procmail
[Top] [All Lists]

Re: Happy99.exe virus/worm filter for mail server gateways

1999-03-07 11:08:56
On Fri, 5 Mar 1999, Michael Rawls wrote:

Hello All,
   There is currently a new virus/worm on the Internet that infects a
users computer by propagating itself across the Internet via email without
the owner of the infected computers' knowledge.  Details of the virus/worm
can be found at;

http://www.avertlabs.com/public/datafiles/valerts/vinfo/w32ska.asp

Please also take a look at:

  ftp://ftp.rubyriver.com/pub/jhardin/antispam/procmail-security.html

I have added the ability to specify particular executable filenames
(for example, happy99.exe) and to recoverably mangle the attachment
format so that it no longer looks like an attachment.

There's also a list of trojan executable filenames gleaned from
bugtraq and news.admin.net-abuse.email

--
 John Hardin KA7OHZ                               
jhardin(_at_)wolfenet(_dot_)com
 pgpk -a finger://gonzo.wolfenet.com/jhardin    PGP key ID: 0x41EA94F5
 PGP key fingerprint: A3 0C 5B C2 EF 0D 2C E5  E9 BF C8 33 A7 A9 CE 76 
-----------------------------------------------------------------------
  If you spend any time administering Windows NT, you're far too
  familiar with the Blue Screen of Death (BSOD) ...
                            - "MSDN Flash" email newsletter, 2/8/1999
-----------------------------------------------------------------------
   74 days until Star Wars episode I


<Prev in Thread] Current Thread [Next in Thread>