On TechRepublic: Why Linux will triumph over Windows
BNET Business Network:
BNET
TechRepublic
ZDNet

By Liam Tung
Posted on ZDNet News: Oct 10, 2007 6:09:00 AM

Spammers are exploiting YouTube's "invite your friends" function to send spam containing a variant of the "Storm worm."

Bradley Anstis, director of product management at security firm Marshal, said that spammers are taking advantage of the YouTube function that lets people invite friends to view videos that they have viewed or posted. The function allows someone to e-mail any address from an account.

The scam on Google's video-sharing site is targeting Xbox owners, urging recipients to collect a prize version of the popular game Halo 3. Anstis said clicking on the link to "winhalo3" leads to a file containing a Storm trojan.

To date, Marshal has tracked around 150,000 of the spam e-mail messages thought to have originated from YouTube accounts.

The e-mail messages are exploiting a vulnerability in the sign-up process, according to Marshal, which reported in August a Trojan designed to generate large numbers of Hotmail and Gmail accounts. A similar vulnerability is being exploited in the case of YouTube, said Anstis, adding that spammers have used intelligent character recognition (ICR) software to circumvent the verification system commonly known as Captcha. The Captcha system, in which a person must read and re-enter a selection of blurred or unevenly spaced letters and numbers into a box before being issued a new account--is used to make it harder for software programs, rather than genuine users, to sign up for services.

"There are ways of subverting those sort of systems," Anstis said. "Service providers need to look at how to prevent that from happening."

The YouTube help center also advises people to exclude the service@youtube.com e-mail address from spam filtering lists--a fact, Anstis, said spammers are likely aware of.

Security vendor Sophos has also reported the YouTube spam problem. Senior technology consultant for the company, Graham Cluley, said this incident differs from the technique commonly associated with the Storm worm, which typically targets PCs for the job of sending spam.

According to Cluley, the YouTube spamming marks a departure for the junk mailers--instead of using botnets to distribute spam, they can use a familiar Web site to pass on messages.

Anstis said this scam could herald the rise of outsourced bot-herding whereby the botnet controller pays a third party to acquire further bots.

"Now, you can rent time on a botnet network and have a tech support department. If I'm spammer, I would just rent time on a botnet which includes tech support from the botnet owner and a massive resource pool with huge amounts of bandwidth. This may be a third business--selling services to the Trojan operators to help expand their networks. For example, if I own a Trojan network, I pay you 20 cents per bot you get me," Anstis noted.

Lynn Tan of ZDNet Asia reported from Singapore.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 30 Talkback(s)
Virii -> viri; definately -> definitely
? (Read the rest)
Posted by: lysdexia Posted on: 11/08/07 You are currently: a Guest | | Terms of Use
Headline needs fixing  Chad_z | 10/10/07
Premise needs fixing  itpro_z | 10/16/07
RE: 'Storm worm' exploits YouTube  elt@... | 10/10/07
RE: 'Storm worm' exploits YouTube  G Brent LeVasseur | 10/10/07
RE: 'Storm worm' exploits YouTube  liveoilfree | 10/10/07
RE: 'Storm worm' exploits YouTube  medmann41@... | 10/10/07
RE: 'Storm worm' exploits YouTube  jrbeaman | 10/10/07
It's not a cover-up...in a sense.  vorris@... | 10/10/07
THE TORRENT  BALTHOR | 10/10/07
You need some kind of medical treatment  gtg781w | 10/10/07
Nice.  handydan918@... | 10/10/07
LMAO  96camaroz28@... | 10/10/07
One word  JT82 | 10/11/07
RE: 'Storm worm' exploits YouTube  A73K | 10/10/07
nice idea  96camaroz28@... | 10/10/07
Re:  RightHandMan | 10/10/07
Software not out of reach.  hisfool@... | 10/10/07
Arrest em or counter virus them  golowenow | 10/10/07
try to understand the problem  i8thecat | 10/11/07
Storm Worm  rgharold2@... | 10/15/07
Virii -> viri; definately -> definitely  lysdexia | 11/08/07
make it a Federal crime  Me_too | 10/18/07
Re: botnets  RobertMoore12@... | 10/10/07
Botnets  RobertMoore12@... | 10/10/07
You're funny.  intranetworkster@... | 10/10/07
RE: 'Storm worm' exploits YouTube  vorris@... | 10/10/07
shut down YouTube  vilppuu@... | 10/10/07
just change the captcha  penile@... | 10/11/07
'Storm worm' exploits YouTube  DirtyJokerE@... | 10/11/07
RE: 'Storm worm' exploits YouTube  tracy anne | 11/08/07

What do you think?

advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

advertisement
Click Here