Go Back   Sports Car Forum - MotorWorld.net > General Discussion > General Chat

General Chat General chat about anything that doesn't fit in another section here



Reply
 
Thread Tools Display Modes
Old 08-05-2003, 06:48 AM   #1
jon_s
Regular User
 
Join Date: Jul 2003
Location: London
Posts: 3,381
Default General Virus alert!

(Just thought I would let people know)

Latest worm uses IT administrator tactics
Mimail bug tries to convince you it was sent by the IT department
A new mass-mailing virus, which disguises itself as a file sent by a computer user's network administrator, began infecting systems on Friday.

The worm, which is being dubbed 'mimail', attempts to exploit a vulnerability in Internet Explorer that allows a script to be executed by an infected computer. The worm then tries to use that script to mass email itself, potentially clogging mail servers or slowing down networks, according to anti-virus company Symantec.

The arrival of Mimail comes amid heightened fears that a large-scale attack on the internet could be looming. The US government warned last week that a widespread flaw in Windows could be used to generate an attack.

The email that carries the worm has "your account" in the subject line, according to Symantec, and the body reads, "Hello there, I would like to inform you about important information regarding your e-mail address. This e-mail address will be expiring. Please read attachment for details."

It is then signed "Best regards, Administrator" and contains an attachment labelled "message.zip" that carries the malicious code.

In terms of its method, the mimail bug is somewhat similar to other mass-mailing worms, said Sharon Ruckman, a senior director at Symantec Security Response. What's trickier than usual, she said, is the way the email that carries the worm tries to get people to open the attachment.

"The social engineering aspect [is] a lot more serious," Ruckman said. "You believe it was the administrator from your own domain, whether that is your company or your ISP."

Also of note, Ruckman said, is that the mass emailing code is contained in an HTML file, a type of file not normally associated with executing programs. Ruckman recommended that corporations either delete the attachments at the server level or block messages with the "your account" subject line.

As of 1:45 p.m. PST, Symantec said it had received 125 total submissions of the worm and had rated it as a threat level of 3 on a scale of 1 to 5.
jon_s is offline   Reply With Quote
Old 08-05-2003, 07:10 AM   #2
TT
Regular User
 
Join Date: Jun 2003
Location: Lugano, Switzerland
Posts: 23,178
Default

Thanks for the info dude

Nothing here so far, but anyway, I never d/l attachement I'm not waiting for
__________________
TT is offline   Reply With Quote
Old 08-05-2003, 07:34 AM   #3
cho_888
Regular User
 
Join Date: Jun 2003
Location: victoria, Australia
Posts: 1,562
Default

thanks,
its been a while since the last major virus
cho_888 is offline   Reply With Quote
Old 08-05-2003, 07:55 AM   #4
gis
Regular User
 
Join Date: Jun 2003
Location: Lancashire,United Kingdom
Posts: 3,846
Default

thanks for the warning dude
__________________

http://img402.imageshack.us/img402/5803/dansigsp7.jpg
gis is offline   Reply With Quote
Old 08-05-2003, 11:49 AM   #5
possessed_beaver
Regular User
 
Join Date: Jun 2003
Location: Lat: -31 56.84 505 Long. 116.00.09 5 Australia
Posts: 2,855
Default

Originally Posted by cho_888
thanks,
its been a while since the last major virus
and i bet money that this won't be the next major virus..
possessed_beaver is offline   Reply With Quote
Old 08-05-2003, 12:14 PM   #6
jon_s
Regular User
 
Join Date: Jul 2003
Location: London
Posts: 3,381
Default

Doubt it will me a major threat, but a pain in the arse none the less.
jon_s is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump