procmail
[Top] [All Lists]

RE: virus recipe for MyDoom

2004-01-27 08:41:58
Gary Funck writes:

John Connover wrote:

BTW, the series beginning with ^T is the Microsoft executable
loader/header information in base64; the UEsD is the PK zip signature
in base64. See /usr/share/misc/signature for particulars, and covert
the first characters to base64 as per RFC1521 where 3 bytes are mapped
into 4 printable characters.


John, is '/usr/share/misc/signature' associated with a particular Unix
utility? That file isn't installed in my RH 9.0 configuration.


No, there is a magic file that contains the signatures of various
files. Try "locate magic" and see if you get something like
/usr/share/misc/magic, and see if it works any better, and will cover
up my typos ... it was a late night ...

        Sorry about that,

        John

-- 

John Conover, conover(_at_)rahul(_dot_)net, http://www.rahul.net/conover/

_______________________________________________
procmail mailing list
procmail(_at_)lists(_dot_)RWTH-Aachen(_dot_)DE
http://MailMan.RWTH-Aachen.DE/mailman/listinfo/procmail

<Prev in Thread] Current Thread [Next in Thread>