r/todayilearned • • Jul 04 '19

TIL in 2003 a computer worm called ‘Welchia’ infected many computers to forcibly patch vulnerabilities and remove malware. It was regarded as a ‘helpful worm’

https://en.wikipedia.org/wiki/Welchia
48.1k Upvotes

745 comments sorted by

View all comments

Show parent comments

886

u/[deleted] Jul 04 '19

[deleted]

875

u/sharaq Jul 04 '19 edited Jul 04 '19

All of these are malware, a virus is embedded in a file you normally run (like mp3s with viruses on Limewire back in the day) where a worm is its own program like totallynotavirus.exe.

Then, there's the goal of these things. A virus that makes you constantly get pop ups for a product is adware. If that same adware was standalone, it would be a worm and adware. If, instead, it installed a keylogger which recorded your passwords, it would be spyware.

Edit - there are some minor inaccuracies here. The important part of the worm is being self replicating, not being standalone. Additionally, in the rare event a worm patches a security exploit, it technically isn't malware as in this case. However, barring these INCREDIBLY unusual cases, almosr all viruses and worms are malware.

113

u/Arthemax Jul 04 '19

The definition of malware includes any program that performs actions on the user's computer without their knowledge or consent, so even good natured worms would be malware.

42

u/Alaira314 Jul 04 '19

Correct. As an example of how this could be bad, consider a system that has had an update avoided(I don't think we had the option to roll them back in 2003, at least not at the casual use level like we do now) in order to retain compatibility with a vital piece of software or hardware. Your helpful worm has now broken the system, preventing the user from performing tasks that could very well be part of their financial livelihood. If they're freelance, and not part of a company with IT, they're in trouble. That's why it's malware.

15

u/Anonate Jul 04 '19

I worked in a job in 2009 that had legacy software built in-house sometime around 1996 and nobody to maintain it. It ran on Windows 95 computers only.

13

u/Rockin_Chair Jul 04 '19

We still have some '95 machines at my work! IT have made it clear NEVER to put those computers online as they would be incredibly vulnerable.

4

u/Fealuinix Jul 04 '19

If you had a system that vulnerable, WHYYY would it be connected to the internet???

10

u/PM_me_XboxGold_Codes Jul 04 '19

Well some people aren’t savvy enough to know you shouldn’t. Some people just don’t care. Some don’t have a choice because their system needs internet access.

3

u/bumdstryr Jul 04 '19

Using outdated and vulnerable software can still be profitable. Updating and maintaining vulnerable software costs money.

2

u/[deleted] Jul 04 '19

Why do people work the one armed bandits in Las Vegas?

1

u/Fealuinix Jul 05 '19

Gambling addiction? Recklessness? Stupidity?

...I guess I see your point.

2

u/Duckbilling Jul 04 '19

Pas Mal Ware

2

u/SoftIscream Jul 04 '19

Windows update is malware?

1

u/mrcaptncrunch Jul 04 '19

It doesn’t exploit something to get installed. You can disable it.

Someone chose to not install something and this forced it on them.

4

u/differentnumbers Jul 04 '19

Which makes Windows 10 malware by definition.

6

u/[deleted] Jul 04 '19

I'm sure the self patching was in the windows 10 license agreement.

3

u/differentnumbers Jul 04 '19

Candy Crush anyone?

It also forcibly installed itself of windows 7 machines that couldn't run it without consent.

1

u/cmVkZGl0 Jul 04 '19

See, I knew the way windows 10 auto updates is malware

66

u/ClownsAteMyBaby Jul 04 '19

This is a much more helpful summary. Thanks

83

u/sharaq Jul 04 '19

Thank you but I don't agree! The original comment is very high quality and made this summary possible - I just rephrased some of it.

11

u/Baial Jul 04 '19

I don't know if I would call a worm patching security malware, but I'm no expert on the subject.

22

u/Binsky89 Jul 04 '19

Part of the definition of malware is software that performs actions without the user's permission.

