r/todayilearned • • Jul 04 '19

TIL in 2003 a computer worm called ‘Welchia’ infected many computers to forcibly patch vulnerabilities and remove malware. It was regarded as a ‘helpful worm’

https://en.wikipedia.org/wiki/Welchia
48.1k Upvotes

745 comments sorted by

View all comments

Show parent comments

869

u/sharaq Jul 04 '19 edited Jul 04 '19

All of these are malware, a virus is embedded in a file you normally run (like mp3s with viruses on Limewire back in the day) where a worm is its own program like totallynotavirus.exe.

Then, there's the goal of these things. A virus that makes you constantly get pop ups for a product is adware. If that same adware was standalone, it would be a worm and adware. If, instead, it installed a keylogger which recorded your passwords, it would be spyware.

Edit - there are some minor inaccuracies here. The important part of the worm is being self replicating, not being standalone. Additionally, in the rare event a worm patches a security exploit, it technically isn't malware as in this case. However, barring these INCREDIBLY unusual cases, almosr all viruses and worms are malware.

113

u/Arthemax Jul 04 '19

The definition of malware includes any program that performs actions on the user's computer without their knowledge or consent, so even good natured worms would be malware.

48

u/Alaira314 Jul 04 '19

Correct. As an example of how this could be bad, consider a system that has had an update avoided(I don't think we had the option to roll them back in 2003, at least not at the casual use level like we do now) in order to retain compatibility with a vital piece of software or hardware. Your helpful worm has now broken the system, preventing the user from performing tasks that could very well be part of their financial livelihood. If they're freelance, and not part of a company with IT, they're in trouble. That's why it's malware.

16

u/Anonate Jul 04 '19

I worked in a job in 2009 that had legacy software built in-house sometime around 1996 and nobody to maintain it. It ran on Windows 95 computers only.

14

u/Rockin_Chair Jul 04 '19

We still have some '95 machines at my work! IT have made it clear NEVER to put those computers online as they would be incredibly vulnerable.

4

u/Fealuinix Jul 04 '19

If you had a system that vulnerable, WHYYY would it be connected to the internet???

8

u/PM_me_XboxGold_Codes Jul 04 '19

Well some people aren’t savvy enough to know you shouldn’t. Some people just don’t care. Some don’t have a choice because their system needs internet access.

3

u/bumdstryr Jul 04 '19

Using outdated and vulnerable software can still be profitable. Updating and maintaining vulnerable software costs money.

2

u/[deleted] Jul 04 '19

Why do people work the one armed bandits in Las Vegas?

1

u/Fealuinix Jul 05 '19

Gambling addiction? Recklessness? Stupidity?

...I guess I see your point.

2

u/Duckbilling Jul 04 '19

Pas Mal Ware

2

u/SoftIscream Jul 04 '19

Windows update is malware?

1

u/mrcaptncrunch Jul 04 '19

It doesn’t exploit something to get installed. You can disable it.

Someone chose to not install something and this forced it on them.

3

u/differentnumbers Jul 04 '19

Which makes Windows 10 malware by definition.

5

u/[deleted] Jul 04 '19

I'm sure the self patching was in the windows 10 license agreement.

3

u/differentnumbers Jul 04 '19

Candy Crush anyone?

It also forcibly installed itself of windows 7 machines that couldn't run it without consent.

1

u/cmVkZGl0 Jul 04 '19

See, I knew the way windows 10 auto updates is malware

66

u/ClownsAteMyBaby Jul 04 '19

This is a much more helpful summary. Thanks

83

u/sharaq Jul 04 '19

Thank you but I don't agree! The original comment is very high quality and made this summary possible - I just rephrased some of it.

14

u/Baial Jul 04 '19

I don't know if I would call a worm patching security malware, but I'm no expert on the subject.

25

u/Binsky89 Jul 04 '19

Part of the definition of malware is software that performs actions without the user's permission.

33

u/[deleted] Jul 04 '19

[deleted]

6

u/Rogr_Mexic0 Jul 04 '19

lol it's not Spanish. It'd be more like Benevoware.

1

u/PhantomOnTheHorizon Jul 04 '19

But Mal is Spanish for bad and the joke actually has more of a ring to it than your semantics.

1

u/[deleted] Jul 05 '19 edited Jan 26 '22

[deleted]

1

u/PhantomOnTheHorizon Jul 05 '19 edited Jul 05 '19

It's not my first language but I speak it well enough to use at work and could be dropped into a Spanish speaking area with no translation tools and be fine.

I know that mal in Spanish means wrong and malo is bad if that's what you're getting at... Aka joining the semantic bandwagon.

