DHAHRAN, 5 August — Public relations firms and newspapers have a symbiotic relationship. PR firms provide newspapers with stories and newspapers provide the agencies with space. It’s usually a beneficial, positive relationship, but lately it’s gotten ugly. Certain PR companies in the Middle East market have begun to give newspapers a little something they don’t need — computer viruses.
It started last year. GHK sent out from its Dubai office the infamous “love bug,” about a month after the virus first struck. Such an attachment demonstrated that this PR firm either hadn’t upgraded its anti-virus program or didn’t have one at all. When Arab News inquired as to why they were sending out such nasties, GHK Dubai stated that it had come from their London office and had infected their entire network. This was actually worse news than what we’d already been imagining. So from then on many journalists in our group were very careful about opening their attachments.
In the spring of this year, once again GHK struck. Their Saudi office sent out a virus to everyone in their address book. They did better this time. Within an hour, they had frantically sent out a second message advising people not to open the first; still not perfect, but progress of a sort. It’s at least polite to apologize for a dastardly deed.
Despite all the recent publicity on the importance of network security, some PR firms are still clueless. Last Saturday, the PR firm SACCS sent out the SirCam worm — more than a week after the malicious code was first discovered. On Sunday morning when my anti-virus program detected the worm in their e-mail I rang SACCS to ask why they hadn’t sent out a follow up advisory about their unfortunate “accident.”
Their response was that they had just found out that they had sent out the worm and their entire network was down. They didn’t have a clean backup copy of their address book or a computer outside the network to use for such a notification. When I inquired if they had considered using the telephone or the fax for notification they replied that such an exercise would be prohibitively expensive.
Four days later, I spoke with another journalist who’d received one of SACCS’ nasties and he was furious. He’d opened the attachment and messed up his machine. The journalist agreed that he’d been at fault for not updating his virus scanner but he was very angry that SACCS hadn’t sent out any sort of advisory or apology. He promised that in the future he’d simply delete their mails without reading them; so much for public relations.
SACCS is not alone in their negligence. SirCam is still spreading nicely throughout the Middle East mostly through private PCs. I’ve received the worm several times now from individuals and I’m less than pleased with the experience — although it has given me frequent reassurance that my anti-virus software is working consistently. Like other malicious codes the SirCam worm spreads by e-mailing copies of itself to everyone in the infected computer’s Windows address book. It also sends itself to any e-mail addresses contained in the web browser’s cache files, which store recently viewed pages. An amusing twist for the recipient is that the worm sends a randomly chosen file from the My Documents folder. The e-mail subject line matches the name of the file being sent.
In SACCS case, reports are that SirCam sent out a file containing labels. The PR firm was very lucky. The worm could have grabbed a letter, price list or some other file containing embarrassing and/or confidential information about them or their clients.
In addition to the security breaches from the release of confidential documents and the amount of e-mail generated, SirCam creates another problem that won’t be obvious for a while. If the worm infects a PC that uses the European date format (day/month/year), like many PCs in the Middle East do, there is a 1-in-20 chance that the worm will delete all files and folders on the hard drive on Oct. 16.
While viruses and worms are unpleasant, at least when I get sent one I don’t feel like I’ve been targeted. But hack attacks are something else. The number of hackers out on the Saudi network these days is simply astonishing. I have a firewall installed on my machine and it is picking up numbers like 15 attempts at intrusion in one hour. I at least know that the hackers are out there and I’m doing my best to keep them out of my machine but most every other computer user I’ve polled on the subject is unaware of how bad the problem has become.
Looking over my firewall’s log, I discerned that the majority of intrusion attempts are taking place from IP addresses within the Saudi network — not from outside. Perhaps there are so many attacks because millions of teenagers are sitting at home this summer with nothing better to do than cause mayhem. Hacking software is readily available over the Net and there is no penalty for such behavior.
According to Dr. Eyas Al-Hajery, head, Information Security Center, Internet Services Unit, King Abdul Aziz City for Science and Technology, laws were drafted six months ago concerning illegal activities on the Internet but as of yet those laws have not been approved by the higher authorities. So even if a hacker causes destruction and is caught, there is little that can be done to him outside of cutting off his Internet connection.
“Individuals and companies must be responsible for their own security,” said Al-Hajery. “Legislation is never going to be the primary method to prevent hacking.”
Al-Hajery emphasized that network managers and individuals must ensure that their ports are blocked and firewalls are up. They should install firewalls and anti-virus software, subscribe to alert lists and upgrade immediately when they receive an alert. Al-Hajery said that firewalls and anti-virus software should be in place before connecting a new machine to the Internet or an e-mail system. To have the tightest security on PCs that have been connected to the Internet or that have received e-mail without security programs in place, it is necessary to reformat the hard drive and then reinstall the operating system behind a firewall. This would ensure that all Trojans that might have been inserted previously in the computer are eliminated.
Al-Hajery mentioned that in the spring, KACST agreed to special arrangements with three major anti-virus software companies to make the anti-virus programs available to the Kingdom’s ISPs at special prices. It was hoped that this would encourage Internet service providers to scan e-mail for all their users so individuals would be relieved of the burden. ISPs did not respond enthusiastically to the plan. In fact, it has been an utter failure and malicious code is proliferating at an ever-increasing rate throughout the Saudi network. It is interesting to note that there is a famous, free e-mail service that does scan for malicious code — Microsoft’s Hotmail.
I urge everyone that is even considering connecting to the Internet to get an anti-virus program, sign up for the user alerts and update the program immediately after receiving an alert. Symantec, Trend and Network Associates are some of the most famous developers of these programs. You’ve got to install original software because pirated versions can’t be updated. Then get a firewall. For individual users I highly recommend “ZoneAlarm.” Download it free from Zone Labs (zonelabs.com). The firewall needs no technical expertise to install or use. Do not ever install a firewall that has not been reviewed by a trusted source. Just imagine if you installed a firewall on your machine that came with a backdoor built in to let certain creeps have access to your data. No matter what type of firewall you have installed on your PC, it is important to remember that sensitive information should never be stored on your hard drive if it is connecting to the Internet. Invest in a CD writer.

