Friday, June 22, 2007

worm breakout for Yahoo Messenger (YM)

There is a recent worm breakout for Yahoo Messenger (YM) users. As usual, the worm exploits the link usage in YM. If infected, the worm will send links to your buddy network, other than that, it also takes advantage of the status mode in YM, making a really innocent looking linked status for your friends to click. The interesting part is, the link will direct you to a webpage filled with high value Google Ads, so practically, the hackers (i assuming there are more than one) is trying to make a living out of worms. Another point of interest is that, you can get infected by this worm by visiting certain web build by the hackers, with Internet Explorer, no surprise there

This is how it look like




Tips to avoid getting infected by worm, for this particular situation, are as below:

Use Firefox

Though there are some recently stir about the security vulnerabilities of Firefox, Mozilla made a patch for that in lightning Internet speed. Even better, the updates were sent to the browser when it is activated. I can go on and on telling you all the better security features of Firefox compared to IE (IE 7 is an exception). But you get the idea, don't compromise the safety of your PC, use Firefox. If you don't already have one, get it here : Get Firefox. If you already have and are using Firefox, then hooray for you


Use IM in a Virtual Environment

This is at the moment, my best suggestion. It may require a little extra effort for you to activate the IM in a virtual environment, but i really believe it is better to be safe than sorry. Using IM within a virtual environment decreases your percentage of getting worms like this one into your system ,down to nothing. Any worms that tries to infect your PC will be stuck in the virtual folder. If you would like to learn more about Virtualization, read this : Read Virtualization Article.

Ask

Ask your friend whether the link is legitimate, just make sure it was a human that sent you the link, not a bot. Sounds a bit silly for some people to do this, but there is not harm from asking, there is a lot of harm that follows a worm though, if it infects your PC

You may read the full report of the worm attack here : Read Full Report
You may also refer to Symantec.com for technical detail of the worm variant