Reseller Hosting, Shared Hosting, Dedicated Hosting by Vortech Inc.

Go Back   Reseller Hosting, Shared Hosting, Dedicated Hosting by Vortech Inc. > >>Network Information & News and Announcements > News and Announcements
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

News and Announcements This is where you can read announcements regarding Vortech Inc.

Reply
 
Thread Tools Display Modes
  #1  
Old 01-26-2004, 09:22 PM
alexc
Guest
 
E-mail worm alert: Mydoom/Novarg.A

We've seen a fair amount of e-mail messages containing the latest in unimaginative e-mail worm technology, dubbed W32/Mydoom@MM by McAfee and W32.Novarg.A@mm by Symantec. It usually appears in the form of a .zip attachment but may take on any of the usual file extensions. Its main purpose is to spread and make its victims participate in a DoS attack on sco.com (insert political statement here). The frequency of rejected messages on the mail servers due to unkosher attachments has been rising since about 17:00 EST so you will probably find copies of it in your mailbox very soon.

Be careful. Antivirus programs may need to be manually updated.

Anyway, more data here:

http://www.datafellows.com/v-descs/novarg.shtml
http://securityresponse.symantec.com...varg.a@mm.html

Last edited by alexc : 01-26-2004 at 09:54 PM.
Reply With Quote
  #2  
Old 01-26-2004, 11:00 PM
generic's Avatar
generic generic is offline
guess who.. :)
Vortech Inc. Customer
 
Location: chicago
Yes, Just got a few return messages from people I never emailed too with the virus, looks like its possibly sending return emails too faking them as returned mail.


FIX is to just download current virus definitions and run a complete scan.
__________________
goodbye idevaffiliate, you can kiss my @$* with your poor support and broken script, I am now using post affiliate pro 3

Last edited by generic : 01-26-2004 at 11:03 PM.
Reply With Quote
  #3  
Old 01-27-2004, 02:12 AM
Bladesnitz
Guest
 
Of course, thats basic spoofing technology in Viruses nowadays. Most new worms now:

1) Run their own SMTP Server (Straight connect to target)
2) Choose Random TO and FROM: addresses

This does not make it difficult to track at all. In fact, I just received one to my private box, and a bounce. Nice.

All I can say is... When will people learn NOT to open attachments?!?!

This one comes in ZIP format to, so its gonna get through the block on SMTP ... It was only a matter of time...
Reply With Quote
  #4  
Old 01-27-2004, 10:08 AM
admin's Avatar
admin admin is offline
Vortech Inc. Owner
Owner
 
Location: Orlando FL
Send a message via ICQ to admin
it says something about doing a dos on feb 1. But it says nothing about who and what it will dos. I wounder when we will find out who and what it will dos..
__________________
Brad Pugh
http://www.vortechhosting.com
------

Local System/Network Monitor
http://nagios.hsphere.cc/
Login:guest Pass:guest
XML FEED http://nagios.hsphere.cc/feed.xml
------

My Other Life:
Reply With Quote
  #5  
Old 01-27-2004, 10:12 AM
admin's Avatar
admin admin is offline
Vortech Inc. Owner
Owner
 
Location: Orlando FL
Send a message via ICQ to admin
Never mind looks like they will be hitting sco.com that sucks..
__________________
Brad Pugh
http://www.vortechhosting.com
------

Local System/Network Monitor
http://nagios.hsphere.cc/
Login:guest Pass:guest
XML FEED http://nagios.hsphere.cc/feed.xml
------

My Other Life:
Reply With Quote
  #6  
Old 01-27-2004, 11:44 AM
jmbeach's Avatar
jmbeach jmbeach is offline
mistra know it all
Vortech Inc. Customer
 
Location: San Diego
Quote:
Originally Posted by Bladesnitz
All I can say is... When will people learn NOT to open attachments?!?!
Are you kidding me? Every time one of these comes out, I get the same clients calling me saying they've done something very bad, and I continue to tell them (in my nicest strong language) not to open anything, even from people you know. Never works, though, and I guess it's a good thing for me - tech support pays pretty well
Reply With Quote
  #7  
Old 01-27-2004, 05:29 PM
resell01 resell01 is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Ok, you gave us spam control, how about virus protection???
Reply With Quote
  #8  
Old 01-27-2004, 05:36 PM
Bladesnitz
Guest
 
We block executables. Any additional virus scanning would be seriously intensive on the server, ESPECIALLY in this case where they are in archives. Thats a serious load issue when you want us to scan your messages and your archived files... Unziping aint cheap when it comes to server resources.
Reply With Quote
  #9  
Old 01-27-2004, 05:43 PM
Vixen's Avatar
Vixen Vixen is offline
Twisted Administrator
Admin
 
Location: Orlando, FL
Send a message via ICQ to Vixen
Quote:
Originally Posted by resell01
Ok, you gave us spam control, how about virus protection???

