Go Back   Velocity Reviews > Newsgroups > Computer Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

Computer Security - New worm tactic.

 
Thread Tools Search this Thread
Old 06-26-2003, 01:35 AM   #1
Default New worm tactic.


I see someone has sent me a .zip file which contains a .pif file
which undoubredly comtains something that is not going to do
my PC any good were it executed.

Checking on McAfee I find it is

W32/Sobig.e@MM.

"This variant is similar to W32/Sobig.d@MM. The worm propagates via
email and over network shares. It contains its own SMTP engine for
constructing outgoing messages.

The virus is sent in a ZIP archive, allowing it to bypass extension
blocking rules. However, this requires the end user to perform extra
steps in order to actually execute the virus."

But they wil, l and it also propagates via Network shares so beware !

**** is about to happen.


--
Jim Watt http://www.gibnet.com


Jim Watt
  Reply With Quote
Old 06-26-2003, 06:22 AM   #2
Don Kelloway
 
Posts: n/a
Default Re: New worm tactic.

"Jim Watt" <> wrote in message
news:...
> I see someone has sent me a .zip file which contains a .pif file
> which undoubredly comtains something that is not going to do
> my PC any good were it executed.
>
> Checking on McAfee I find it is
>
> W32/Sobig.e@MM.
>
> "This variant is similar to W32/Sobig.d@MM. The worm propagates via
> email and over network shares. It contains its own SMTP engine for
> constructing outgoing messages.
>
> The virus is sent in a ZIP archive, allowing it to bypass extension
> blocking rules. However, this requires the end user to perform extra
> steps in order to actually execute the virus."
>
> But they wil, l and it also propagates via Network shares so beware !
>
> **** is about to happen.
>
>
> --
> Jim Watt http://www.gibnet.com



Fortunately there are mail filtering applications (e.g.. Elron Software
Message Inspector and/or Anti-Virus) capable of examining and if necessary
blocking such attachments. Even if the file's extension has been changed.


--
Best regards,
Don Kelloway
Commodon Communications

Visit http://www.commodon.com to learn about the "Threats to Your Security
on the Internet".


  Reply With Quote
Old 06-26-2003, 07:57 AM   #3
Jim Watt
 
Posts: n/a
Default Re: New worm tactic.

On Thu, 26 Jun 2003 05:22:17 GMT, "Don Kelloway"
<> wrote:

>"Jim Watt" <> wrote in message
>news:.. .
>> I see someone has sent me a .zip file which contains a .pif file
>> which undoubredly comtains something that is not going to do
>> my PC any good were it executed.
>>
>> Checking on McAfee I find it is
>>
>> W32/Sobig.e@MM.
>>
>> "This variant is similar to W32/Sobig.d@MM. The worm propagates via
>> email and over network shares. It contains its own SMTP engine for
>> constructing outgoing messages.
>>
>> The virus is sent in a ZIP archive, allowing it to bypass extension
>> blocking rules. However, this requires the end user to perform extra
>> steps in order to actually execute the virus."
>>
>> But they wil, l and it also propagates via Network shares so beware !
>>
>> **** is about to happen.
>>
>>
>> --
>> Jim Watt http://www.gibnet.com

>
>
>Fortunately there are mail filtering applications (e.g.. Elron Software
>Message Inspector and/or Anti-Virus) capable of examining and if necessary
>blocking such attachments. Even if the file's extension has been changed.


Its not that the extension has been changed, its really a .zip file

However, you are right, the best point of defense is at the mail
server.
--
Jim Watt http://www.gibnet.com
  Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump