Russian Denies Writing SoBig Worm 67
IphtashuPhitz writes "The Russian spamware programmer anonymously accused eariler this week of writing the Sobig worm has responded to the accusations. Ruslan Ibragimov of Send-Safe doesn't deny that his program uses proxies to hide spammer's identities. But he totally refutes the report's technical analysis in an online interview over at OReilly Network."
in Soviet Russia (Score:2, Funny)
I don't buy it (Score:3, Interesting)
Re:I don't buy it (Score:3, Funny)
Man, the Bush ideology spreads so fast?
Re:I don't buy it (Score:1)
Karma be damned... (Score:1)
What have I failed to comprehend? Suggesting lynching someone for having a motive, whether they actually did the deed or not, scares me.
Re:I don't buy it (Score:2, Informative)
0) All of these ideas involve disassembly. http://www.datarescue.com/idabase [datarescue.com]IDA Pro is the best dsassembler on the market; all ideas below are implemented as extensions to it. Nothing even comes close to its sheer strength, except perhaps the underdeveloped, alpha knockoff http://lida.sourceforge.net/ [sourceforge.net]Lida.
1) http://www.datarescue.com/idabase/flirt.htm [datarescue.com]FLIRT signatures work surprisingly
After all this.. (Score:5, Funny)
Re:After all this.. (Score:5, Funny)
As long as we're on the topic of spam and such, I think slashdot has slashdotted itself. The "bush wins" thread is average at least a post every 3 seconds, who knows how many hits, and the server is crawling
Re:After all this.. (Score:2, Interesting)
Re:After all this.. (Score:1)
Remember the rules (Score:5, Insightful)
Spammers lie!
Re:Remember the rules (Score:3, Funny)
Re:Remember the rules (Score:1)
What a stand-up guy... (Score:5, Funny)
The report noted, for example, a strong similarity in the email headers created by Send-Safe and SoBig. But Ibragimov said Send-Safe chose the particular order of headers merely to mimic Outlook Express and to better evade spam filters.
Somehow I think Ibragimov's righteous indignation over the accusation is a teensy bit misplaced...
WTF? (Score:5, Insightful)
Re:WTF? (Score:3, Insightful)
I found the biggest piece of evidence be the opcode similarities. which he doesn't comment at all, conviently.
but would he ADMIT IT? with 250 000$ reward on his head? of course not. but I'd rather have had him refute it totally, by reasoning and not just claiming that it's bullshit(when he even admits himself that his full of bullshit and into selling software for harassing people who try to _not_ get harassed).
No, (Score:1)
I did it!
Re:No, (Score:1)
I did it!*
holy shit! now to collect that 250k $!
Re:WTF? (Score:3)
When said anonymous person's report lists some pretty damning evidence, such as header and code comparisons and analysis, ermm yes.
Proxie Shortage (Score:5, Interesting)
Well, well, well, (Score:3, Interesting)
Re:Well, well, well, (Score:2)
Re:Well, well, well, (Score:1)
For sure he denies. (Score:5, Informative)
The binary comparison in the report shows evidence for a correlation between Send-Safe and Sobig-F which could be proved if Ibragimov would be forced to open the Send-Safe source.
Hmm... (Score:5, Funny)
TOTALLY REFUTES??? !!! (Score:2, Insightful)
Re:TOTALLY REFUTES??? !!! (Score:1)
refutes != rebutts.
If you don't know the difference, do what the story did: use "denies."
Surprise! (Score:5, Funny)
"Totally refutes"??? (Score:4, Interesting)
The only interesting comment I found is that his company is currently having difficulties due to trojans, something that the SendSafe forums seem to confirm. That seems quite probable, but it hardly helps his case - why, exactly, would trojans be causing his SendSafe business any problems? Unless, of course, it might be something to do with other trojans that he didn't write such as NetSky/Sasser preventing SoBig getting as many hosts as it used to? Given that there was a spat between the various trojan authors, complete with a possible Russian connection, just before Sven Jaschen was arrested that at least seems entirely plausible to me.
Re:"Totally refutes"??? (Score:2)
Of course he didn't. (Score:1, Redundant)
Well, he would, wouldn't he... (Score:3, Insightful)
Denied (Score:3, Funny)
Innocent until proven guilty (Score:1)
Re:Innocent until proven guilty (Score:2, Insightful)
Questions of "innocence" and "guilt" do not apply to these species; they don't have a concept for these things.
Hopefully, one day, we will find a way to teach such things to these strange, primitive beings so that they can live beside humans in our struggle against the species that dominates this planet and threatens to wipe us out:
Re:Innocent until proven guilty (Score:2)
Sheesh, some people, no sense of understanding or humor. Apparently politicians mod on Slashdot. Who woulda thunk it?
The evidence... (Score:5, Insightful)
1. Send-Safe and SoBig had same release dates. Where the margin on same is up to 10 days, and there are strange inaccuracies, for example the document states that on 5/23/2003 there was a SoBig release compiled on June 24, 2003. Other evidence hinges on the actions of SSSG without considering the possibilities that they were using a hacked version of Send-Safe.
2. Document contains unfounded statements like "As SSSG appears to be a sizable organization, it would seem unlikely that any individual within the group would actually know the Sobig author(s)."
3. The skills section is particularly funny since it lists skills like "Newsgroups" and states the the Russian has been posting on Newsgroups since 1998. Woo hoo!
4. The use of %s section made me want to LOL. The authors see significance in the fact that neither piece of software uses %s to concatenate strings, would be unusual for any C programmer, yet looks like something any C programmer would do.
5. The note on string ordering with an example of SoBig vs Send Safe appears to me to show the opposite of what the authors intended. The two blocks look very different.
6. A large part of the document is dedicated to showing how the two exectuables are "similar" at the opcode level. There is no actual evidence here, e.g. how about a disassembly of two identical blocks of code? The comparison is interesting, but doesn't tell us much without being able to see the actual code.
Overall I though the PDF file was poorly written, lacking in rigor and provided no real evidence for the naming of this individual.
Yes, he helps people spam, and that's very, very annoying, but "innocent until proven guilty" people? Or at least "innocent until you actually show some convincing evidence".
John.
Well of COURSE he didn't write it. (Score:3, Funny)
IT wrote HIM.
Get your facts straight.
Hasn't anyone else caught this obvious lie? (Score:2, Interesting)
Here's the quote from the "Who wrote sobig" article:
Least comment story ever? (Score:2)
If I didn't know any better, I'd think that there was something else on most people's minds!
Have you read it?.. (Score:1)