<?xml version="1.0" encoding="utf-8" ?>

<rss version="2.0" 
   xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
   xmlns:admin="http://webns.net/mvcb/"
   xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
   xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule">
<channel>
    <title>JaBbA's Hut - Viruses</title>
    <link>http://jalcorn.net/weblog/</link>
    <description>White Hat Liberal Geek Dad</description>
    <dc:language>en</dc:language>
    <generator>Serendipity 1.2.1 - http://www.s9y.org/</generator>
    <pubDate>Tue, 26 Sep 2006 21:32:06 GMT</pubDate>

    <image>
        <url>http://jalcorn.net/weblog/templates/default/img/s9y_banner_small.png</url>
        <title>RSS: JaBbA's Hut - Viruses - White Hat Liberal Geek Dad</title>
        <link>http://jalcorn.net/weblog/</link>
        <width>100</width>
        <height>21</height>
    </image>

<item>
    <title>Microsoft Patch</title>
    <link>http://jalcorn.net/weblog/archives/1032-Microsoft-Patch.html</link>
            <category>Viruses</category>
    
    <comments>http://jalcorn.net/weblog/archives/1032-Microsoft-Patch.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=1032</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=1032</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    Microsoft released a patch for the &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL2phbGNvcm4ubmV0L3dlYmxvZy9hcmNoaXZlcy8xMDMxLVN0YXR1cy1ZZWxsb3cuLUV4cGxvaXQtQ29kZS1pcy1tYWtpbmctdGhlLXJvdW5kcyEuaHRtbA==&amp;amp;entry_id=1032&quot; title=&quot;http://jalcorn.net/weblog/archives/1031-Status-Yellow.-Exploit-Code-is-making-the-rounds!.html&quot;  onmouseover=&quot;window.status=&#039;http://jalcorn.net/weblog/archives/1031-Status-Yellow.-Exploit-Code-is-making-the-rounds!.html&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot; &gt;VML Issue&lt;/a&gt;.  Make sure your automatic update is on, or go to windowsupdate.com to get the update directly.&lt;br /&gt;
&lt;br /&gt;
JaBbA says patch.  Now!&lt;br /&gt;
&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Tue, 26 Sep 2006 17:32:06 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/1032-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Status: Yellow.  Exploit Code is making the rounds!</title>
    <link>http://jalcorn.net/weblog/archives/1031-Status-Yellow.-Exploit-Code-is-making-the-rounds!.html</link>
            <category>Viruses</category>
    
