RE: New virus outbreak.

From: Danny (Dannyat_private)
Date: Mon Mar 10 2003 - 11:17:46 PST

  • Next message: Bennett Todd: "Re: Real-world attacks on sendmail CA-2003-07 seen"

     
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    I don't have direct access to any of these boxes, in fact I don't have any access other than being able to hit their non routable IP's from out network. So unfortunately the info I've given you guys is all I have.
    
    Cheers
    Danny
    Network Security Engineer
    Drexel University
    PGP Print: C6AD B205 E3C6 38AB 0164 6604 66F5 CCFC F4ED F1E0
    PGP Key: http://akasha.irt.drexel.edu/danny.asc
     
    
    |->-----Original Message-----
    |->From: Harlan Carvey [mailto:keydet89at_private]
    |->Sent: Monday, March 10, 2003 9:18 AM
    |->To: incidentsat_private
    |->Subject: re: New virus outbreak.
    |->
    |->Danny,
    |->
    |->What else can you tell us about this?
    |->
    |->I checked McAfee's site for what you mentioned...
    |->http://vil.mcafee.com/dispVirus.asp?virus_k=98963
    |->
    |->How do you know that this is misdetected?  What
    |->processes are running and are associated with what
    |->you're seeing?  What ports, if any, are opened?  Have
    |->you tried updating your A/V software, and re-running
    |->the scan?
    |->
    |->__________________________________________________
    |->Do you Yahoo!?
    |->Yahoo! Tax Center - forms, calculators, tips, more
    |->http://taxes.yahoo.com/
    |->
    |->-------------------------------------------------------------------------
    |->---
    |->
    |-><Pre>Lose another weekend managing your IDS?
    |->Take back your personal time.
    |->15-day free trial of StillSecure Border Guard.</Pre>
    |-><A href="http://www.securityfocus.com/stillsecure">
    |->http://www.securityfocus.com/stillsecure </A>
    
    
    -----BEGIN PGP SIGNATURE-----
    Version: PGP 8.0
    
    iQA/AwUBPmzlqWb1zPz07fHgEQJL5wCfRER/tLR4YtJelTqDVoLcBKy4iSoAoLXY
    huNe7W2ZvdBtxrAo+qEqYooy
    =RiYH
    -----END PGP SIGNATURE-----
    
    ----------------------------------------------------------------------------
    
    <Pre>Lose another weekend managing your IDS?
    Take back your personal time.
    15-day free trial of StillSecure Border Guard.</Pre>
    <A href="http://www.securityfocus.com/stillsecure"> http://www.securityfocus.com/stillsecure </A>
    



    This archive was generated by hypermail 2b30 : Mon Mar 10 2003 - 12:10:35 PST