![]() |
|
|||||||
| News and Announcements This is where you can read announcements regarding Vortech Inc. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||||||||||
|
|||||||||||
|
E-mail worm alert: Mydoom/Novarg.A
We've seen a fair amount of e-mail messages containing the latest in unimaginative e-mail worm technology, dubbed W32/Mydoom@MM by McAfee and W32.Novarg.A@mm by Symantec. It usually appears in the form of a .zip attachment but may take on any of the usual file extensions. Its main purpose is to spread and make its victims participate in a DoS attack on sco.com (insert political statement here). The frequency of rejected messages on the mail servers due to unkosher attachments has been rising since about 17:00 EST so you will probably find copies of it in your mailbox very soon.
Be careful. Antivirus programs may need to be manually updated. Anyway, more data here: http://www.datafellows.com/v-descs/novarg.shtml http://securityresponse.symantec.com...varg.a@mm.html Last edited by alexc : 01-26-2004 at 09:54 PM. |
|
#2
|
||||||||||||
|
||||||||||||
|
Yes, Just got a few return messages from people I never emailed too with the virus, looks like its possibly sending return emails too faking them as returned mail.
FIX is to just download current virus definitions and run a complete scan.
__________________
goodbye idevaffiliate, you can kiss my @$* with your poor support and broken script, I am now using post affiliate pro 3 Last edited by generic : 01-26-2004 at 11:03 PM. |
|
#3
|
|||||||||||
|
|||||||||||
|
Of course, thats basic spoofing technology in Viruses nowadays. Most new worms now:
1) Run their own SMTP Server (Straight connect to target) 2) Choose Random TO and FROM: addresses This does not make it difficult to track at all. In fact, I just received one to my private box, and a bounce. Nice. All I can say is... When will people learn NOT to open attachments?!?! This one comes in ZIP format to, so its gonna get through the block on SMTP ... It was only a matter of time... |
|
#4
|
||||
|
||||
|
it says something about doing a dos on feb 1. But it says nothing about who and what it will dos. I wounder when we will find out who and what it will dos..
__________________
Brad Pugh http://www.vortechhosting.com ------ Local System/Network Monitor http://nagios.hsphere.cc/ Login:guest Pass:guest XML FEED http://nagios.hsphere.cc/feed.xml ------ My Other Life:
|
|
#5
|
||||
|
||||
|
Never mind looks like they will be hitting sco.com that sucks..
__________________
Brad Pugh http://www.vortechhosting.com ------ Local System/Network Monitor http://nagios.hsphere.cc/ Login:guest Pass:guest XML FEED http://nagios.hsphere.cc/feed.xml ------ My Other Life:
|
|
#6
|
||||||||||||
|
||||||||||||
|
Quote:
![]() |
|
#7
|
|||||||||||
|
|||||||||||
|
Ok, you gave us spam control, how about virus protection???
|
|
#8
|
|||||||||||
|
|||||||||||
|
We block executables. Any additional virus scanning would be seriously intensive on the server, ESPECIALLY in this case where they are in archives. Thats a serious load issue when you want us to scan your messages and your archived files... Unziping aint cheap when it comes to server resources.
|
|
#9
|
||||
|
||||
|
Quote:
I would never dream of expecting someone else to scan all of my mail. Plus, what happens if they delete something you actually WANTED?? Then of course, you would be upset but in reality it would not be there fault. Norton's and McAfee are both relatively cheap and give you the control of setting up the amount of protection you want on your computer.
__________________
~Vixen~ ![]() Team Warped MySpace ![]() ![]() **If you want something done right, get a woman to do it.** All questions, comments, concerns, complaints, frustrations, irritations, aggravations, insinuations, allegations, accusations, contemplations, consternations, or input should be directed elsewhere. |
|
#10
|
|||||||||||
|
|||||||||||
|
Just a suggestion. SpamAssasin scans all your mail (if you want it to). Option to 'Delete' or move to specific folder. Yep Norton is cheap and I tell my customers the same thing your saying (and it does spam and virus protection). Anyways....just a thought...
|
|
#11
|
|||||||||||
|
|||||||||||
|
Is there any way that vortech can block some of these bounces? There has to be some kind of pattern to it. Maybe just drop any bounced mail that has a zip attached or something to that affect..
My clients are well informed when it comes to avoiding virii. I think it's their friends that are causing the most trouble. I keep getting "I didn't send this" reports and I have to explain to them how the whole spoofing thing works and it's turning into a big ordeal. |
|
#12
|
||||||||||||
|
||||||||||||
|
I'm sure they are doing what they can to minimize the damage - remember, they have to pay for bandwidth and personnel to remedy these situations. In the end, they can only do so much, and your customers have to know that this is a global issue, not one with a simple fix.
|
|
#13
|
|||||||||||
|
|||||||||||
|
End users do not always know how big the issue is. They do however expect me to make the issue go away.
|
|
#14
|
||||||||||||
|
||||||||||||
|
Quote:
We host here, we don't hand hold. My opinion. |
|
#15
|
|||||||||||
|
|||||||||||
|
Ignorance - pure and simple.
This virus is on national news, so if your customers just want it to 'go away', well then tell them to wait till hotmail and yahoo and aol take care of it first. I'm sure they might actually be having problems. And not lets forget about SCO, shaking in their boots about to be DoS (lamen terms - they are on the brink of a slaughter). If they really want someone to blame, blame Microsoft, everyone else seems to... But in my opinion, the only people to blame are those that are still ignorant enough to open up any attachment that comes into their mailbox. I dont even open attachments from people I know, unless its a picture. I dont even open office documents... |
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| New Mydoom variant | dpyers | Chit Chat Public | 11 | 07-30-2004 10:34 AM |
| Virus/Worm Warning | Brangwyn | Chit Chat Public | 3 | 05-02-2004 01:35 AM |
| Clean up MyDoom infections!!! | Vantage | Chit Chat Public | 0 | 02-12-2004 03:46 PM |
| Microsoft / MyDoom | Vantage | Chit Chat Public | 1 | 02-02-2004 11:47 PM |
| Another Worm | shadowfyre | Chit Chat Public | 16 | 08-21-2003 12:30 PM |