    <comments>http://jalcorn.net/weblog/archives/1031-Status-Yellow.-Exploit-Code-is-making-the-rounds!.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=1031</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=1031</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    ISC has gone &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL2lzYy5zYW5zLm9yZy9kaWFyeS5waHA/c3RvcnlpZD0xNzI3&amp;amp;entry_id=1031&quot;  onmouseover=&quot;window.status=&#039;http://isc.sans.org/diary.php?storyid=1727&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;  title=&quot;Internet Storm Center&quot;&gt;Status Yellow&lt;/a&gt; because of new exploit code.&lt;br /&gt;
&lt;br /&gt;
It&#039;s a drive by - you&#039;ll NEVER know you got hacked on a fully-patched Win XP system until someone empties your PayPal account.&lt;br /&gt;
&lt;br /&gt;
Video of it happening is at &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy53ZWJzZW5zZS5jb20vc2VjdXJpdHlsYWJzL2Jsb2cvYmxvZy5waHA/QmxvZ0lEPTgy&amp;amp;entry_id=1031&quot;  onmouseover=&quot;window.status=&#039;http://www.websense.com/securitylabs/blog/blog.php?BlogID=82&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;  title=&quot;Websense&quot;&gt;The Websense Security Blog&lt;/a&gt;.  &lt;br /&gt;
&lt;br /&gt;
More info in &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL2lzYy5zYW5zLm9yZy9kaWFyeS5waHA/c3RvcnlpZD0xNzEz&amp;amp;entry_id=1031&quot;  onmouseover=&quot;window.status=&#039;http://isc.sans.org/diary.php?storyid=1713&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;  title=&quot;ISC&quot;&gt;Tuesday&#039;s ISC Diary&lt;/a&gt;, and &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL2lzYy5zYW5zLm9yZy9kaWFyeS5waHA/c3RvcnlpZD0xNzIy&amp;amp;entry_id=1031&quot;  onmouseover=&quot;window.status=&#039;http://isc.sans.org/diary.php?storyid=1722&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;  title=&quot;ISC&quot;&gt;Thursday&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
JaBbA&#039;s Recommendations:&lt;br /&gt;
&lt;br /&gt;
#1 - &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5nZXRmaXJlZm94LmNvbS8=&amp;amp;entry_id=1031&quot;  onmouseover=&quot;window.status=&#039;http://www.getfirefox.com/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;  title=&quot;getfirefox.com&quot;&gt;Use Firefox&lt;/a&gt; with &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5ub3NjcmlwdC5uZXQvd2hhdHM=&amp;amp;entry_id=1031&quot; title=&quot;http://www.noscript.net/whats&quot;  onmouseover=&quot;window.status=&#039;http://www.noscript.net/whats&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot; &gt;NoScript&lt;/a&gt;.&lt;br /&gt;
#2 - Update your Antivirus.  If you don&#039;t have Antivirus, try &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL2ZyZWUuZ3Jpc29mdC5jb20v&amp;amp;entry_id=1031&quot;  onmouseover=&quot;window.status=&#039;http://free.grisoft.com/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;  title=&quot;GRISoft&quot;&gt;AVG Anti-Virus Free Edition&lt;/a&gt;.&lt;br /&gt;
#3 - &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5tb3ppbGxhLmNvbS90aHVuZGVyYmlyZC8=&amp;amp;entry_id=1031&quot;  onmouseover=&quot;window.status=&#039;http://www.mozilla.com/thunderbird/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;  title=&quot;mozilla&quot;&gt;Use Thunderbird&lt;/a&gt; instead of outlook.&lt;br /&gt;
#4 - Slow down on that itchy trigger finger.  Do you really need to click that link that was just sent to you?&lt;br /&gt;
#5 - Unregister the DLLs.  This isn&#039;t for the faint of heart, but it will stop the hack&lt;br /&gt;
&lt;blockquote&gt;&lt;center&gt;regsvr32 -u &quot;%ProgramFiles%\Common Files\Microsoft Shared\VGX\vgx.dll&quot;&lt;br /&gt;
or&lt;br /&gt;
regsvr32 /u &quot;%CommonProgramFiles%\Microsoft Shared\VGX\vgx.dll&quot; &lt;br /&gt;
&lt;/center&gt;&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
Remove the -u to reregister them after October 10th, the date this is supposed to be fixed. 
    </content:encoded>

    <pubDate>Fri, 22 Sep 2006 15:05:45 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/1031-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>German SPAM? Or Virus</title>
    <link>http://jalcorn.net/weblog/archives/884-German-SPAM-Or-Virus.html</link>
            <category>SPAM</category>
            <category>Viruses</category>
    
