All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Alexis" <alexis@attla.net.ar>
To: netfilter <netfilter@lists.netfilter.org>
Subject: Re: virus warning
Date: Tue, 27 Jan 2004 10:17:58 -0300	[thread overview]
Message-ID: <002901c3e4d7$fb73fcd0$0200000a@heretic> (raw)
In-Reply-To: F22386C3FEB012449238672E38ED61E71642AC@overlord.overturemedia.com

In this case, we are protected !!!!!

We are all using a firewall with netfilter and input policy drop

:))))



----- Original Message ----- 
From: "Fritz Mesedilla" <fritz.mesedilla@overturemedia.com>
To: "Netfilter Mailing List (E-mail)" <netfilter@lists.netfilter.org>
Sent: Tuesday, January 27, 2004 4:30 AM
Subject: RE: virus warning



I forgot to send the details.


W32.Novarg.A@mm is a mass-mailing worm. The worm will arrive as an
attachment with a file extension of .bat, .cmd, .exe, .pif, .scr, or .zip.

When the machine gets infected, the worm will set up a backdoor into the
system by opening TCP ports 3127 thru 3198. This will potentially allow a
hacker to connect to the machine and utilize it as a proxy to gain access to
it's network resources. In addition, the backdoor has the ability to
download and execute arbitrary files.

The worm will perform a DoS starting on February 1, 2004. On February 12,
2004 the worm has a trigger date to stop spreading.


http://securityresponse.symantec.com/avcenter/venc/data/w32.novarg.a@mm.html



Cheers,

fritz <www.mesedilla.com>
---
+ Basta Ikaw Lord




-----Original Message-----
From:
Sent: Tuesday, January 27, 2004 2:45 PM
To: Netfilter Mailing List (E-mail)
Subject: Re: virus warning



Obviously this is a really new one ... F-prot didn't catch it .. and mines
up to date ...
However ... since kmail and linux don't much like 7 bit mime ... *grin*

I'm handing this one up to the folks at F-Prot to see why they didn't catch
it...


Alistair.

On January 27, 2004 12:44 am, Fritz Mesedilla wrote:
> friends,
>
> we got a virus in our list.
> clamav warned me about it.
> it's now spreading like fire even on other lists.
>
> thought you might like to be warned.
>
>
> Cheers,
>
> fritz <www.mesedilla.com>
> ---
> + Basta Ikaw Lord
>
>
>
>
> ----------------------------------------------------------------------
> This email and any files transmitted with it are confidential and
> intended solely for the use of the individual or entity to whom they
> are addressed. If you have received this email in error please notify
> the sender immediately by e-mail and delete this e-mail from your
> system. Please note that any views or opinions presented in this
> email are solely those of the author and do not necessarily represent
> those of the company. Finally, the recipient should check this email
> and any attachments for the presence of viruses. The company accepts
> no liability for any damage caused by any virus transmitted by this
> email.
>
> Overture Media, Inc.
> Direct Line: (632) 635-4785
> Trunkline:   (632) 631-8971 Local 146
> Fax: (632) 637-2206
> Level 1 Summit Media Offices, Robinsons Galleria EDSA Cor. Ortigas Ave.,
> Quezon City 1100


----------------------------------------------------------------------
This email and any files transmitted with it are confidential and
intended solely for the use of the individual or entity to whom they
are addressed. If you have received this email in error please notify
the sender immediately by e-mail and delete this e-mail from your
system. Please note that any views or opinions presented in this
email are solely those of the author and do not necessarily represent
those of the company. Finally, the recipient should check this email
and any attachments for the presence of viruses. The company accepts
no liability for any damage caused by any virus transmitted by this
email.

Overture Media, Inc.
Direct Line: (632) 635-4785
Trunkline:   (632) 631-8971 Local 146
Fax: (632) 637-2206
Level 1 Summit Media Offices, Robinsons Galleria EDSA Cor. Ortigas Ave.,
Quezon City 1100






  reply	other threads:[~2004-01-27 13:17 UTC|newest]

Thread overview: 24+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2004-01-27  7:30 virus warning Fritz Mesedilla
2004-01-27 13:17 ` Alexis [this message]
2004-01-28  4:46   ` Nilesh
  -- strict thread matches above, loose matches on Subject: below --
2004-01-28  7:02 Babar Kazmi
2004-01-27  5:44 Fritz Mesedilla
2004-01-27  6:45 ` Unknown, Alistair Tonner
     [not found] ` <200401270145.12799.Alistair Tonner <>
2004-01-27  7:38   ` Info
2004-01-27  8:12     ` Cedric Blancher
2004-01-27 15:44     ` Juan Hernandez
2004-01-27 15:47     ` Juan Hernandez
2003-09-07  9:47 Virus Warning administrator-PjAqaU27lzQ
2003-09-06 11:52 administrator-PjAqaU27lzQ
2003-09-05 22:29 administrator-PjAqaU27lzQ
2003-09-03 10:59 administrator
     [not found] <200309030954.BVS39064@dagger.cc.vt.edu>
2003-09-03 10:32 ` Russell King
2003-09-03 11:43   ` Bas Mevissen
2003-09-03  5:38 administrator-PjAqaU27lzQ
2003-09-03  3:33 administrator
2003-09-02 11:00 administrator-PjAqaU27lzQ
2003-09-02  2:41 administrator-PjAqaU27lzQ
2003-08-30 23:22 administrator-PjAqaU27lzQ
2003-08-27  9:46 administrator
2003-08-20 20:41 administrator
2003-06-26 20:06 administrator-PjAqaU27lzQ

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to='002901c3e4d7$fb73fcd0$0200000a@heretic' \
    --to=alexis@attla.net.ar \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.