information and reverse engineering bits of the Mydoom worm
From: Gadi Evron (ge_at_linuxbox.org)
Date: 01/27/04
- Previous message: JT: "Re: Internet Monitoring Software Detection"
- Next in thread: Markus Zingg: "Re: information and reverse engineering bits of the Mydoom worm"
- Reply: Markus Zingg: "Re: information and reverse engineering bits of the Mydoom worm"
- Maybe reply: Markus Zingg: "Re: information and reverse engineering bits of the Mydoom worm"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Tue, 27 Jan 2004 23:59:23 +0200
We've released a digest of a few of the messages that passed through
TH-Research about this new worm.
In it is information about the worm that is not included in the
different vendors web pages, and requires a higher understanding of
assembly and reverse engineering.
We release it for the purpose of assisting sysadmins and security
researchers by making the information available publicly.
You can find the digest at: http://www.math.org.il/newworm-digest1.txt.
As always, this information is released with the agreement of the
different authors, according to the list's FAQ guidelines.
Sorry for cross-posting, but I figure this is much like an article and
sending it to three news groups is not that big of a deal, when it is
on-topic. My apologies if the cross-posting offended anyone.
Gadi Evron.
The Trojan Horses Research Mailing List - http://ecompute.org/th-list
- Previous message: JT: "Re: Internet Monitoring Software Detection"
- Next in thread: Markus Zingg: "Re: information and reverse engineering bits of the Mydoom worm"
- Reply: Markus Zingg: "Re: information and reverse engineering bits of the Mydoom worm"
- Maybe reply: Markus Zingg: "Re: information and reverse engineering bits of the Mydoom worm"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|