    <comments>http://jalcorn.net/weblog/archives/884-German-SPAM-Or-Virus.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=884</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=884</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    Actually, a little of both.&lt;br /&gt;
&lt;br /&gt;
At some point, you&#039;ll get a German email today.  It will either be a short message with a link:&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;Lese selbst:&lt;br /&gt;
http://www.npd.de/npd_info/deutschland/2005/d0405-39.html&lt;br /&gt;
&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
Or a long tract:&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;In den fruehen Abendstunden des 13. Februar 1945 gegen 21:41 Uhr&lt;br /&gt;
heulten die Sirenen der Lazarettstadt Dresden das erste mal auf. Die Bewohner der Elbmetropole machten sich zu der Zeit noch keine Sorgen, da Dresden als Stadt ohne Bewaffnung und ohne militaerischen Nutzen bekannt war und von ca. 1,2 Millionen Frauen, Kindern und Greisen bewohnt wurde.&lt;br /&gt;
&lt;br /&gt;
Gegen 22:09 Uhr gab der Rundfunk durch, daÃ die alliierten Bomberverbaende ihren Kurs geaendert haben und nun auf Dresden zufliegen. Kurz darauf befanden sich 244 britische Bomber am Himmel der deutschen Kulturstadt. Drei Stunden nach dieser ersten Angriffswelle - es befanden sich bereits alle verfuegbaren Rettungsmannschaften, Sanitaeter und Feuerwehmaenner in Dresden - verdunkelten weitere 500 Bomber den Himmel.&lt;br /&gt;
Am naechsten Tag folgte die letzte Angriffswelle mit erneut 300 US-B-17-Bombern. Zwischen 12:12 Uhr und 12:21 Uhr warfen diese 783 Tonnen Bomben ab. - Das entspricht mehr als 85 Tonnen pro Minute. Nach dem Abwerfen setzten die US-Bomber zum Tiefflug an und beschossen Fluechtende mit ihren Bordwaffen. In diesen drei Angriffsschlaegen, die insgesamt 14 Stunden andauerten, warfen die &quot;Befreier&quot; 650.000 Brandbomben und 200.000 Sprengbomben ab, welche einen Feuersturm von ueber 1000 Grad in der Stadt erzeugten. Obwohl Dresden weder Flugabwehr, noch Ruestungsindustrie oder aehnliche kriegswichtige Ziele besass wurden weit mehr als 350.000 unschuldige deutsche Zivilisten in diesen zwei Tagen kaltbluetig ermordet.&lt;br /&gt;
&lt;br /&gt;
Keiner der schuldigen Alliierten wurde jemals fuer dieses brutale Kriegsverbrechen auch nur angeklagt und die Massenmedien und die bundesdeutsche Regierung schweigen diese Taten tot und sehen es nicht als noetig an den Opfern zu gedenken.!&lt;br /&gt;
&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
It&#039;s an artifact of the Sober-Q Virus.  Apparently, the virus targets European users with copies of itself, but targets the whole world with a political message related to the anniversary of the end of WWII and upcoming elections.&lt;br /&gt;
&lt;br /&gt;
Don&#039;t trust the fact that US users seem to get only email.  Delete the German emails immediately, in case it morphs to sending malware to everyone.&lt;br /&gt;
&lt;br /&gt;
More info at &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL2lzYy5zYW5zLm9yZy9kaWFyeS5waHA/ZGF0ZT0yMDA1LTA1LTE1&amp;amp;entry_id=884&quot; title=&quot;http://isc.sans.org/diary.php?date=2005-05-15&quot;  onmouseover=&quot;window.status=&#039;http://isc.sans.org/diary.php?date=2005-05-15&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;SANS&lt;/a&gt; 
    </content:encoded>

    <pubDate>Mon, 16 May 2005 12:26:24 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/884-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Oops!  Almost got bit....</title>
    <link>http://jalcorn.net/weblog/archives/533-Oops!-Almost-got-bit.....html</link>
            <category>Viruses</category>
    