I would never dream of expecting someone else to scan all of my mail. Plus, what happens if they delete something you actually WANTED?? Then of course, you would be upset but in reality it would not be there fault. Norton's and McAfee are both relatively cheap and give you the control of setting up the amount of protection you want on your computer.
__________________
~Vixen~





Team Warped MySpace



View Team Warped's Profile


**If you want something done right, get a woman to do it.**


All questions, comments, concerns, complaints, frustrations, irritations, aggravations, insinuations, allegations, accusations, contemplations, consternations, or input should be directed elsewhere.
Reply With Quote
  #10  
Old 01-27-2004, 06:15 PM
resell01 resell01 is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Just a suggestion. SpamAssasin scans all your mail (if you want it to). Option to 'Delete' or move to specific folder. Yep Norton is cheap and I tell my customers the same thing your saying (and it does spam and virus protection). Anyways....just a thought...
Reply With Quote
  #11  
Old 01-28-2004, 02:44 PM
nickp nickp is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Is there any way that vortech can block some of these bounces? There has to be some kind of pattern to it. Maybe just drop any bounced mail that has a zip attached or something to that affect..

My clients are well informed when it comes to avoiding virii. I think it's their friends that are causing the most trouble. I keep getting "I didn't send this" reports and I have to explain to them how the whole spoofing thing works and it's turning into a big ordeal.
Reply With Quote
  #12  
Old 01-28-2004, 03:14 PM
jmbeach's Avatar
jmbeach jmbeach is offline
mistra know it all
Vortech Inc. Customer
 
Location: San Diego
I'm sure they are doing what they can to minimize the damage - remember, they have to pay for bandwidth and personnel to remedy these situations. In the end, they can only do so much, and your customers have to know that this is a global issue, not one with a simple fix.
Reply With Quote
  #13  
Old 01-28-2004, 03:46 PM
nickp nickp is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
End users do not always know how big the issue is. They do however expect me to make the issue go away.
Reply With Quote
  #14  
Old 01-28-2004, 04:03 PM
jmbeach's Avatar
jmbeach jmbeach is offline
mistra know it all
Vortech Inc. Customer
 
Location: San Diego
Quote:
Originally Posted by nickp
End users do not always know how big the issue is. They do however expect me to make the issue go away.
No offense, but this is a really naive way for customers to look at the situation, no matter how much they pay us to support them. If it's all over the news, it's a big deal, and all of our customers must learn that they are as responsible as we are. If they don't want to be responsible, they have to learn to deal with consequences and must be ready to pay for the added support.

We host here, we don't hand hold. My opinion.
Reply With Quote
  #15  
Old 01-28-2004, 04:07 PM
Bladesnitz
Guest
 
Ignorance - pure and simple.

This virus is on national news, so if your customers just want it to 'go away', well then tell them to wait till hotmail and yahoo and aol take care of it first. I'm sure they might actually be having problems. And not lets forget about SCO, shaking in their boots about to be DoS (lamen terms - they are on the brink of a slaughter).

If they really want someone to blame, blame Microsoft, everyone else seems to... But in my opinion, the only people to blame are those that are still ignorant enough to open up any attachment that comes into their mailbox. I dont even open attachments from people I know, unless its a picture. I dont even open office documents...
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
New Mydoom variant dpyers Chit Chat Public 11 07-30-2004 10:34 AM
Virus/Worm Warning Brangwyn Chit Chat Public 3 05-02-2004 01:35 AM
Clean up MyDoom infections!!! Vantage Chit Chat Public 0 02-12-2004 03:46 PM
Microsoft / MyDoom Vantage Chit Chat Public 1 02-02-2004 11:47 PM
Another Worm shadowfyre Chit Chat Public 16 08-21-2003 12:30 PM


All times are GMT -5. The time now is 02:47 AM.


Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Vortech Inc. ©2005
Page generated in 0.74746 seconds with 18 queries
[Output: 111.28 Kb. compressed to 102.34 Kb. by saving 8.94 Kb. (8.04%)]