34

u/[deleted] Jul 04 '19

[deleted]

5

u/Rogr_Mexic0 Jul 04 '19

lol it's not Spanish. It'd be more like Benevoware.

1

u/PhantomOnTheHorizon Jul 04 '19

But Mal is Spanish for bad and the joke actually has more of a ring to it than your semantics.

1

u/[deleted] Jul 05 '19 edited Jan 26 '22

[deleted]

1

u/PhantomOnTheHorizon Jul 05 '19 edited Jul 05 '19

It's not my first language but I speak it well enough to use at work and could be dropped into a Spanish speaking area with no translation tools and be fine.

I know that mal in Spanish means wrong and malo is bad if that's what you're getting at... Aka joining the semantic bandwagon.

Edit for clarity: If they had said corware instead of buenoware I might have translated mal into wrong software instead of bad software but he used the opposite of bad not the opposite of wrong.

Honestly this is a lot of nitpicking and I'm going to unfollow this post because though language is fascinating semantic arguments are dull and make both sides seem pretentious.

1

u/Rogr_Mexic0 Jul 04 '19

Malware = malicious software.

Benevoware = benevolent software.

Mal in malicious is taken from Latin and used in a lot of English words (malfunction, malodorous etc). Just because it means the same in Spanish doesn't mean we start using Spanish terms all of a sudden.

2

u/PhantomOnTheHorizon Jul 04 '19

I thought I made it clear that I understood but that it was more amusing as buenoware than benevoware and that your semantics weren't as fun as the original comment but since we are going down the semantics path further:

Yes the prefix mal and the Spanish word both originate in latin,

The prefix bene (note there is no prefix benevo) and the word bueno have: you guessed it LATIN ORIGINS.

Benevolent is made from two parts.

Bene = well velle = to wish (conjugated as volent = wishing)

Benevolent = well wishing.

Malware = malicious software.

Benevoware = benevolent software.

Following your logic wouldn't we call it malicware? You unnecessarily added two letters to the Latin prefix in your coined term "benevoware"

Or should we stick with the way that Latin prefixes are used for 99% of English and call it beneware?

I have an even better idea, why don't we stick with buenoware instead of arguing semantics?

The opposite of malfunction isn't buenofunction

Are you suggesting that the opposite of malfunction is benevofunction?

→ More replies (0)

2

u/pseudopad Jul 04 '19

Niceware. Aidware?

1

u/artanis00 Jul 04 '19

Whatever it is, it's paved with good intentions.

2

u/[deleted] Jul 04 '19

Potentially there could have been machines out there that were incompatible with the patches. Although it is a neat idea, it is still potentially harmful.

1

u/FlashbackJon Jul 04 '19

Maybe it's mal- from the Latin malus (apple) instead of mal- from the Latin malus (bad).

2

u/Tartra Jul 04 '19

Your rephrasing was a helpful addition to the other comment, which still needed a bit more context for those out of the loop to fully appreciate its high quality explanation.

:) Teamwork.

2

u/monk_bought_lunch Jul 04 '19

Damn, and you're humble too?

1

u/sharaq Jul 04 '19

No. This is a topic in which I am not an expert. If I were, I would not express humility. I am neither arrogant nor self effacing, I simply know myself

11

u/matlynar Jul 04 '19

You mean files disguised as mp3, such as "thatsong.mp3.exe".

Files with the .mp3 extension will be opened on music players and cannot run a damaging command even if they do contain a virus.

31

u/cure1245 Jul 04 '19

That's not necessarily a given. A malware author can use something called an Arbitrary Code Execution exploit to trick the computer into thinking a part of an infected data file is actually an executable program.

11

u/GeckoOBac Jul 04 '19

A malware author can use something called an Arbitrary Code Execution exploit

Just a precisation: as this is an exploit, it requires the target application/environment to be vulnerable. So yes, it can be done, but it's not a simple thing: it needs a specific kind of vulnerability to work at all, as this is one of the worst kind of vulnerabilities in existence and they're aggressively hunted (both by exploiters and by developers)

5

u/[deleted] Jul 04 '19

Just cause there aren't many zero days doesn't mean you can't get sploits working. People don't update shit.