    <comments>http://jalcorn.net/weblog/archives/533-Oops!-Almost-got-bit.....html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=533</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=533</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    Got an email caught in the &quot;Failure&quot; queue this morning.  That means that there&#039;s something about the MIME boundaries that IronMail just doesn&#039;t like - it&#039;s VERY picky, nasty emails that every MUA in the world display correctly IronMail chokes on, because it can&#039;t scan for viruses if it can&#039;t figure out where the attachments are.&lt;br /&gt;
&lt;br /&gt;
Looking at it, it looks like it might be a real email, so I download it to a text editor and look at the source.&lt;br /&gt;
&lt;div class=&quot;code&quot;&gt;Received: from ([67.163.144.96])&lt;br /&gt;
	by smtp2.mydomain.com with ESMTP  id 134030011.445707;&lt;br /&gt;
	Thu, 13 Jan 2005 10:08:57 -0500&lt;br /&gt;
SUBJECT: attachments&lt;br /&gt;
FROM: flastname@arealcompany.com&lt;br /&gt;
TO: first_last@mydomain.com&lt;br /&gt;
DATE: [[ Thu, 13 Jan 2005 10:10:07 AM ]]&lt;br /&gt;
MIME-Version: 1.0&lt;br /&gt;
Content-Type: multipart/mixed; boundary=&quot;--------bound--&quot;&lt;br /&gt;
&lt;br /&gt;
----------bound--&lt;br /&gt;
Content-Type: text/plain; charset=us-ascii&lt;br /&gt;
Content-Transfer-Encoding: 7bit&lt;br /&gt;
&lt;br /&gt;
I have updated my email address&lt;br /&gt;
See the (.pdf) file attached and&lt;br /&gt;
please respond if you have any questions. &lt;br /&gt;
----------bound--&lt;br /&gt;
Content-Type: application/x-msdownload; name=&quot;zip.zip&quot;&lt;br /&gt;
Content-Transfer-Encoding: base64&lt;br /&gt;
Content-Disposition: attachment; filename=&quot;zip.zip&quot;&lt;br /&gt;
&lt;br /&gt;
UEsDBBQAAAAIAENRLTI&lt;/div&gt;&lt;br /&gt;
etc...&lt;br /&gt;
&lt;br /&gt;
It took a second to the lack of headers to register - I&#039;d only had one cup of coffee, and I stopped going to starbuck&#039;s, so sometimes it takes a while for my brain to kickstart.  There&#039;s no Mailer-Agent.  Only one received header.  The Date is formatted oddly.&lt;br /&gt;
&lt;br /&gt;
So I checked out the IP address:&lt;br /&gt;
&lt;div class=&quot;code&quot;&gt;$ host 67.163.144.96&lt;br /&gt;
96.144.163.67.in-addr.arpa domain name pointer c-67-163-144-96.client.comcast.net.&lt;br /&gt;
&lt;/div&gt;&lt;br /&gt;
No large company (which is where this supposedly came from) is going to allow their people to send directly from their home accounts.  &lt;br /&gt;
&lt;br /&gt;
Sure enough, it&#039;s a virus - The &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy50cmVuZG1pY3JvLmNvbS92aW5mby92aXJ1c2VuY3ljbG8vZGVmYXVsdDUuYXNwP1ZOYW1lPVdPUk1fQkFHWi5DJlZTZWN0PVQ=&amp;amp;entry_id=533&quot; title=&quot;http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_BAGZ.C&amp;amp;VSect=T&quot;  onmouseover=&quot;window.status=&#039;http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_BAGZ.C&amp;amp;VSect=T&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;Bagz worm&lt;/a&gt;, apparently. 
    </content:encoded>

    <pubDate>Thu, 13 Jan 2005 10:35:04 -0500</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/533-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Zafi-D Effects...</title>
    <link>http://jalcorn.net/weblog/archives/516-Zafi-D-Effects....html</link>
            <category>Viruses</category>
    
    <comments>http://jalcorn.net/weblog/archives/516-Zafi-D-Effects....html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=516</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=516</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    &lt;a href=&#039;http://jalcorn.net/weblog/uploads/emailspike.png&#039;&gt;&lt;img width=&quot;110&quot; height=&quot;69&quot; border=&quot;0&quot; hspace=&quot;5&quot; align=&quot;left&quot; src=&quot;http://jalcorn.net/weblog/uploads/emailspike.serendipityThumb.png&quot; alt=&quot;&quot;  /&gt;&lt;/a&gt;Here&#039;s an interesting effect.  This is the inbound Internet email volume I manage each day.  I&#039;ve been waiting for the volume to top 40,000 - we&#039;ve gotten within 300 messages of that number before, but never quite there.&lt;br /&gt;
&lt;br /&gt;
Until yesterday.  I came in to a new number:&lt;br /&gt;
&lt;br /&gt;
49,398 inbound messages.&lt;br /&gt;
&lt;br /&gt;
Turns out that 11,000 of them were to a single, (thankfully) invalid email address.  Mostly bounces from the Zafi-D virus.  So even though we were protected from the virus, we ended up seeing a significant effect.&lt;br /&gt;
&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Wed, 15 Dec 2004 11:01:56 -0500</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/516-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>If you haven't patched, it may be too late....</title>
    <link>http://jalcorn.net/weblog/archives/319-If-you-havent-patched,-it-may-be-too-late.....html</link>
            <category>Viruses</category>
    
