Web site. "We estimate the total amount of infected computers to be over one million. Of those, only the computers that have been rebooted (or infected) today are actually attacking."

SCO had been targeted for the denial-of-service attack last week. At the time, SCO had said it hoped to keep its Web site running and had contingency plans in place.

In its statement on Sunday, SCO it still "had a series of contingency plans to deal with this problem," but would wait until Monday--at about 5 a.m. PST--to communicate them.

"We didn't expect a lot of business on Super Bowl Sunday," Blake said, explaining the reason to hold off on the contingency plans. The site attracts an estimated hundreds of thousands of users each week, he said. The site is used to communicate information about SCO as well as provide software updates and patches.

SCO has incurred the wrath of the Linux community for its claims that important pieces of the open-source OS are covered by SCO's Unix copyrights. IBM, Novell and other Linux backers strongly dispute the claims.

SCO has offered a US$250,000 bounty for information leading to the arrest and conviction those who are responsible for the virus.

MyDoom is one of the fastest-growing worms ever. The bug raced onto the Internet on Monday, quickly clogging e-mail servers. Some analysts speculate the worm is of Russian origin.

A variant of MyDoom is expected to attack Microsoft's main Web site on Tuesday. Microsoft also has offered a US$250,000 bounty to catch the worm's perpetrator.

The attack aimed at Microsoft by computers infected with the B variant of MyDoom is not expected to have as much effect because that version hasn't spread as widely, said Vincent Weafer, a senior director at computer-security company Symantec.

"Really, we are seeing very little of the B variant," he said.

The original virus, which only attacks the SCO site, is continuing its attempts at spreading, he added. During the height of the epidemic, the company received about 150 submissions of the virus every hour from companies and home users. Now, Symantec is seeing about half that rate of submissions, mainly from home users.

"The virus is not dropping off as fast as we had expected," he said.

Robert Lemos contributed to this report.

Advertisement

Talkback 4 comments

    For the real truth people shou ...Anonymous -- 02/02/04

    For the real truth people should read this:
    http://www.groklaw.net/article.php?story=20040131180221881

    SCO are doing what they do best, spreading FUD.

    http://news.netcraft.com/ has ...Anonymous -- 02/02/04

    http://news.netcraft.com/ has lots of other stories about the SCO web site.

    http://news.netcraft.com/archives/2004/02/01/www2scocom_enjoys_good_response_times.html
    "www2.sco.com enjoys good response times"

    http://news.netcraft.com/archives/2004/02/01/sco_drop_wwwscocom_from_the_dns.html
    "Generally, conditions on the Internet seem very acceptable at the moment, ... This contrasts markedly with forecasts from Anti-virus companies and this morning's press release from SCO which reported the Internet as being overwhelmed."

    http://news.netcraft.com/archives/2004/01/30/wwwscocom_is_a_weapon_of_mass_destruction.html
    "www.sco.com is a weapon of mass destruction"

    It's interesting that SCO & ...Anonymous -- 02/02/04

    It's interesting that SCO & Microsoft are suddenly palling up on soooo many activities!

    Doesn't that raise interesting questions about which arm is up which puppet ;-)

    Should we spread Mydoom? For t ...Anonymous -- 03/02/04

    Should we spread Mydoom?

    For the first time I briefly considered that maybe I should help spread this virus as SCO are running an IT protection racket, and the authorities are not doing anything to stop them. . . . . .

    Are we seeing the beginnings of "IT viral protesting"?

Add your opinion

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Renai LeMay How reliable is IP telephony?
    Have you ever heard a weird kind of hissing, crackling or popping noise when calling someone on an IP telephony line? How rare is the phenomenon these days?
  • Array Forget the NBN, 100Mbps is already here
    Telstra and TransACT will shortly begin offering 100Mbps broadband to many customers. By moving early, the companies have not only raised the bar for Australia's broadband services, but thrown down a challenge to a government that now faces increased pressure to deliver the NBN as promised.
  • Array IT: Govt's cost-cutting bitch
    The government needs to stop looking at IT as a necessary evil or the place to remove costs when the Treasurer comes calling.
  • More blogs »

Tags

Back to top

Featured