Security Incidents mailing list archives

RE: Novarg


From: "Chris Aguilar" <CAguilar () holdenandrew com>
Date: Wed, 28 Jan 2004 09:24:34 -0800

Beleguese and everyone else
We had been trapping Zip files for a while now and developed quarantine
procedures and "pick up" methods for our clients of these zip files. For
most of them we are resorting to web based up load utilities for file
transport to assure that the correct, clean attachments are arriving at
the correct destinations. With our over 20 or so Internet Mail
accessible networks we have not had one desktop infected by stripping
Zip files and other executable attachments. Our network administrators
have however seen a lot of traffic on the mail servers and we have had
to restart a couple to bring them back on line as the barrage of
incoming email has been tremendous. But all told, for our end, so far so
good...so long as no one downloads it off a yahoo or hotmail site. (but
hopefully the Norton scanners will catch it at that point.). For
everyone's info, we have been using Symantec Corporate edition and it
has been flawless catching the incoming bugs. Once our mail server
strips the attachments, the Symantec scanner has been able to detect the
infected files and quarantine. I could employ a full time person right
now to dump the quarantines out ! If any one has questions on our set up
or tools, let me know
Thanks! 



Christopher M. Aguilar
Holden Andrew Corporation
http://www.holdenandrew.com
caguilar () holdenandrew com
 
-----Original Message-----
From: sloppy seconds [mailto:beleguese () yahoo com] 
Sent: Tuesday, January 27, 2004 8:32 PM
To: incidents () securityfocus com
Subject: Novarg

To all, 

Yes as many of you have noticed Novarg is spreading
fast. I work for a large international corporation and
we have seen extensive infiltration. However, this
worm has not proved to be as "damaging" as some may
claim. The scary part is that our investment in AV
solutions (Trend, Symantec, et al...) has not
protected us. We are now reconsidering our stance on
allowing .ZIP files in Email. 

We engineered our own cleaning utility hours before
our AV vendors even had signatures. Infecting lab
clients and using diff tools...etc

From a network perspective we are watching for the
supposed DOS against SCO. 

We have had the outbreak under control just a few
hours after it's inception. 

Anyone care to contribute their experience?

Thanks, 
Beleguese


__________________________________
Do you Yahoo!?
Yahoo! SiteBuilder - Free web site building tool. Try it!
http://webhosting.yahoo.com/ps/sb/

------------------------------------------------------------------------
---
------------------------------------------------------------------------
----


---------------------------------------------------------------------------
----------------------------------------------------------------------------


Current thread: