Re: Warning Worm/MyDoom.A1 spreading very fast!

This is a discussion on Re: Warning Worm/MyDoom.A1 spreading very fast! within the mailing.postfix.users forums, part of the Mail Servers and Related category; Ralf Hildebrandt wrote: > * Michael 'Moose' Dinn <dinn@blend.twistedpair.ca>: > >>I'm using this: &...


Go Back   Usenet Forums > Mail Servers and Related > mailing.postfix.users

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 01-27-2004
David Landgren
 
Posts: n/a
Default Re: Warning Worm/MyDoom.A1 spreading very fast!

Ralf Hildebrandt wrote:

> * Michael 'Moose' Dinn <dinn@blend.twistedpair.ca>:
>
>>I'm using this:
>>
>>/filename="(document|readme|doc|text|file|data|test |message|body).(pif|scr|exe|cmd|bat|zip)"/ REJECT
>>infected with W32.MyDoom.A

>
>
> Must of course be:
>
> /filename="?(document|readme|doc|text|file|data|tes t|message|body)\.(pif|scr|exe|cmd|bat|zip)"?/
> REJECT infected with W32.MyDoom.A


Is it always filename= ? I played it safe and used the following (nb:
this is in pcre format):

/\b(?:file)?name\s*=\s*"?(?:body|data|doc(?:ument)? |file|message|readme|te[sx]t)\.zip\b/
REJECT Suspected W32.MyDoom.A/W32.Novarg.A@mm worm in zip attachment

I'm already blocking the other extensions earlier on, so I wasn't
worried about them.

During the last virus outbreak delivered in .zip files, I had the
following rule active:

/\b(file)?name\s*=\s*"?[^.]+\.zip\b/ HOLD zip hold

It's usually commented out, but I reactivated it this morning.

What I was really hoping for though when I asked for a recipe was that
someone had found a reliable character string for a body check that
would allow the message to be discarded. IIRC, it was Victor Duchovni
who cooked up a regexp for safely discarding Sven; I was wondering if
anyone had anything for MyDoom. Right now I'm just spamming innocent
victims with REJECT.

David

--
Commercial OS breeds commerce, whereas free OS breeds freedom,
the only thing more dangerous and confusing than commerce.
-- Michael R. Jinks, redhat-list, circa 1997

Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 04:16 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0