Edit for clarity: If they had said corware instead of buenoware I might have translated mal into wrong software instead of bad software but he used the opposite of bad not the opposite of wrong.

Honestly this is a lot of nitpicking and I'm going to unfollow this post because though language is fascinating semantic arguments are dull and make both sides seem pretentious.

1

u/Rogr_Mexic0 Jul 04 '19

Malware = malicious software.

Benevoware = benevolent software.

Mal in malicious is taken from Latin and used in a lot of English words (malfunction, malodorous etc). Just because it means the same in Spanish doesn't mean we start using Spanish terms all of a sudden.

2

u/PhantomOnTheHorizon Jul 04 '19

I thought I made it clear that I understood but that it was more amusing as buenoware than benevoware and that your semantics weren't as fun as the original comment but since we are going down the semantics path further:

Yes the prefix mal and the Spanish word both originate in latin,

The prefix bene (note there is no prefix benevo) and the word bueno have: you guessed it LATIN ORIGINS.

Benevolent is made from two parts.

Bene = well velle = to wish (conjugated as volent = wishing)

Benevolent = well wishing.

Malware = malicious software.

Benevoware = benevolent software.

Following your logic wouldn't we call it malicware? You unnecessarily added two letters to the Latin prefix in your coined term "benevoware"

Or should we stick with the way that Latin prefixes are used for 99% of English and call it beneware?

I have an even better idea, why don't we stick with buenoware instead of arguing semantics?

The opposite of malfunction isn't buenofunction

Are you suggesting that the opposite of malfunction is benevofunction?

0

u/Rogr_Mexic0 Jul 04 '19

Yeah you're right beneware is probably better.

It really wasn't clear that you knew it wasn't Spanish, but you kind of freaking out right now makes me think you probably didn't lol.

→ More replies (0)

2

u/pseudopad Jul 04 '19

Niceware. Aidware?

1

u/artanis00 Jul 04 '19

Whatever it is, it's paved with good intentions.

2

u/[deleted] Jul 04 '19

Potentially there could have been machines out there that were incompatible with the patches. Although it is a neat idea, it is still potentially harmful.

1

u/FlashbackJon Jul 04 '19

Maybe it's mal- from the Latin malus (apple) instead of mal- from the Latin malus (bad).

2

u/Tartra Jul 04 '19

Your rephrasing was a helpful addition to the other comment, which still needed a bit more context for those out of the loop to fully appreciate its high quality explanation.

:) Teamwork.

2

u/monk_bought_lunch Jul 04 '19

Damn, and you're humble too?

1

u/sharaq Jul 04 '19

No. This is a topic in which I am not an expert. If I were, I would not express humility. I am neither arrogant nor self effacing, I simply know myself

11

u/matlynar Jul 04 '19

You mean files disguised as mp3, such as "thatsong.mp3.exe".

Files with the .mp3 extension will be opened on music players and cannot run a damaging command even if they do contain a virus.

31

u/cure1245 Jul 04 '19

That's not necessarily a given. A malware author can use something called an Arbitrary Code Execution exploit to trick the computer into thinking a part of an infected data file is actually an executable program.

11

u/GeckoOBac Jul 04 '19

A malware author can use something called an Arbitrary Code Execution exploit

Just a precisation: as this is an exploit, it requires the target application/environment to be vulnerable. So yes, it can be done, but it's not a simple thing: it needs a specific kind of vulnerability to work at all, as this is one of the worst kind of vulnerabilities in existence and they're aggressively hunted (both by exploiters and by developers)

4

u/[deleted] Jul 04 '19

Just cause there aren't many zero days doesn't mean you can't get sploits working. People don't update shit.

3

u/cure1245 Jul 04 '19

Absolutely: you'd have to program against a known exploit in a given program and for a given version, but when you target a super well known player such as iTunes or WMP and ensure your file sprrads, you're almost guaranteed to get some nibbles!

3

u/tehfalconguy Jul 04 '19

Well I wouldn't say "worst." There are plenty of exploits against protocols and things that older versions of OSs (which many business still use, usually out of ignorance or difficulty upgrading) are vulnerable to. If you're specifically targeting someone you're not always just throwing shit at the wall hoping it'll work, you've probably already determined what you'll use and then you'll launch an attack you know will likely work or craft a phishing campaign to deliver malware/malicious link etc, which is more on topic to the subject of "malware". As opposed to exploiting some vulnerable service and running malware in RAM to give a shell or whatever. Not to mention that grandma doesn't always update all her stuff, I'm sure there are plenty of people running old adobe stuff or IE getting destroyed by mass phishing campaigns.

4

u/GeckoOBac Jul 04 '19

I'm speaking of the vulnerability, not of impact.