    <comments>http://jalcorn.net/weblog/archives/319-If-you-havent-patched,-it-may-be-too-late.....html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=319</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=319</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    This came through on the 0day list a few minutes ago:&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;-= 0day - Freedom of Voice - Freedom of Choice =-&lt;br /&gt;
&lt;br /&gt;
dropped file: %SYSTEM%/msiwin84.exe&lt;br /&gt;
remote process established to: lsass.exe&lt;br /&gt;
remote ip:4.x.x.x&lt;br /&gt;
&lt;br /&gt;
note: file msiwin84.was not running&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
this appears to be a &quot;blaster&quot; type of worm working on the first and / or&lt;br /&gt;
second subset of the infected host to begin scanning for more hosts.&lt;br /&gt;
I have not completly unpacked the binary but here is some strings.&lt;br /&gt;
&lt;br /&gt;
------------------ snip --------------&lt;br /&gt;
DnsFlushResolve&lt;br /&gt;
{ache.dapi.dllVQUIT RIVMSG %s : screw you KGGo home  cCmd.Net, +MODEW ]m715&lt;br /&gt;
522947&lt;br /&gt;
6660M USERHOST/@ JOINFL :YnASSo DCC \ND &quot; o:.bmp&quot;Jd Error: fix&gt;ipS enc&lt;5n  clos&lt;br /&gt;
*+h2(P/ t,O cu.g ACHO=Ds NEU(fkbit/s)  tal!x f@m&#039;Q_  IP addrvs3&lt;br /&gt;
&lt;br /&gt;
------------------ snip ---------------&lt;br /&gt;
&lt;br /&gt;
based on the above, the worm / viri tries to connect to a IRC server.&lt;br /&gt;
&lt;br /&gt;
anyone else experiencing this?&lt;br /&gt;
&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
This is in reference to one of the Microsoft Windows security patches that came out this month - see the &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5jdmUubWl0cmUub3JnL2NnaS1iaW4vY3ZlbmFtZS5jZ2k/bmFtZT1DQU4tMjAwMy0wNTMz&amp;amp;entry_id=319&quot; title=&quot;http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0533&quot;  onmouseover=&quot;window.status=&#039;http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0533&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;CVE CAN-2003--0533&lt;/a&gt; and the Microsoft bulletin &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5taWNyb3NvZnQuY29tL3RlY2huZXQvc2VjdXJpdHkvYnVsbGV0aW4vTVMwNC0wMTEubXNweA==&amp;amp;entry_id=319&quot; title=&quot;http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx&quot;  onmouseover=&quot;window.status=&#039;http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;MS04-011&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Get patched NOW.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;font size=&quot;large&quot; color=&quot;red&quot;&gt;UPDATE&lt;/font&gt; This report is apparently still not a worm, it is instead an example of &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5jb21wdXRlcndvcmxkLmNvbS9wcmludHRoaXMvMjAwNC8wLDQ4MTQsOTI3MzIsMDAuaHRtbA==&amp;amp;entry_id=319&quot; title=&quot;http://www.computerworld.com/printthis/2004/0,4814,92732,00.html&quot;  onmouseover=&quot;window.status=&#039;http://www.computerworld.com/printthis/2004/0,4814,92732,00.html&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;targeted attacks against the PCT vulnerability&lt;/a&gt; which implant the Backdoor.mipsiv worm.  However...&lt;br /&gt;
&lt;br /&gt;
Expect the worm soon.  The exploit code is out there... 
    </content:encoded>

    <pubDate>Thu, 29 Apr 2004 12:20:01 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/319-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>New MIMAIL-I/J combines Phishing and Virus</title>
    <link>http://jalcorn.net/weblog/archives/109-New-MIMAIL-IJ-combines-Phishing-and-Virus.html</link>
            <category>Viruses</category>
    
    <comments>http://jalcorn.net/weblog/archives/109-New-MIMAIL-IJ-combines-Phishing-and-Virus.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=109</wfw:comment>

    <slash:comments>1</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=109</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    The MIMAIL variants have been an especially nasty breed of virus.  The newest ones - MIMAIL-I and MIMAIL-J - try to grab Credit Card information from unsuspecting people by masquerading as PayPal information.&lt;br /&gt;
&lt;br /&gt;
See &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy50aGVyZWdpc3Rlci5jby51ay9jb250ZW50LzU2LzMzOTk0Lmh0bWw=&amp;amp;entry_id=109&quot; title=&quot;http://www.theregister.co.uk/content/56/33994.html&quot;  onmouseover=&quot;window.status=&#039;http://www.theregister.co.uk/content/56/33994.html&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;The Register&lt;/a&gt;, &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3NlY3VyaXR5cmVzcG9uc2Uuc3ltYW50ZWMuY29tL2F2Y2VudGVyL3ZlbmMvZGF0YS93MzIubWltYWlsLmpAbW0uaHRtbA==&amp;amp;entry_id=109&quot; title=&quot;http://securityresponse.symantec.com/avcenter/venc/data/w32.mimail.j@mm.html&quot;  onmouseover=&quot;window.status=&#039;http://securityresponse.symantec.com/avcenter/venc/data/w32.mimail.j@mm.html&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;Symantec&lt;/a&gt;, &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy50cmVuZG1pY3JvLmNvbS92aW5mby92aXJ1c2VuY3ljbG8vZGVmYXVsdDUuYXNwP1ZOYW1lPVdPUk1fTUlNQUlMLkk=&amp;amp;entry_id=109&quot; title=&quot;http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_MIMAIL.I&quot;  onmouseover=&quot;window.status=&#039;http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_MIMAIL.I&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;Trend Micro&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br clear=left /&gt; 
    </content:encoded>

