CRYPT NEWSLETTER 54
April 1999

Editor: George Smith, Ph.D.
INTERNET: 70743.1711@compuserve.com
          crypt@sun.soci.niu.edu
http://www.soci.niu.edu/~crypt

Mail to:
Crypt Newsletter
1635 Wagner St.
Pasadena, CA 91106
ph: 626-568-1748

Crypt Newsletter articles may not be copied or reproduced in or
on other media, on CD-ROM collections of data, or offered - in part
or in toto - as part of any database, data survey, information or
research service without prior consent of the editor. Rates based
on word count are reasonable. Queries by e-mail are welcome.


                                       
  Contents: Crypt Newsletter #54       
                                       

 THIS ISSUE

NEWS

MELISSA VIRUS SPREADS BUT HYPERBOLE SPREADS FASTER

CATCH THE GUY?  MAYBE, MAYBE NOT

SOME CHEAP -- FREE -- MACRO VIRUS INHIBITION

CYBER-WARRIORS ARE A DIME-A-DOZEN WHEN REPORTERS ARE NEAR:
SERBIAN HACKERS ANNOUNCE ACTION AGAINST NATO VIA PRESS
CONFERENCE
===============================================



Time for a computer virus convulsion. The media panicked over the
Melissa computer virus this weekend. A local TV news station in
southern California, right near Crypt News central, attested that
millions were said to be infected.

"The story of the Melissa virus is the virus," quipped one Crypt
Newsletter reader. "It's spread faster than the actual thing. Of 
course, no one I know has seen it," he added from the redoubt of 
a large heterogeneous corporate network.  Others begged to differ.

Ziff-Davis news network reporters, in their zeal to proclaim
the sky falling on Melissa, used URLs to link their readers to
Web pages offering working computer viruses, including Melissa,
for download.  With friends like these, who needs enemies?
"Wankers!" was a more succinct epithet heard from Australian
anti-virus expert Rod Fewster. Fewster chastised some of his
colleagues in the industry for calling Melissa "the Big One."
The sky wasn't falling, but it had dropped a couple feet, he
remarked wryly. Fewster added that future developments might
be worse.

Reports drifted into Crypt News central from various readers
and sources.  The majority were silly and bad. Some were, 
relievedly, just silly. One broadcast by ABC News on the 29th 
asserted all computer users could be affected by Melissa.  On 
the 30th, the Los Angeles Times reported Lucent Technologies 
had shuttered its e-mail system after being mailed two copies -- 
that's T-W-O -- of Melissa.

Upon hearing of this, another computer security analyst at
a Fortune 500 company laughed and said rhetorically,  "Someone shut
down their entire e-mail service over two copies?" It was also 
said by the Times that Lockheed Martin had done the same after 
noticing a surge in electronic e-mail, attributing the volume to 
the virus. Crypt News also noticed a surge
in electronic mail just about everywhere on the Internet over
the weekend, but this was more a reflection of people e-mailing
each other in reaction to the news of it, than evidence of the virus
itself. Readers from Lockheed Martin also e-mailed Crypt News.
No viruses were sent.

Also typical of the unusual mania surrounding the
coverage was the Sunday edition of the New York Times.  The
Times treated Melissa like a mysterious black box of unknown
but potentially very menacing property: "Network security 
administrators said they had seen no evidence that Melissa was 
able to open and use the address books in [mail programs other 
than Outlook], but they did not rule out the possibility it could 
and would do so."  It was a bracing dose of phlogiston. By the 
weekend Melissa's naked source code had been distributed widely 
on the Internet.  Fairly simple for experts to understand, it showed
Melissa had no hidden properties. It was aimed specifically at
Outlook's e-mail address book. "Hold on to your hats," as Rob 
Rosenberger of Virus Myths would say.

By Tuesday March 30th, the media hype cycle was complete.  Crypt 
Newsletter and his signficant other's mothers telephoned Pasadena 
to inquire of Melissa.  Even though neither use nor possess
computers, the media outburst had been successful in bullying them
into a non-specific angst. 

So, when it has been decided that the world has ended, please
e-mail Crypt Newsletter.

