Re: [Full-Disclosure] Cleanining viruses from netware
From: Gadi Evron (ge_at_linuxbox.org)
Date: 06/01/04
- Previous message: Sam Bashton: "Re: [Full-Disclosure] Possible bug in PHPNuke and other CMS"
- In reply to: Harlan Carvey: "Re: [Full-Disclosure] Cleanining viruses from netware"
- Next in thread: Dowling, Gabrielle: "Re: [Full-Disclosure] Cleanining viruses from netware"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: Full-Disclosure <full-disclosure@lists.netsys.com> Date: Tue, 01 Jun 2004 18:46:55 +0200
Harlan Carvey wrote:
> Gadi,
>
> For the sake of the list, would you be willing to
> share the answer you received?
Begin quote>>>
ST wrote:
---------
It relatively easy if the virus is detectable remotely i.e. it has a
component listening on a port. A simple nmap scan followed by a remote
connect and run of the disinfection tool will work. I prefer this
approach over using the directory service as it catches all active
machines, irrespective of whether they are in the directory or not.
Another approach is to use a login script that runs the disinfection
util automatically, subsequent logins do not run the script. I used the
absence of a file in a directory to indicate that the util had to be
run, run the script and then *IF* successful, create the flag file.
A combo of these methods will rapidly and effectivly catch most of the
infected machines and remove them.
-----
Gadi.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
- Previous message: Sam Bashton: "Re: [Full-Disclosure] Possible bug in PHPNuke and other CMS"
- In reply to: Harlan Carvey: "Re: [Full-Disclosure] Cleanining viruses from netware"
- Next in thread: Dowling, Gabrielle: "Re: [Full-Disclosure] Cleanining viruses from netware"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|
|