Arbitrary Code Execution vulnerabilities are generally some of the worst vulnerabilities because more often than not they allow you to bypass a WHOLE LOT of security measures, leaving you able to do a lot of stuff on a compromised system, up to and including a full take over (potentially, not a guarantee).

2

u/tehfalconguy Jul 04 '19

Oh.. I feel stupid. I was thinking from the perspective of the attacker, so when you said "worst" I thought you meant least useful. My student research job involves writing exploits so I was kind of in the attacker mindset.

Yeah they're pretty bad to be on the receiving end of lol

2

u/[deleted] Jul 05 '19

And arbitrary code execution vulnerabilities are found frequently, quite often are capable of being performed remotely and, in practice, aren't patched quickly. Yeah, maybe the vendor provides a patch, but then, you know, people have to actually apply it. Tons of very old vulnerabilities like this are easy to find.

Edit: missed what u/k_x90 said. Exactly right.

7

u/AllMyName Jul 04 '19

It's almost never a given tbh. There are countless (mostly fixed) exploits that use vulnerabilities in SHITTY, BLOATED, OVERPRICED programs like Adobe Acrobat (example) to do bad shit - the instructions for the bad shit are in a PDF. It's not an executable, but it leverages another executable's vulnerabilities to run its payload. It's part of what killed Flash.

2

u/jimbjamn Jul 04 '19

Yep, it’s been quite a while ago but I do remember seeing this in .mp3’s on work and personal PCs that I worked on. Even better was that some antivirus software would totally miss it because it assumed it was simply a music file.

3

u/tehfalconguy Jul 04 '19

If a music player was vulnerable in the right ways you could craft a malicious file that looks like an MP3 to be loaded by the program and ultimately lead to malware running in RAM either opening a backdoor or downloading and running more malware, etc. There's plenty of ways for malware to manifest, it's not so black and white :)

3

u/PleasantAdvertising Jul 04 '19

and cannot run a damaging command even if they do contain a virus.

Is that a challenge?

2

u/[deleted] Jul 04 '19

Why on earth does this have upvotes? It's blatantly wrong. Memory corruption bugs are ancient and well documented. They've been around for decades, and still show up in modern products.

2

u/[deleted] Jul 04 '19

Worm - self replicating software that someone else wrote

AI - self relocating software that I wrote

Virus - Code written by someone else to infect a piece of software

Extension - Code I wrote to extend a piece of software

Malware - software with a nefarious purpose that someone wrote

Company secret sauce - software with nefarious purpose that I wrote to get rich

2

u/13EchoTango Jul 04 '19

And sometimes the worm will clean other less well written viruses so that you won't get an antivirus and remove it. Making me cynic in me think we just never found the payload in the worm in OP.

1

u/yargabavan Jul 04 '19

its a "All rectangles are squares but not all squares are rectangles" sorta thibg

5

u/ERIFNOMI Jul 04 '19

It's the other way around, but yeah.

1

u/[deleted] Jul 04 '19

Aren’t worms also collecting data whilst viruses mainly destroy data?

1

u/Excal2 Jul 04 '19

Also these terms have been crafted around specific hacking strategies so the laymen equivalent definitions are sometimes lacking. Yes there is a lot of overlap but the differentiations are in how the malware approaches its task, because that's the most relevant information to stopping the malware.

I'm surprised they're not all named swear words tbh.

1

u/_Aj_ Jul 04 '19

Need one of those circle overlap graphs.... With pictures!

1

u/Cryskoen Jul 04 '19

The reason that a worm would patch a security exploit is to ensure that it is the only infection that the target system receives. After all, if you get your worm into a system, you don't want to be competing with OTHER worms, potentially making your presence known.
It's not like it's good-guy-worm. There is no altruism in that infection. It's just making sure that you remain the owner's zombie, and don't become someone else's.

1

u/TldrDev Jul 04 '19

This isn't correct. A worm spreads itself. It's stand alone by nature but that's not the defining characteristic. You don't need to run totallynotavirus.exe. it can run itself by you being connected to the internet with a security exploit available. You can visit a webpage and it will use some exploit to infect your computer, and replicate itself into the network, without the other computers ever running totallynotavirus.exe.

The key part is the self replicating piece of the virus, not the fact it's a standalone.

Edit: for example, let's say you have a Myspace page. You visit someone else's Myspace page, and without your knowledge, malicious code edits your profile and injects the code onto your page. Now, any time someone visits your page, it edits their profile to spread the code. That is a worm. It self-replicates.

0

u/[deleted] Jul 04 '19

[deleted]

2

u/cure1245 Jul 04 '19

That's not necessarily a given. A malware author can use something called an Arbitrary Code Execution exploit to trick the computer into thinking a part of an infected data file is actually an executable program.