Additionally, a longer summary of the newsmedia reaction to Melissa 
and some words on macro virus prevention, straight from the piquant 
Dave Spalding at the Korova Milk Bar. Time for a bit of the 
ultra-violence, mate?

http://korova.com/virus/hoax990329.htm

Short term predictions on the impact of Melissa: (1) An immediate
Congressional hearing in which all and sundry bloviate on the need to
find and incarcerate virus authors as well as craft more legislation 
to criminalize them; (2) an immediate call by all and sundry Pentagon
leaders, domestic terror experts, lawmen, and Alvin Toffler-loving
info-warriors to increase spending for cyberdefense because Melissa
was [choose your cliche]: "a wake-up call," "the tip of the iceberg,"
"the start of electronic Pearl Harbor," "a demonstration of what
electronic Pearl Harbor might look like," etc.; and (3) no noticeable
effect on Internet use or the U.S. gross national product. Hey, the
Dow Jones went through 10,000 this week.


CATCH THE GUY?  MAYBE, MAYBE NOT

Regardless of the impact of Melissa, the media furor surrounding
it ensures that it is a very bad time to be associated
with virus-writers.  Simply, in such an environment, everyone
even loosely connected with them becomes a suspect.

Therefore, running a virus site on the World Wide Web becomes
a real liability, depending upon the interest and determination of
Federal and international lawmen interested in the event.

Ziff-Davis News Network, in its efforts to hype the story,
linked to a number of virus exchange Web sites and ran stories
suggesting that an ID number embedded in one of the original
files seeded with Melissa would lead to the perpetrator.

Not so fast, says astute Crypt Newsletter reader Nic Brown
of Strasbourg, France.

"There's a lot of hype on the Internet how some intergalactic 
superheroes have tracked down the author of Melissa from his
GUID in the [original infected] Word document.  This is apparently 
going to lead us to his machine.  Well, dream on . . ."

While the discussion is somewhat technical, it is right on the
money. It involves spoofing or counterfeiting the ID our supersleuths
are looking for and while it appears to be in Greek to the 
unitiated it is easily applied by anyone with a modicum of knowledge
on computer dirty tricks.

Here 'tis:

The [Internet] address which is placed in [this fingerprint] GUID, is 
not obtained directly from the network card's hardware.  It is 
obtained from the [software] driver.  And on Windows NT,
at least, and I imagine on Windows 95/98, you can change this.  On NT 
it's at -- example for an N100 Ethernet card like I have in my Compaq
PC -- HKLM\System\CCS\Services\N1001\Parameters .

"Add a string named 'NetworkAddress' containing 12 hex digits and 
away you go.  

"Of course, this is hugely powerful [in the hands of the mischievous].  
I get my colleague's NIC address 
with ping and arp.  Then I disconnect my PC from the network (to avoid
conflicts), change my NIC address, create my Word document saying 
'the boss sucks,' and leave the document lying around . . .

"When the network administrator is called in to help in the 
witch-hunt, he'll find a smoking gun leading to my colleague's PC . . . 
in the office which he keeps locked at all times . . ."

In reality, there are much easier ways to roughly track the movements 
of virus authors on the Internet.

As a rule, virus writers -- the ones who consider themselves
big deals, anyway -- are fairly obvious.  They hang out on 
Internet Relay Chat, often brag to anti-virus software developers,
and put together efforts to mount Websites that chronicle their
work and creations.

And code styles in viruses are often similar to viruses created
by the same author.  While this is not readily apparent to those
not in the field, it is a feature of note to computer security workers
who analyze computer viruses for a living.

The simplest way to track the creator of Melissa is to query
anti-virus experts.  Invariably, they will point to a particular
author, like the writer of Class virus, for instance, 
a fellow by the name of VicodinES, or any well known virus Website that 
caters to such and their fans. [In December of 1998, Class 
overran the House of Representatives' PC network.  USA Today ran
a story on it but few seemed to really care. Now the FBI cares. Go
figure.]

