<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel> 

	<title>Comments on: Comments on 16779</title>
	<link>http://www.metafilter.com/16779//</link>
	<description>Comments on MetaFilter post Comments on 16779</description>
	<pubDate>Tue, 30 Apr 2002 19:03:48 -0800</pubDate>
	<lastBuildDate>Tue, 30 Apr 2002 19:03:48 -0800</lastBuildDate>
	<language>en-us</language>
	<docs>http://blogs.law.harvard.edu/tech/rss</docs>
	<ttl>60</ttl>

	<item>
		<title>Post number 16779</title>
		<link>http://www.metafilter.com/16779/</link>	
		<description>&lt;a href="http://www.flavoredthunder.com/vcards/pubmail.phtml"&gt;VCards&lt;/a&gt; are sort of a viral(or maybe voyeuristic) greeting card. You send one to someone, and they are sent your note with some attachments. The recipient is asked to run one of them(a VB script), that decrypts the other files, which are three images randomly chosen from the hard drive of the person who sent it to them, and so on. Everything is explained up front, and full source is provided at the web page.</description>
		<guid isPermaLink="false">post:www.metafilter.com,2002:site.16779</guid>
		<pubDate>Tue, 30 Apr 2002 18:53:35 -0800</pubDate>
		<dc:creator>Su</dc:creator>		<category>brokenlink</category>
	</item>	<item>
		<title>By: machaus</title>
		<link>http://www.metafilter.com/16779/#268785</link>	
		<description>&lt;i&gt;Step04: Simultaneously, images are being harvested from the user&apos;s hard drive and mailed to the people in that user&apos;s address book. &lt;/i&gt;

note to self:  disconnect drive mapping to porn before launching attachment... 

I&apos;d love to see one without using it (as if I could on a Mac.)  I imagine that the images it usually gathers are probably pretty damn boring bits and pieces of application help files and other &quot;clip art.&quot;  Anyone who knows VB that can tell how intelligent the script is?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2002:site.16779-268785</guid>
		<pubDate>Tue, 30 Apr 2002 19:03:48 -0800</pubDate>
		<dc:creator>machaus</dc:creator>
	</item>	<item>
		<title>By: swell</title>
		<link>http://www.metafilter.com/16779/#268798</link>	
		<description>A worm that works on the honor system. Super. Won&apos;t take long at all for somebody to add a slightly more destructive payload to this, and disguise it as this.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2002:site.16779-268798</guid>
		<pubDate>Tue, 30 Apr 2002 19:27:16 -0800</pubDate>
		<dc:creator>swell</dc:creator>
	</item>	<item>
		<title>By: chipr</title>
		<link>http://www.metafilter.com/16779/#268803</link>	
		<description>Right now, Internet users are suffering a massive attack by the &lt;a href=&quot;http://www.wired.com/news/print/0,1294,52055,00.html&quot;&gt;klez worm&lt;/a&gt;.  We are trying to train people &lt;i&gt;not&lt;/i&gt; to launch attachments--even from people they know.  Then these twits come along and encourage people to transmit and execute strange script content by email.  This is not simply moronic.  It is evil.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2002:site.16779-268803</guid>
		<pubDate>Tue, 30 Apr 2002 19:32:50 -0800</pubDate>
		<dc:creator>chipr</dc:creator>
	</item>	<item>
		<title>By: Su</title>
		<link>http://www.metafilter.com/16779/#268807</link>	
		<description>Can&apos;t believe I forgot to post the actual message. Here goes:

Click the &quot; vcards.vbs &quot; attachment to view your card! One of your friends is giving you a voyeuristic glimpse of their personal images.
The images were randomly chosen and are totally uncensored! There is no telling what you will see!

Click the &quot; vcards.vbs &quot; file attachment to see the uncensored images, and send your own images out to the people in your address book!

+ + + + + + + + + + + + + + + + + + + + + + + +
Message from your friend:
***MESSGE GOES HERE***
+ + + + + + + + + + + + + + + + + + + + + + + +

If you are not interested? Just delete this email. VCards, Lets get with hot communications