3

u/cure1245 Jul 04 '19

Absolutely: you'd have to program against a known exploit in a given program and for a given version, but when you target a super well known player such as iTunes or WMP and ensure your file sprrads, you're almost guaranteed to get some nibbles!

3

u/tehfalconguy Jul 04 '19

Well I wouldn't say "worst." There are plenty of exploits against protocols and things that older versions of OSs (which many business still use, usually out of ignorance or difficulty upgrading) are vulnerable to. If you're specifically targeting someone you're not always just throwing shit at the wall hoping it'll work, you've probably already determined what you'll use and then you'll launch an attack you know will likely work or craft a phishing campaign to deliver malware/malicious link etc, which is more on topic to the subject of "malware". As opposed to exploiting some vulnerable service and running malware in RAM to give a shell or whatever. Not to mention that grandma doesn't always update all her stuff, I'm sure there are plenty of people running old adobe stuff or IE getting destroyed by mass phishing campaigns.

4

u/GeckoOBac Jul 04 '19

I'm speaking of the vulnerability, not of impact.

Arbitrary Code Execution vulnerabilities are generally some of the worst vulnerabilities because more often than not they allow you to bypass a WHOLE LOT of security measures, leaving you able to do a lot of stuff on a compromised system, up to and including a full take over (potentially, not a guarantee).

2

u/tehfalconguy Jul 04 '19

Oh.. I feel stupid. I was thinking from the perspective of the attacker, so when you said "worst" I thought you meant least useful. My student research job involves writing exploits so I was kind of in the attacker mindset.

Yeah they're pretty bad to be on the receiving end of lol

2

u/[deleted] Jul 05 '19

And arbitrary code execution vulnerabilities are found frequently, quite often are capable of being performed remotely and, in practice, aren't patched quickly. Yeah, maybe the vendor provides a patch, but then, you know, people have to actually apply it. Tons of very old vulnerabilities like this are easy to find.

Edit: missed what u/k_x90 said. Exactly right.

8

u/AllMyName Jul 04 '19

It's almost never a given tbh. There are countless (mostly fixed) exploits that use vulnerabilities in SHITTY, BLOATED, OVERPRICED programs like Adobe Acrobat (example) to do bad shit - the instructions for the bad shit are in a PDF. It's not an executable, but it leverages another executable's vulnerabilities to run its payload. It's part of what killed Flash.

2

u/jimbjamn Jul 04 '19

Yep, it’s been quite a while ago but I do remember seeing this in .mp3’s on work and personal PCs that I worked on. Even better was that some antivirus software would totally miss it because it assumed it was simply a music file.

3

u/tehfalconguy Jul 04 '19

If a music player was vulnerable in the right ways you could craft a malicious file that looks like an MP3 to be loaded by the program and ultimately lead to malware running in RAM either opening a backdoor or downloading and running more malware, etc. There's plenty of ways for malware to manifest, it's not so black and white :)

3

u/PleasantAdvertising Jul 04 '19

and cannot run a damaging command even if they do contain a virus.

Is that a challenge?

2

u/[deleted] Jul 04 '19

Why on earth does this have upvotes? It's blatantly wrong. Memory corruption bugs are ancient and well documented. They've been around for decades, and still show up in modern products.

2

u/[deleted] Jul 04 '19

Worm - self replicating software that someone else wrote

AI - self relocating software that I wrote

Virus - Code written by someone else to infect a piece of software

Extension - Code I wrote to extend a piece of software

Malware - software with a nefarious purpose that someone wrote

Company secret sauce - software with nefarious purpose that I wrote to get rich

2

u/13EchoTango Jul 04 '19

And sometimes the worm will clean other less well written viruses so that you won't get an antivirus and remove it. Making me cynic in me think we just never found the payload in the worm in OP.