Sticking out like a sore thumb, VicodinES or someone running a page
in tribute to him linked to news stories about infections attributed 
to his viruses, making him one of the more obvious characters
in the underground menagerie. [Remember what I said about it being
a hot time to be a virus-writer? By Tuesday VicodinES and his 
"colleagues'" Websites -- Source of Kaos -- located on a small ISP in 
Orlando, Florida, had been yanked from the Net. VicodinES had linked
to Crypt Newsletter's story on his Class virus and downloads for the
story on www.soci.niu.edu went through the roof at the beginning of
the week as gawkers hurried to his Website due to the media 
attention.]

But that's the easy part.

The hard part is determining beyond a shadow of a doubt that
you have the right man.

This is far from trivial.  Viruses are easy to diddle and are diddled
by many. What was written by one may have been modified slightly
or radically by another before hitting the wild. And it would help
if you could determine who actually put the virus into active 
circulation, not who passed it out to the like-minded or stuck it on 
a tasteless Website. For example, since VicodinES' site has been
up for some time, it has been elementary for potentially thousands
of the like-minded to download documents and live viruses from it.

Virus toolkits, written by one author, can be used 
by others to create viruses put into the wild, too.  The variables, of 
which these are only a few, can get pretty hairy.

Ultimately, it all comes down to good police work by experts
who know a great deal about the subject, not novices.

An expert, for example, may be able to establish a case for
authorship and intent to distribute a computer virus by thorough 
forensic analysis of virus code, recovered programming samples of 
viruses, and related material found on a seized computer after a 
suspect has been reasonably identified by good old-fashioned police 
work.  Such was the case with Chris Pile, a convicted English virus 
writer who served 18 months for his part in causing infections by his 
SMEG virus in 1994.


CHEAP -- FREE -- MACRO VIRUS PROTECTION

Annoyed by infections on his network by VicodinES' Class virus in 
December of this year, Crypt Newsletter reader Nic Brown started
working on a simple program to take away Microsoft Word's 
ability to act as a conduit for many macro viruses.

The result was ATLAS-T, a program written in C that can be applied
to two files critical to Microsoft's Visual Basic interpretation,
WWINT32.DLL and VBE.DLL.  ATLAS-T patches these files, effacing
the names of a number of macro function normally used by macro
viruses.  The names of the functions can also be changed to 
custom designations by the one employing the program 
should he/she so desire. This does not always preserve 
the functionality of the altered macro but it's a small loss
from a practical standpoint.

It will not protect against all macro viruses -- no anti-virus 
software can do that -- but it worked brilliantly against Class 
and is effective against many, many generic Word macro viruses
and goes along way toward correcting the criminally brain-dead
computer security model Microsoft implements in Word.

However, since it alters WWINT32.DLL and VBE.DLL it can stick in
the craw of hidebound American corporate managers.  The standard
comment would be: "No, because if we change WWINT32.DLL we void
our Microsoft Word support."

But 100 percent of nothing is still nothing.  Crypt Newsletter
leaves the reader to wrestle with this logic: You
can give all macro viruses free reign and have no Microsoft
support, or do something that works and still have no Microsoft 
support and the displeasure of your misinformed supervisor.
 
Bang you head on the wall.

Anyway, from Nic Brown's documentation for ATLAS-T:

"ATLAS-T works by simply changing the strings which Word uses to 
identify the various forms of auto-execute macros ("Auto-macros") 
which it allows.  In Word 95 and Word 97, these are
  AutoOpen
  AutoClose
  AutoExec
  AutoNew
  AutoExit

" . . . ATLAS-T can also prevent VBA macros such as Document_Open from 
running.  This kind of macro is used in the infamous "Melissa" virus.

"You can find the exact functions of all of these macros in the Word 
documentation.  But their main real-world function is to deploy Word 
macro viruses.  If you have applications which depend on any
of these macros, you can tell ATLAS-T to patch out only the ones you 
don't need.

"Why doesn't Microsoft provide this functionality?

"You'll have to ask Microsoft.  How hard would it be to include an 
install-time option to prevent any Auto-macros ever being executed?  
Of course, that would be an admission that Word is the best
virus-writer's toolkit ever produced.  [Microsoft] will try to tell 
you that the virus warning pop-up in Word 97 is adequate protection, 
but dream on guys - a lot of users will click "Enable" because it
sounds so much nicer, more PC even, than "disable".  And that's 
assuming that a virus or Trojan hasn't already disabled the pop-up 
in the registry."

