Security Incidents mailing list archives
RE: Novarg
From: "Chris Aguilar" <CAguilar () holdenandrew com>
Date: Wed, 28 Jan 2004 09:24:34 -0800
Beleguese and everyone else We had been trapping Zip files for a while now and developed quarantine procedures and "pick up" methods for our clients of these zip files. For most of them we are resorting to web based up load utilities for file transport to assure that the correct, clean attachments are arriving at the correct destinations. With our over 20 or so Internet Mail accessible networks we have not had one desktop infected by stripping Zip files and other executable attachments. Our network administrators have however seen a lot of traffic on the mail servers and we have had to restart a couple to bring them back on line as the barrage of incoming email has been tremendous. But all told, for our end, so far so good...so long as no one downloads it off a yahoo or hotmail site. (but hopefully the Norton scanners will catch it at that point.). For everyone's info, we have been using Symantec Corporate edition and it has been flawless catching the incoming bugs. Once our mail server strips the attachments, the Symantec scanner has been able to detect the infected files and quarantine. I could employ a full time person right now to dump the quarantines out ! If any one has questions on our set up or tools, let me know Thanks! Christopher M. Aguilar Holden Andrew Corporation http://www.holdenandrew.com caguilar () holdenandrew com -----Original Message----- From: sloppy seconds [mailto:beleguese () yahoo com] Sent: Tuesday, January 27, 2004 8:32 PM To: incidents () securityfocus com Subject: Novarg To all, Yes as many of you have noticed Novarg is spreading fast. I work for a large international corporation and we have seen extensive infiltration. However, this worm has not proved to be as "damaging" as some may claim. The scary part is that our investment in AV solutions (Trend, Symantec, et al...) has not protected us. We are now reconsidering our stance on allowing .ZIP files in Email. We engineered our own cleaning utility hours before our AV vendors even had signatures. Infecting lab clients and using diff tools...etc
From a network perspective we are watching for the
supposed DOS against SCO. We have had the outbreak under control just a few hours after it's inception. Anyone care to contribute their experience? Thanks, Beleguese __________________________________ Do you Yahoo!? Yahoo! SiteBuilder - Free web site building tool. Try it! http://webhosting.yahoo.com/ps/sb/ ------------------------------------------------------------------------ --- ------------------------------------------------------------------------ ---- --------------------------------------------------------------------------- ----------------------------------------------------------------------------
Current thread:
- RE: Novarg - Stopping .Zip Files, (continued)
- RE: Novarg - Stopping .Zip Files Tom Milliner (Jan 28)
- Re: Novarg - Stopping .Zip Files Keith W. McCammon (Jan 28)
- Re: Novarg - Stopping .Zip Files Alvin Mills (Jan 30)
- RE: Novarg - Stopping .Zip Files jamesworld (Jan 28)
- Re: Novarg - Stopping .Zip Files Bill Pennington (Jan 28)
- RE: Novarg - Stopping .Zip Files Timmothy Posey (Jan 30)
- Re: Novarg - Stopping .Zip Files Alvin Mills (Jan 30)
- Re: Novarg - Stopping .Zip Files Keith W. McCammon (Jan 28)
- Re: Novarg Dave Laird (Jan 28)
- RE: Novarg Wayne S. Ackley (Jan 28)
- Re: Novarg James Riden (Jan 28)
- RE: Novarg Chris Aguilar (Jan 28)
- RE: Novarg Jeremy Strachan (Jan 28)
- RE: Novarg Stephen Warren (Jan 29)
- Re: Novarg Robin Sheat (Jan 30)
- RE: Novarg steve bernacki (Jan 30)
- Re: Novarg Skip Carter (Jan 30)
- RE: Novarg Duston Sickler (Jan 29)
- RE: Novarg sloppy seconds (Jan 30)
- RE: Novarg Stephen Warren (Jan 29)
- RE: Novarg Robert Morales (Jan 28)
- RE: Novarg Rickert Gerhard (rgerhard) (Jan 29)
- Re: Novarg Ivan Coric (Jan 29)
(Thread continues...)
- RE: Novarg - Stopping .Zip Files Tom Milliner (Jan 28)
