RE: [Full-Disclosure] Re: Why are postmasters distributing the MyDoom virus?

From: Bill Royds (full-disclosure_at_royds.net)
Date: 02/08/04

  • Next message: Valdis.Kletnieks_at_vt.edu: "Re: [Full-Disclosure] (no subject)"
    To: <gadgeteer@elegantinnovations.org>, <full-disclosure@lists.netsys.com>
    Date: Sat, 7 Feb 2004 20:07:27 -0500
    
    

    The problem is not just AV systems sending out warnings which is
    unnecessary. It is the fact that many viruses also forge the to addresses as
    well as the from addresses. The normal MTA response to a non-existent
    address is to send a Non-delivery reply back to the from address containing
    the original message as an attachment. These go to the spoofed from address
    of original message, adding another transmission vector for the virus, with
    even better "social engineering" to persuade someone to open it. Since some
    AV systems scan direct attachments, but not attachments within attachments,
    it even provides a greater possibility of passing though an anti-virus
    gateway than the original message.
       P.S. The correct plural of virus is viruses. The original Latin word
    virus had no plural. The word virii is the plural of the word vir which
    means man.

    -----Original Message-----
    From: full-disclosure-admin@lists.netsys.com
    [mailto:full-disclosure-admin@lists.netsys.com] On Behalf Of
    gadgeteer@elegantinnovations.org
    Sent: February 7, 2004 4:34 PM
    To: full-disclosure@lists.netsys.com
    Subject: [Full-Disclosure] Re: Why are postmasters distributing the MyDoom
    virus?

    On Sat, Feb 07, 2004 at 02:15:43PM -0500, Richard M. Smith
    (rms@computerbytesman.com) wrote:
    > Perhaps these postmasters need to review
    > their bounce message policies and remove all attached files from messages
    > being bounced.

    Since it is well known that virii forge From headers the better policy
    adjustment would be to NOT bounce virii messages at all. The Anti-Virus
    companies are certainly well aware of it as it is a characteristic
    described in their alerts.

    Many of these bounces triggered by virii are nothing less then a spam
    opprotunity for the A-V software company. There is no "opt-out"
    from these spam messages. This would seem to be a clear violation of
    CAN-SPAM.

    Some sites have implemented various schemes to reject virii at the smtp
    level. See nanog mail archives for recent threads dealing with this and
    related topics.

    -- 
    Chief Gadgeteer
    Elegant Innovations
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    

  • Next message: Valdis.Kletnieks_at_vt.edu: "Re: [Full-Disclosure] (no subject)"

    Relevant Pages

    • Re: Get your free microsoft secuirty posters
      ... >>God, doesn't anyone have a dictionary anymore? ... The plural of virus ... It is NOT virii. ... Kazaa users should not be surprised at receiving viruses and other ...
      (alt.computer.security)
    • A Very Stubborn Spyware
      ... If Cliff wants virii to be plural for virus it is his ... use of language in any form he wishes to even if it is ... >>anomolous hosts files, the registry was no longer reset ...
      (microsoft.public.windowsxp.general)
    • Re: How to easily infect any linux box...especially up-yr-fucking-butt-too...LOL!
      ... malicious programs and they do not need root access to cause damage. ... "We are seeing a growing interest by virus writers and virus writing ... Then it starts talking about virus problems when hosting/serving Windows ... 'known' virii are 'proof of concept' virii, ...
      (microsoft.public.windows.vista.general)
    • Re: pocket PC and Virii and Malware
      ... 'virii' is not the correct plural of 'virus'; ... Werner Ruotsalainen - Microsoft MVP - Windows - Mobile Devices ... Symantec makes a version of Norton Antivirus for Handhelds, ... Virii is not a word. ...
      (microsoft.public.pocketpc)
    • [Full-Disclosure] Re: Why are postmasters distributing the MyDoom virus?
      ... Since it is well known that virii forge From headers the better policy ... adjustment would be to NOT bounce virii messages at all. ... opprotunity for the A-V software company. ... from these spam messages. ...
      (Full-Disclosure)

  • Quantcast