Re: [Full-disclosure] Corporate Virus Threats



On 6/30/06, Castigliola, Angelo <ACastigliola@xxxxxxxxxxxxxxxxx> wrote:
>When the malicious code writers build their viruses and Trojans why not
>code the threats to detect the use of proxy servers and if used, connect
>through them.

Typically you can get to the internet through the default gateway directly from the computer without needing to configure proxy settings. A better question would be why do viruses run in user-mode versus kernel mode (see http://www.phrack.org/show.php?p=62&a=6 "Kernel-mode backdoors for Windows NT")? My guess is that 15-18 year old kids that write viruses mostly use recycled code and are often poorly written.

>Working in Corporate America, most firewall configurations block outbound
>TCP 80, asthe proxies listen on other non-standard TCP ports.

I do not agree with this. Most corporations allow outbound TCP 80.

I think this thread is more appropriate for focus-virus and not Full-disclosure.

Full-Disclosure should setup its own dedicated lists for individual
topics like securityfocus.com do.

The thought of going near a Symantec run list makes me cringe.

John Cartwright, can we have more Full-Disclosure lists setup for
specialized topics?

Heres my suggestions:

FD social engineering and phishing list - discussion of social
engineering issues and its variants

FD vulnerability development list - discussion of development and
prevention of vulnerabilities

FD incident response and recovery list - discussion of response and
recovery issues

FD voice over internet protocol list - discussion of VoIP security issues

FD web application security list - discussion of web application, and
AJAX, FJAX secure coding.

FD bug disclosures list - discussion of new security threats and analysis

FD enterprise security list - discussion of corporate security issues,
and patch management, and employee monitoring

FD security careers list - discussion of latest jobs within security industry

FD media coverage list - discussion of security related stories in the news

FD vendor software support list - discussion of security product
support, anti virus, ids, firewall issues, security basics, setting up
software securely

FD is the future! Its time to upgrade FD, so we can take on the might
of Securityfocus.com, and give them a run for their money. Don't copy
Securityfocus though, originate, not duplicate!

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • RE: PAWS security vulnerability
    ... FreeBSD security list" isn't grammatically correct. ... "I told you to post the patch and info to the appropriate FreeBSD security ... "...This point and others are often discussed on the mailing lists, ...
    (freebsd-questions)
  • May I have permission to travel???????
    ... ""Homeland Security Tightens Grip on International Travel ... The Department of Homeland Security proposed new rules back in July ... These lists ... Instead of providing a passenger manifest after departure as now ...
    (alt.true-crime)
  • RE: PAWS security vulnerability
    ... You STILL haven't taken this to the correct security mailing list, ... > FreeBSD security ... >>lists, and you aren't the least bit interested in doing what ... >>appropriate forum to post the patch, ...
    (freebsd-questions)
  • [NEWS] Cisco IOS Stack Group Bidding Protocol Crafted Packet DoS
    ... Get your security news from a reliable source. ... The SGBP implementation provided by the Cisco Internetwork Operating ... This vulnerability affects any device that runs Cisco IOS and has enabled ... to apply Access Control Lists to prevent untrusted hosts from ...
    (Securiteam)
  • [Full-Disclosure] "Fud, lies and libel" against (type any name here, Ill use mi2g)
    ... I am a usual reader of all the major security lists and I laughed ... I'm not affiliated with mi2g. ... questioning the authenticity of the postings) with false vulnerabilities, ...
    (Full-Disclosure)