ATLAS-T can be download from:

http://www.geocities.com/NapaValley/Vineyard/1446/atlas-t.html

Crypt Newsletter's Website also makes it available.


CYBER-WARRIORS ARE A DIME-A-DOZEN WHEN REPORTERS ARE NEAR:
SERBIAN HACKERS ANNOUNCE ACTION AGAINST NATO VIA PRESS
CONFERENCE

As long-time readers know, cyberwar is Hell but never so hellish
that it cannot be announced with a grandiose press campaign.

Fresh from the CIA's Foreign Broadcast Information Service, comes
this translation of a March 28 story from the Pale SRNA news source,
datelined Belgrade.

"Serb Hackers Reportedly 'Attacked' US Navy Computer" the   
reporter writes breathlessly, from the original Serbo-Croatian.

"A member of the Serb 'Black Hand' hackers' group at 0330 [0230 gmt] 
yesterday morning 'attacked' a US Navy computer and deleted all data, 
Belgrade `Blic' writes today." 

The hacking group and leader, "Serbian Angel," boasted to the
Belgrade paper that he would begin "daily actions at 0200 [0100 gmt]" 
against military computers in NATO countires.  Or at least until
the bombs cut the power.

The Black Hands claimed they would attack secret military
servers and also alleged that the same had already been withdrawn
from the Net as a precaution against their attacks.  The reader
will note this quite the neat trick: Get your p.r. person to claim
you are attacking a list of secret computers that no one can 
confirm and then confirm that your actions caused the same secret
computers to be withdrawn from the Net.  You don't even have to
fire an electronic shot!

The Black Hands promised they would continue their press 
conferences announcing their victories.

The second part of the Black Hand info-war plan is to carry
lap-tops on the roads to Macedonia and Albania and, presumably,
to offer their services as computer technicians ready for 
employment in NATO command centers, or to launch attacks from
other countries:

"We won't be joking from now on. If one of our members in the 
diaspora manages to infiltrate a NATO computer, he or she will delete 
all the data. We will focus our attacks on the most important bases 
where there are a large number of military computers . . . "

As for attacking secret military computers, the Black Hand 
plan apparently disintegrated early (hackers have notoriously poor
operational discipline), and the Serbian info-warriors chose to 
focus on spamming, to little effect, a public NATO site in Brussells. 
While the purported target has zero military 
value, if the aim was the more modest one of attracting the
media and assorted sucker journalists, it could be considered a 
grand strategic victory.

Previously, Black Hands have been in and out of the CIA FBIS 
database for attacking newspaper Websites in various contentious
sections of Serbia.  With friends like these . . .

Short time prediction: Although the Black Hand won't impact
the NATO sortie rate, the press profile will make it into a 
Congressional hearing or two, set off more stories
in which bureaucrats are heard to utter cliches and bromides
like "potential electronic Pearl Harbor" and "the computer is the 
weapon of the future and the front is everywhere" . . . and become 
source material for a master's degree thesis project by would-be 
info-warriors at the Pentagon's National Defense
University in Washington, D.C. Also look for a brothers-in-arms
movement in which American teenagers, or a collection of similar
from around the world who meet regularly on Internet Relay Chat, 
proclaim solidarity with their "Serbian brethren," shake the 
electronic fist at Uncle Sam, and vow to . . . harass some poor 
slob administrator's Website in the vast domain of 
.gov and .mil.

That the story of Serbian hackers even made it out of obscurity
has more to do with the idiotic, lightweight and avaricious nature 
of the mainstream media machine than any grand plan by mixed up 
teenagers. Only reporters for a dumb, corporate machine like CNN 
(where the story rotated every hour or so on the 31st, a NATO spokesman
said junk mail and viruses in file attachments, presumably inspired
by Melissa, were sent) would think people twiddling computers and 
sending harassing e-mail have the same gravitas as those trekking in 
the mud on the road to Macedonia after losing everything or those 
fixing their truncheons and getting ready 
to exchange hot lead and cold steel with an enemy in the Serbian war.

