Security Incidents mailing list archives
Re: Novarg
From: "Jonathan A. Zdziarski" <jonathan () nuclearelephant com>
Date: Wed, 28 Jan 2004 12:05:26 -0500
Anyone care to contribute their experience?
You can implement all the MTA policies and anti-virus software you want, but ultimately if you have dumb employees, you will get burned at some point. The best defense to viruses like this is user education. If you haven't trained your users not to open unknown attachments by now, I would take the time to revamp whatever training (if any) you provide your users with. Part of the new employee handbook should include a basic tutorial on email security and other related areas such as what types of passwords to avoid. Being that you work for a large company, a regular publication for all employees giving them small updates about the latest end-user vulnerabilities and tips on improving security of their laptop, etc., would be very useful. Finally a means of detection is helpful in spearheading the really daft ones who don't read what you give them or pay attention in training. Setting up detection on port 25 outgoing and other suspicious ports can tell you who went and opened the attachment. Jonathan --------------------------------------------------------------------------- ----------------------------------------------------------------------------
Current thread:
- Novarg sloppy seconds (Jan 28)
- Re: Novarg Jonathan A. Zdziarski (Jan 28)
- Re: Novarg James Riden (Jan 28)
- Re: Novarg Jim Zajkowski (Jan 28)
- Re: Novarg Nick FitzGerald (Jan 29)
- Re: Novarg Greg A. Woods (Jan 28)
- Re: Novarg Jonathan A. Zdziarski (Jan 28)
- best defense (was: Re: Novarg Meritt James (Jan 29)
- Re: best defense (was: Re: Novarg Greg A. Woods (Jan 30)
- Re: Novarg Matt Curtin (Jan 30)
- Re: Novarg Matt Curtin (Jan 29)
- Re: Novarg Jonathan A. Zdziarski (Jan 28)
- RE: Novarg - Stopping .Zip Files Tom Milliner (Jan 28)