    <pubDate>Wed, 19 Nov 2003 12:44:20 -0500</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/109-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Another Dangerous Hoax</title>
    <link>http://jalcorn.net/weblog/archives/72-Another-Dangerous-Hoax.html</link>
            <category>Viruses</category>
    
    <comments>http://jalcorn.net/weblog/archives/72-Another-Dangerous-Hoax.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=72</wfw:comment>

    <slash:comments>1</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=72</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    &#039;Dumaru&#039; is a new virus spread by seeming to be a Microsoft patch for the DCOM exploit used by Blaster and Welchia.  &lt;br /&gt;
&lt;br /&gt;
Remember, NEVER execute something you get in email that you have not confirmed with the sender!  Update your virus definitions!&lt;br /&gt;
&lt;br /&gt;
Dumaru Details:&lt;br /&gt;
FYI: W32.Dumaru@mm	Discovered:  August 16, 2003&lt;br /&gt;
W32.Dumaru@mm is a mass-mailing worm that drops an IRC Trojan onto the infected machine.  The worm gathers email addresses from the certain file types and uses its own STMP engine to email itself.&lt;br /&gt;
The email has the following characteristics:&lt;br /&gt;
&lt;br /&gt;
From:  &quot;Microsoft&quot;&lt;security@microsoft.com&gt;&lt;br /&gt;
Subject:  Use this patch immediately!&lt;br /&gt;
Message: Dear friend, use this Internet Explorer patch now!There are dangerous viruses in the Internet now! More than 500,000 already infected!&lt;br /&gt;
Attachment:  patch.exe&lt;br /&gt;
Type:  WormInfection Length:  9,216&lt;br /&gt;
Systems Affected: Windows 2000, 95, 98, Me, NT &amp;amp; XP&lt;br /&gt;
Systems Not Affected:  Linux, Macintosh, OS/2, UNIX&lt;br /&gt;
Threat Assessment Level 3 &lt;br /&gt;
Wild = Medium &lt;br /&gt;
Damage = Low&lt;br /&gt;
Distribution = Medium 
    </content:encoded>

    <pubDate>Tue, 19 Aug 2003 09:24:53 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/72-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>A 'Good' Worm?</title>
    <link>http://jalcorn.net/weblog/archives/73-A-Good-Worm.html</link>
            <category>Viruses</category>
    
    <comments>http://jalcorn.net/weblog/archives/73-A-Good-Worm.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=73</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=73</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    Someone has released a new worm dubbed &#039;Welchia&#039; that uses the same exploit as the blaster worm.  However, this worm is an attempt to eradicate the previous worm and to stop the spread of new worms.  When it infects a PC, it looks for copies of msblast.exe and deletes them, removes the registry keys, and then downloads the latest patch from Microsoft and installs it.&lt;br /&gt;
&lt;br /&gt;
It then starts looking for more computers that are vulnerable.&lt;br /&gt;
&lt;br /&gt;
Unfortunately, it also reboots your computer upon completion,so it can cause problems if you are in the middle of something. In addition, the reinfection and downloading can swamp networks.&lt;br /&gt;
&lt;br /&gt;
It&#039;s illegal under the 1986 law that made all computer intrusions illegal.&lt;br /&gt;
&lt;br /&gt;
There&#039;ve been a lot of debates over the ethics of a hypothetical &#039;good virus&#039;.  It&#039;s not hypothetical anymore. 
    </content:encoded>

    <pubDate>Tue, 19 Aug 2003 09:22:54 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/73-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>

</channel>
</rss>