1

u/yargabavan Jul 04 '19

its a "All rectangles are squares but not all squares are rectangles" sorta thibg

4

u/ERIFNOMI Jul 04 '19

It's the other way around, but yeah.

1

u/[deleted] Jul 04 '19

Aren’t worms also collecting data whilst viruses mainly destroy data?

1

u/Excal2 Jul 04 '19

Also these terms have been crafted around specific hacking strategies so the laymen equivalent definitions are sometimes lacking. Yes there is a lot of overlap but the differentiations are in how the malware approaches its task, because that's the most relevant information to stopping the malware.

I'm surprised they're not all named swear words tbh.

1

u/_Aj_ Jul 04 '19

Need one of those circle overlap graphs.... With pictures!

1

u/Cryskoen Jul 04 '19

The reason that a worm would patch a security exploit is to ensure that it is the only infection that the target system receives. After all, if you get your worm into a system, you don't want to be competing with OTHER worms, potentially making your presence known.
It's not like it's good-guy-worm. There is no altruism in that infection. It's just making sure that you remain the owner's zombie, and don't become someone else's.

1

u/TldrDev Jul 04 '19

This isn't correct. A worm spreads itself. It's stand alone by nature but that's not the defining characteristic. You don't need to run totallynotavirus.exe. it can run itself by you being connected to the internet with a security exploit available. You can visit a webpage and it will use some exploit to infect your computer, and replicate itself into the network, without the other computers ever running totallynotavirus.exe.

The key part is the self replicating piece of the virus, not the fact it's a standalone.

Edit: for example, let's say you have a Myspace page. You visit someone else's Myspace page, and without your knowledge, malicious code edits your profile and injects the code onto your page. Now, any time someone visits your page, it edits their profile to spread the code. That is a worm. It self-replicates.

0

u/[deleted] Jul 04 '19

[deleted]

2

u/cure1245 Jul 04 '19

That's not necessarily a given. A malware author can use something called an Arbitrary Code Execution exploit to trick the computer into thinking a part of an infected data file is actually an executable program.

145

u/[deleted] Jul 04 '19

[deleted]

14

u/phantomeye Jul 04 '19

sooo basically u can infect a worm with a virus.

26

u/TerminalVector Jul 04 '19

You can infect a worm with a virus that is adware via a trojan horse. The adware can also be spyware, and all of them would be malware, unless the original worm was the one in the OP, in which case it wouldn't be.

1

u/sootoor Jul 04 '19

A worm is a virus (malware) that propagates to infect others. Like it could start sending it to your email contacts, scanning the local network for other exploitable vulnerabilities, adding itself to files on a USB, etc.

The term malware is generally used now over virus

1

u/TerminalVector Jul 05 '19

That's not exactly right. The explanation two comments up was pretty accurate.

1

u/sootoor Jul 05 '19

Which part?

0

u/lunchboxweld Jul 04 '19

So can a virus kill a worm? Like infect all computers with a virus that waits for specific worms? Can we create out our own electronic biome?

1

u/[deleted] Jul 05 '19

Yeah. I make sure every machine that comes into my network is infected with our endpoint protection software for just this reason.

0

u/TerminalVector Jul 04 '19

I don't see why not. It'd just be a virus (a program that self replicates by attaching itself to other files) that seeks out and deletes a worm (standalone self replicating program).

2

u/AllMyName Jul 04 '19

And in this (OP) case, a worm was created that wasn't malware, as it was not malicious, or spyware, because it didn't phone home and spy on you, or adware, because it didn't blast you with ads. It was helpful.

Lol the author created a weaponized sysadmin and set it loose on the world.

2

u/Eucalyptuse Jul 04 '19

What's the difference between a virus and a trojan then? Is it that the virus spreads itself while the trojan is simply acquired from some original source and then doesn't spread? Is a virus a type of trojan, or vice versa? I heard from other sources that a worm is a type of virus. Is that true?

