Re: [Full-Disclosure] Cleanining viruses from netware

From: Gadi Evron (ge_at_linuxbox.org)
Date: 06/01/04

  • Next message: Aviram Jenik: "[Full-Disclosure] Firebird Database Remote Database Name Overflow"
    To: Full-Disclosure <full-disclosure@lists.netsys.com>
    Date: Tue, 01 Jun 2004 18:46:55 +0200
    
    

    Harlan Carvey wrote:

    > Gadi,
    >
    > For the sake of the list, would you be willing to
    > share the answer you received?

    Begin quote>>>
    ST wrote:
    ---------
    It relatively easy if the virus is detectable remotely i.e. it has a
    component listening on a port. A simple nmap scan followed by a remote
    connect and run of the disinfection tool will work. I prefer this
    approach over using the directory service as it catches all active
    machines, irrespective of whether they are in the directory or not.

    Another approach is to use a login script that runs the disinfection
    util automatically, subsequent logins do not run the script. I used the
    absence of a file in a directory to indicate that the util had to be
    run, run the script and then *IF* successful, create the flag file.

    A combo of these methods will rapidly and effectivly catch most of the
    infected machines and remove them.
    -----

            Gadi.

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Aviram Jenik: "[Full-Disclosure] Firebird Database Remote Database Name Overflow"

    Relevant Pages

    • Re: cron jobs not done during sleep
      ... First thing in your script look for a flag file indicating last time ... If the flag file does exist compare dates. ... they must first drive mad. ...
      (freebsd-questions)
    • Re: Login script question
      ... Joe Banks wrote: ... > I was curious if there is a way that I can some how create a login script ... > that will map drives acording to the local server? ...
      (microsoft.public.scripting.vbscript)
    • Re: Assigning Printers w/ GPO per machine - Workaround
      ... solution is to use the login script to get the computer name and set ... Here is a copy of my login script: ... Find the default user directory and give everyone permission. ... The problem with the default user profile ...
      (microsoft.public.win2000.group_policy)
    • Re: Newbie to logon scripts - how to make a script run once only?
      ... script can check for the existence. ... The logon script would check for the existence of the flag file. ... nature of the flag file depends on the deployment. ...
      (microsoft.public.windows.server.scripting)
    • RE: Login Scripts do not run in group policy (w2k3DC) - More info for you!!!
      ... Created a "testou login script group policy" and linked it to the ... Edited "testou login script group policy" user configuration/ windows ... Check group policy modelling wizard - claims test login script policy was ...
      (microsoft.public.windows.group_policy)