(picture)

August 21, 2003

Sobig power law

Like many of you, I'm inundated by the Sobig.F worm. Yesterday: 570 copies of it in my inbox. But there's a massive disparity: my work email got none (likely because of the company's perimeter scanner), and none of my family received any either, despite their active use of email. (They also never get spam...)

To explain this, I suspect that my 570 SOBIGs came from a small handful of infected DSL- or cable-connected users who have my email in their address book. Which really shows a design flaw in the worm; those most likely to be targeted would also be "most connected", and possibly also the least likely to become accidental vectors in this nasty game. Which is quite different from Slammer or Blaster propagation.

Despite its infrastructural impact, I still don't think Sobig is very scary. The truly bad viruses are those which make your machine a zombie, 0wned. Owned by whom?