Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

RE: Bugbear.b not blocked! why?

From: Hunt, Jim <Jim.Hunt(at)nwsc.k12.in.us>
Date: Tue Jun 10 2003 - 12:51:30 EDT


I block those as well as anything with a "double file extension." (filename.jpg.vbs) I know that is sometimes controversial but seems to be prudent.

Jim Hunt
Network & Systems Engineer
Northwestern School Corporation
Technology Department

Network Monitoring Tools & Tutorials
http://www.netmon.org
Featured in Network Computing Magazine

-----Original Message-----
From: Dongen, Jeroen van [mailto:jvandongen@seneca.nl] Sent: Tuesday, June 10, 2003 9:26 AM
To: 'Nick Warr'; gdecurtis@ennedi.com
Cc: focus-virus@securityfocus.com
Subject: RE: Bugbear.b not blocked! why?

I've heard more 'rumblings' about the current reincarnation of bugbear not
being blocked 100% by AV - though a good practice would be to rigorously block/strip every attachement that contains '.exe', '.scr' or '.pif' somewhere in its filename. In combination with nohtml.dll (if you happen to
run Outlook 2000/2002, see e.g.
http://ntbugtraq.ntadvice.com/default.asp?sid=1&pid=55&did=38) this would
stop practically all Bears dead in their tracks, without harming functionality too much.

-----Original Message-----
From: Nick Warr [mailto:nick@mobilia.it] Sent: Tuesday, June 10, 2003 9:53 AM
To: gdecurtis@ennedi.com
Cc: focus-virus@securityfocus.com
Subject: Re: Bugbear.b not blocked! why?

I've seen viruses pass when they were corrupted (and non functional), we use
a different mail scanner (rav) though.

Nick
----- Original Message -----
From: <gdecurtis@ennedi.com>
To: <focus-virus@securityfocus.com>
Sent: Monday, June 09, 2003 2:04 PM
Subject: Bugbear.b not blocked! why?

Do you need help?X

> Hi all,
all
> infected e-mails with Bugbear.b.


--
-

>
------------------------------------------------------------------------ -- --
>
------------------------------------------------------------------------ --- ------------------------------------------------------------------------ ---- ------------------------------------------------------------------------ --- ------------------------------------------------------------------------ ---- --------------------------------------------------------------------------- ----------------------------------------------------------------------------
Received on Tue Jun 10 14:06:27 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:39 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library