Re: trojans

From: news (geerge_at_yahoo.com)
Date: 06/27/04


Date: Sun, 27 Jun 2004 13:59:58 GMT


"Bit Twister" <BitTwister@localhost.localdomain> skrev i meddelandet
news:slrncdtgtt.mut.BitTwister@wb.home.invalid...
> On Sun, 27 Jun 2004 12:18:43 GMT, news wrote:
> >
> > But i read that recently there were some kind of spyware/trojan from
Russia
>
> "Berbew" trojan
>
> > that were installed on Yahoo visitors computer.
>
> I kind of doubt it was caught from Yahoo.com. They are using Freebsd
> servers and the exploit was cause by a worm infecting the Microsoft's
> IIS servers using one of the multiple known IIS vulnerabilities.
>
> > A firewall could not stop
> > it. The spyware sent out information about bank account passwords.
>
> Firewall does not stop what is being brought to you by your browser.
>
> The Anti-virus software is the one to catch it, if it is not a day one
> virus and you have the very virus lastest database update.

Perhaps Process guard. Abtrusion trotector or TDS-3 will work for these new
ones?



Relevant Pages

  • Re: trojans
    ... They are using Freebsd ... > IIS servers using one of the multiple known IIS vulnerabilities. ... > Firewall does not stop what is being brought to you by your browser. ...
    (alt.computer.security)
  • RE: Slow user logon on Terminal server after migration to Windows 2003
    ... The Terminal Servers are 2000 or 2003. ... "Inside the firewall zone" means that the Citrix Servers have a firewall ... available RPC ports? ...
    (microsoft.public.windows.server.active_directory)
  • Re: medical records, web server, & stateful firewall vs packet filter
    ... > image and SQL servers directly (the image server link in particular ... The image and SQL servers ... the 2 firewall layers should run different s/ware - the idea is that a major ... security always cost a lot more than you expect (this comes up whenever we ...
    (comp.dcom.sys.cisco)
  • Re: I have been hacked (WAS: Have I been hacked or is nmap wrong?)
    ... > console based ftp client. ... the FTP servers have? ... > They are really mail servers, at least smtp for outgoing mails ... If you're firewall was dropping incoming packets destined to ...
    (freebsd-questions)
  • RE: Secure Network Design (DMZ, LAN, etc)
    ... you'll see that their both on the same subnet. ... It has a port for the trusted network and a port ... Our firewall handles NAT. ... > servers, wouldn't it require a public IP and therefore be somewhat ...
    (Security-Basics)