RE: [Full-Disclosure] Culprit Bio: Perfect Storm Averted or Just Ahead?

From: Clairmont, Jan (JMC13_at_mail3.cs.state.ny.us)
Date: 01/29/04

  • Next message: Dave Sherohman: "Re: [Full-Disclosure] Proposal: how to notify owners of compromised PC's"
    To: full-disclosure@lists.netsys.com
    Date: Thu, 29 Jan 2004 10:06:53 -0500
    
    

    The guy who wrote this virus and/or unleashed it should not be too hard
    to track down. One, they are a Forth programmer, old school.
    I once met the Guy who invented Forth('83) and was in a seminar where
    he talked it up, not too many programmer then, not now. This language is
    very compact and powerful allowing a lot of functionality in a compact
    environment. There is the CVS tag that mentions Andy. So there is an
    association with Andy and Forth. Finally, the person knows communications
    programming, old school,
    tcp, ports, and sockets not portals etc, probably in assembler or C.

    Lastly, this person has a big Ego, so they have probably published on
    security, sockets, communications, SMTP, bios and/or forth. This person
    knows
    the ins and out of many computer architectures UNIX, PC, attacking Bios is
    old school int 20 , 21 stuff. Probably really hates Intel, Gates and
    MS, 8-> boy that's about everyone on this list. ;->

    Anyone with information, a reward is going to be posted.

    Regards,
    Jan Clairmont

    -----Original Message-----
    From: Collin R. Mulliner [mailto:collin@betaversion.net]
    Sent: Thursday, January 29, 2004 8:48 AM
    To: full-disclosure@lists.netsys.com
    Subject: Re: [Full-Disclosure] Mydoom: Perfect Storm Averted or Just Ahead?

    Hi,

    > That'd be an interesting defense. Has anyone tried renaming their
    > incoming MX machine so that it includes one of these strings?

    I think all email addresses which contain the unwanted strings are filtered
    out before asking for the mx host for a specific domain - so this defense
    wont work. Everything else would be to slow.

    ... Collin

    -- 
    Collin Mulliner <collin@betaversion.net>
    BATAVERSiON Systems [www.betaversion.net]
    fom: To know recursion, you must first know recursion.
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    

  • Next message: Dave Sherohman: "Re: [Full-Disclosure] Proposal: how to notify owners of compromised PC's"

    Relevant Pages

    • Re: [Full-disclosure] Should I Be Worried?
      ... think twice about actually going public with my school's security hole by having school notify students, parents and/or faculty at risk due to it. ... Full-Disclosure - We believe in it. ... Charter: http://lists.grok.org.uk/full-disclosure-charter.html ... Hosted and sponsored by Secunia - http://secunia.com/ ...
      (Full-Disclosure)
    • Re: [Full-disclosure] Should I Be Worried?
      ... If it is another school, maybe all these break-in news reports will ... Full-Disclosure - We believe in it. ... Charter: http://lists.grok.org.uk/full-disclosure-charter.html ... Hosted and sponsored by Secunia - http://secunia.com/ ...
      (Full-Disclosure)
    • Re: [Full-disclosure] Grab a myspace credential
      ... Full-Disclosure - We believe in it. ... Hosted and sponsored by Secunia - http://secunia.com/ ... Charter: http://lists.grok.org.uk/full-disclosure-charter.html ... I am a programmer by day, ...
      (Full-Disclosure)
    • Re: [Full-disclosure] PWCK Overflow POC Code Redhat/Suse older versions or something (maybe later to
      ... It may or may not be fake, but you are an *astonishingly* lame C programmer: ... Full-Disclosure - We believe in it. ... Charter: http://lists.grok.org.uk/full-disclosure-charter.html ...
      (Full-Disclosure)
    • Re: Career Advice? Your assistance is graciously appreciated!
      ... My boss is terrific, really great. ... These can make for a good programmer. ... Going back to school is something I ... If school is something you need to move up in the world, your employer ...
      (comp.programming)