Welcome | Sign In
CRMBuyer.com
Social Networking

Second Life Target of Self-Replicating Worm

Print Version
E-Mail Article
Reprints
Second Life Target of Self-Replicating Worm

A self-replicating worm dubbed "Grey Goo" forced the shutdown of the virtual community Second Life after the worm's creators claimed to spin rings of gold, duping players who interacted with it into spreading the malware throughout the virtual environment. "The worm dropped into Second Life is a 'Grief Bomb,'" Rob Enderle, principal analyst at the Enderle Group, told TechNewsWorld.


Talk about art imitating life. A self-replicating worm dubbed "Grey Goo" has caused the virtual community Second Life to shut down at least once, according to the site's owners, Linden Life. Within the Second Life virtual environment, Grey Goo's creators claimed to spin gold rings, and unwitting players interacted with them to spread the malware further.

"This was basically a proof-of-concept worm that only self-replicated using the scripting features inside Second Life," explained Stefan Savage, a professor of Computer Science and Engineering at UC San Diego and a computer security/worm/virus expert. "They have filters that try to prevent this kind of self-replication, but evidently the author found a hole in them," he told TechNewsWorld.

A 'Grief Bomb'

Given that it only affected Second Life users' game time, it was not as destructive as some worms have been. Also, Grey Goo does not appear to have been financially motivated -- that is, it didn't try to phish or otherwise steal personal financial data from users. Nonetheless, players were rattled by the interruption -- which was likely the whole point, says Rob Enderle, principal analyst at the Enderle Group.

"The worm dropped into Second Life is a 'Grief Bomb.' This kind of an attack's sole purpose is to mess up the game" and get those that play and maintain it upset, Enderle told TechNewsWorld.

Targeting Web 2.0

Even though it was a relatively benign occurrence as worms go, Grey Goo is worth noting, as it may be only the first of this type of malware to come, warned Roger Thompson, CTO of anti-exploit software vendor Exploit Prevention Labs. "Increasingly, as we move [toward] Web 2.0, [and] with applications like MySpace or YouTube becoming commonplace, I think we will see more worms targeting these communities," he told TechNewsWorld.

Until the next YouTube or MySpace becomes apparent, however, virus writers are likely to focus on virtual communities like Second Life. If the real world is any guide, a proof-of-concept worm is likely to be followed with one that has a genuine payload.

Users of these virtual communities should start taking the necessary precautions if they haven't been already, Randy Abrams, director of Technical Education, ESET, told TechNewsWorld.

The Payload Next Time

"Second Life may be a virtual world, but real dollars are being exchanged. This creates some pretty strong motivations. In the case of Grey Goo, theft doesn't appear to be a motivation. However ... it would have been fairly easy to add a payload if the author had so desired," he said.

The worm's appearance shouldn't have been a surprise, Rob Graham, CEO of Errata Security added, as most popular online games have had similar worm-replication problems.

"One exception is the game 'World of Warcraft,'" he told TechNewsWorld. "It's not because they have smarter programmers, but because its creator had already been burned by replication bugs in its previous game called 'Diablo.'"

Programmers in the gaming industry are still coding in a negligent manner, Graham concluded. "We will continue to see such problems in online games in the coming years."


Print Version E-Mail Article Reprints More by Erika Morphy


More by Erika Morphy

Ballmer Gives Shareholders - and Dell - Cause for Optimism
November 20, 2009
Microsoft CEO Steve Ballmer was all smiles at the company's shareholders meeting, as he touted the early success of Windows 7. Ballmer's cheer may have been contagious; after posting a massive earnings decline for the third quarter, Dell needed some good news to latch onto, and the prospect of broad enterprise adoption of Windows 7 could spur PC sales.
AA.com Sucks the Fun Out of Trip-Planning
November 20, 2009
Using AA.com to book a flight was a painful experience. Densely packed, disorganized information was displayed in an unattractive format. On the plus side, it did seem as though the deals American Airlines advertised were real and not mere bait-and-switch lures. For anyone who wants a travel-planning Web site to inject a little pleasure into the experience, though, I say look elsewhere.
Salesforce.com Pumps Up Volume of Workplace Chatter
November 19, 2009
Salesforce.com has developed a collaboration platform that puts social networking to work. Salesforce Chatter facilitates employee collaboration on projects through Facebook-like profiles, status updates, feeds and groups. The question remains whether employees will be as open to social networking in the workplace as they are in their personal lives.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network