Tuesday, July 27, 2004 - Posts

The .NET Developer's Guide to Windows Security

A great idea from Keith Brown: exposing his "The .NET Developer's Guide to Windows Security" book as an online collaborative Wiki.

Keith is asking to the community to help him to improve the site... check it!

Curiosity of MyDoom...

Yesterday Google (and seems also other big search engines) was down for a big attack of a new variant of MyDoom virus (MyDoom.O).

The type of attack is always the same: a big number of simultaneous requests directed to the search engine at the same time.

This new variant of MyDoom spreads itself as usually via email and, when it infects a computer, it starts looking for email addresses on the infected computer and also (and this was the yesterday problem) starts a big search on search engines (like Google) for email addresses. Seems that Google has received a lot of query with arguments like these:

"Delivery failed", "Message could not be delivered", "Mail System Error - Returned Mail", "Delivery reports about your e-mail", "Returned mail: see transcript for details", "Returned mail: Data format error instruction", "MAILER-DAEMON", "Mail Administrator", "Automatic Email Delivery Software", "Post Office", "Bounced mail", "Returned mail", "Mail Delivery Subsystem".

You can try by simply do a query with one of the items above (like THIS for example). Can you see how many mail addresses you could obtain?

This is a problem... Search Engines must start thinking a way to obfuscate email addresses (and obviously users must always do it).