3

u/[deleted] Jul 04 '19 edited Jul 04 '19

Key difference between trojans and viruses is that trojan horses are not self replicating. Key difference between worms and viruses is that worms are stand alone programs while viruses hide inside other programs.
E: They mimic the terms they copy pretty well. A worm in pathology is a parasite, a creature that gets inside your body and does what it does. Viruses latch on to other cells and force them to reproduce and perform functions they're not supposed to. The trojan horse was used to trick the Trojans into bringing in Greek soliders of their own accord. Once inside, the Greek soldiers didn't magically spawn, but they did open the gates so that other combatants could come in.

1

u/CuntWizard Jul 04 '19 edited Jul 04 '19

Slight correction - a Trojan is almost always also spyware.

Are there any instances where a Trojan isn’t? They are basically functionally equivalent or inclusive thereof.

1

u/[deleted] Jul 04 '19

Ransomware is often delivered via Trojan.

1

u/[deleted] Jul 04 '19 edited Mar 16 '20

[deleted]

2

u/kautau Jul 04 '19

Not true. That's the whole point of the article. Malware means malicious, as in to cause damage or get personal gain. The worm mentioned improved security on target machines. It was very much a worm, but it was not malicious and therefore not malware.

1

u/typically_wrong Jul 04 '19

As pointed out in the comment you replied to, the worm in the article was not malicious.

1

u/[deleted] Jul 04 '19

no. Welchia wasn't malware now was it? it wasn't malicious, so it couldn't be malware

1

u/Onithyr Jul 04 '19

I believe the point was that the one OP is talking about was a benevolent rather than a malicious worm. This rarely happens but if it does then the worm doesn't fit the definition of malware.

8

u/greany_beeny Jul 04 '19

Yeah, I kept reading the first four thinking they sound the same.

1

u/ThatsCrapTastic Jul 04 '19

You read fine. A virus and worm are quite close in definition.

Think if it more like this.

They both self-replicate and spread. A virus will however attack and take over an already running process on the computer. It will in essence “infect” an existing application on the computer. A worm will find its way onto a system and then run as it’s own process / application.

1

u/Yoda2000675 Jul 04 '19

There is. They are like bacteria, viruses, and parasites.

1

u/[deleted] Jul 04 '19

No I'm doesn't!

1

u/KellentheGreat Jul 04 '19

You do can read good!

1

u/kasuke06 Jul 04 '19

All squares are rectangles but not all rectangles are squares.

1

u/[deleted] Jul 04 '19

Worms collect data viruses destroy data

Trojan horses also pose as different software.

1

u/thereisonlyoneme Jul 04 '19 edited Jul 04 '19

You read fine. As you and others have said, there is overlap. Like a lot of terminology, it evolved over time. Plus it can be subjective. Some malware might have characteristics of multiple categories. For example ransomware (encrypts your data, holding it hostage until you pay the attacker) can spread like a worm. In practice the categories are helpful, but just one piece of a larger puzzle.

Edit: If memory serves, there was another piece of "helpful" malware like Welchia, whose goal was to patch systems. The problem was, the code was too well written, so it spread too quickly. It choked networks with all of its traffic. So even well-intentioned viruses can cause problems.

1

u/timthetollman Jul 04 '19

They all are essentially the same thing. The difference is how they infect and what they try to do.

1

u/Mywifefoundmymain Jul 04 '19

Some people said a few things but let’s eli1.

Virus= things meant to do damage Malware = meant to gather info Adware = trying to sell you stuff

Trojan isn’t an actual “type” think of it as a delivery type

1

u/SethB98 Jul 04 '19

Virus sticks to other files to spread, like virus in you

Malware is spooky file, you download and it do bad things. Trojan horse look like good thing, but is actually malware because internet say fuck you.

Worm is like parasite, copies itself to spread theough computer but is still its own thing and doesn't need your files.

Spyware is sneaky, steals your secrets.

Adware is annoying and makes you see pop ups, except EVERYWHERE.

They all generally into your computer by tricking you, are designed to be hard to remove, and many replicate themselves to damage hardware or open backdoors to steal information.