=================
AND FROM THE MARCH 31 EDITION OF THE WALL STREET JOURNAL:

How'd I Miss Melissa

By George Smith

Run for your lives! Melissa is coming! Cyberspace is being overwhelmed by
this computer virus! Millions are already infected!

OK, I'm exaggerating. But not much more than everyone else. Over the
weekend, Carnegie Mellon University's Computer Emergency Response 
Team, one of the most august groups on the Net, issued an alert about 
Melissa -- a remarkable occurrence, since CERT almost never issues 
alerts on computer viruses.

Yet the last time I looked, my e-mail was still working. So was the 
e-mail of everyone I correspond with. Oh Melissa, why have you 
forsaken us?

What's clear is that the news of Melissa spread a lot faster 
than the virus. In fact, it was much more virus-like than Melissa. 
Both had one thing in common, however. They wasted the time of those 
infected by them.

Aimed at users of the Microsoft Outlook e-mail system, Melissa was 
designed to look in the e-mail address books of Outlook owners and 
mail itself, attached to a surreptitious e-mail, to the first 50 
names it ran across. The eruption of Melissa-instigated messages was 
going to crash corporate e-mail servers world-wide.

It didn't happen. And this is far from the first disaster that hasn't
happened. Computer virus alarms come and go in the media with some
frequency. But other than generating a significant amount of swearing 
and cleanup effort, viruses have had very little effect on the business 
of the nation.

In March 1992 there was Michelangelo. Like Melissa, it was said to 
infect millions. Michelangelo was real, but the numbers were wildly 
exaggerated. On March 6, the day the virus was supposed to do its 
damage, few symptoms of infection were in evidence except for a lot 
of red faces. 

Credit these virus-inspired media explosions to the convulsive 
and haphazard manner in which we hear and deal with problems 
associated with technology.

No one really wants to know that computer viruses are written by
uninteresting teenagers who don't have any special knowledge of 
computers but who do have a desire to make themselves into pests. It 
is far more fascinating and newsworthy to imagine the writer of 
Melissa as a cyber-terrorist of great power and computing genius. 

It does not feed the romance of the story to know that because of the 
publicity, the source code of Melissa -- the computer instructions 
that it consists of--was easier to
find on the Internet than the virus itself. And in the haste to 
cover Melissa, some online news sources actually provided links to 
Web sites that offered computer viruses for download. With friends 
like that, who needs enemies? 

No one really wants to hear that Melissa's fame and the availability 
of its code will almost certainly motivate virus writers to make a 
couple of hundred variations of it in the weeks to come, most of 
which, while destined to go nowhere, necessitate that those who pay 
for antivirus software immediately get updated copies. 

The furor over Melissa once again emphasizes the eternal allure 
of the idea that we live in a high-technology world so fragile 
that a single bullet with everyone's name on it, be it Melissa or 
Y2K, can turn it all into hash in an instant. Not often told is the 
reality that the networked world is astonishingly complex and that 
the complexity is both a nettlesome bane and an accidental boon. In 
such a world, while the illusion can be created that
Melissa strikes at everyone, the reality is that the complexity 
and variety of the technology ensures that for every person set 
upon by something like Melissa, many more will never actually see 
it and more still will not be vulnerable.

In another two weeks most will neither remember nor care about 
Melissa. Unable to stifle the urge to brag, Melissa's author, or 
more likely a supporter, may erect a Web site linking to all the 
online news stories on the matter. If the author is careless about 
it he might get a visit from law enforcement. 

But irrespective of viruses, networks will still crash and now and 
then your computer will issue a cryptic message, reboot unexpectedly 
and lose everything you've been been working on, doubtless at the 
worst possible time. Yet life will go on. You will pick up your 
e-mail in the morning, as usual.

-------------------------------------------------------------
Acknowledgments: Electronic clippings courtesy of David Isenberg
and Steven Aftergood to whom the Crypt Newsletter is mighty obliged.
-------------------------------------------------------------
George Smith, Ph.D., edits the Crypt Newsletter from Pasadena,
CA.

copyright 1999 Crypt Newsletter. All rights reserved.


 