Swell &amp;amp; Chipr: What&apos;s your point? There are plenty of viruses out there that require the person to run a script. It&apos;s usually achieved through deception. So it becomes a question of how much you trust you computer and/or your friends, no? Still no different.
If you&apos;re that paranoid, then don&apos;t run it. E-mail the person first and ask if they really sent the thing.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2002:site.16779-268807</guid>
		<pubDate>Tue, 30 Apr 2002 19:34:50 -0800</pubDate>
		<dc:creator>Su</dc:creator>
	</item>	<item>
		<title>By: Su</title>
		<link>http://www.metafilter.com/16779/#268809</link>	
		<description>Also, the honor system worm idea has already been done, though I&apos;m having a hell of a time finding the thing. It was created by someone who decided to play with the idea of computer security. When the thing infected your system, it would ask permission to encrypt the files on your hard drive, and actually did a pretty good job of it. If you refused, it wouldn&apos;t. Simple.
Anybody else heard of this, and know where it is? It&apos;s most likely that I saw it at Slashdot.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2002:site.16779-268809</guid>
		<pubDate>Tue, 30 Apr 2002 19:40:35 -0800</pubDate>
		<dc:creator>Su</dc:creator>
	</item>	<item>
		<title>By: swell</title>
		<link>http://www.metafilter.com/16779/#268815</link>	
		<description>More info from &lt;a href=&quot;http://www.antivirus.com/pc-cillin/vinfo/virusencyclo/default5.asp?VName=VBS_YURIS.A&quot;&gt;antivirus.com.&lt;/a&gt; My VBS knowledge is somewhat limited, but I do see where they create the directory described in the solution.

The problem, IMO, is that the person who first sends it aims it at a particular friend,  who is either a) clued in enough never to run a VBS attachment, or b) trusts it because it came from a friend, and seems like harmless fun. Admittedly, this is a bit unique in that it admits up front that it&apos;s sending to random files to &lt;i&gt;everyone&lt;/i&gt; in that victim&apos;s address book. This is &lt;i&gt;not&lt;/i&gt; harmless at all. Also, worms mutate as they land in the hands of someone more malicious than the original author. A couple lines of changes and ... something bad starts happening. Chipr&apos;s right, this is evil.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2002:site.16779-268815</guid>
		<pubDate>Tue, 30 Apr 2002 19:56:05 -0800</pubDate>
		<dc:creator>swell</dc:creator>
	</item>	<item>
		<title>By: skallas</title>
		<link>http://www.metafilter.com/16779/#268828</link>	
		<description>&lt;i&gt;When the thing infected your system, it would ask permission to encrypt the files on your hard drive, and actually did a pretty good job of it. &lt;/i&gt;

You&apos;re thinking of the KOH virus.  You can get some info on it &lt;a href=&quot;http://www.avp.ch/avpve/entry/entry2.htm&quot;&gt;here.&lt;/a&gt; I wanted to play with it a long time ago, but the only place I could find it was on some software site for ten bucks.  Not only is it friendly its for sale.  Go figure.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2002:site.16779-268828</guid>
		<pubDate>Tue, 30 Apr 2002 20:40:58 -0800</pubDate>
		<dc:creator>skallas</dc:creator>
	</item>	<item>
		<title>By: plemeljr</title>
		<link>http://www.metafilter.com/16779/#268830</link>	
		<description>Maybe this is like the lottery, an idiot tax.
But seriously, I spend about 2-3 hours of my day explaining things to my peers, installing / uninstalling / guiding friends who did things to their system that confounds me.  Then someone thinks that it would be cute to do this and then releases it in the wild?  Yeah thanks, I&apos;ll pass.  It is hard enough to deal with the malware and KaZaA instals.

&lt; / rant&gt;
&lt;/&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2002:site.16779-268830</guid>
		<pubDate>Tue, 30 Apr 2002 20:45:57 -0800</pubDate>
		<dc:creator>plemeljr</dc:creator>
	</item>	<item>
		<title>By: malevolent</title>
		<link>http://www.metafilter.com/16779/#268888</link>	
		<description>&lt;i&gt;So it becomes a question of how much you trust you computer and/or your friends, no?&lt;/i&gt;
No, it becomes a question of how much you trust the author of the .vbs file. It&apos;s a clever idea, but I still won&apos;t be running any emailed vbs/exe files or Office docs with macros (setting Outlook/Outlook Express to use the Restricted zone and making sure that zone if locked down is also a good idea to stop scripting in emails).
That&apos;s not paranoia, it&apos;s common sense.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2002:site.16779-268888</guid>
		<pubDate>Tue, 30 Apr 2002 23:33:49 -0800</pubDate>
		<dc:creator>malevolent</dc:creator>
	</item>	<item>
		<title>By: Su</title>
		<link>http://www.metafilter.com/16779/#269636</link>	
		<description>The VCard program has been added to McAfee&apos;s &lt;a href=&quot;http://vil.nai.com/vil/content/v_99463.htm&quot;&gt;virus DAT file&lt;/a&gt;.

*giggle*</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2002:site.16779-269636</guid>
		<pubDate>Thu, 02 May 2002 03:11:22 -0800</pubDate>
		<dc:creator>Su</dc:creator>
	</item>
	</channel>
</rss>
