Security Incidents mailing list archives

Re: Nimda and samba, chap II (20010531?)


From: Kris Carlier <root () iguana be>
Date: Wed, 19 Sep 2001 14:34:55 +0200 (MET DST)

Chip,

It isn't all that easy to clean up, even
with the new definition tables, F-prot
linux scanner will report clean with

quasinix:/etc/mail # fsav --version
F-Secure Anti-Virus for i386-linux Release 4.13 build 3360
Frisk Software International F-PROT engine version 3.10 build 701
sign.def version 2001-09-18
sign2.def version 2001-09-17
fsmacro.def version 2001-09-18


clearly infected .eml(s) laying everywhere.

OK, .eml, this ain't spreading through mail, is it ? We run fsav with
sendmail and amavis, and it clearly blocks those. Even 4.12 would do so,
but needs the latest signature

kr=


----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management 
and tracking system please see: http://aris.securityfocus.com


Current thread: