[iwar] New viruses in town - two seen so far today

From: Fred Cohen (fc@all.net)
Date: 2001-09-18 07:35:20


Return-Path: <sentto-279987-2015-1000823722-fc=all.net@returns.onelist.com>
Delivered-To: fc@all.net
Received: from 204.181.12.215 by localhost with POP3 (fetchmail-5.1.0) for fc@localhost (single-drop); Tue, 18 Sep 2001 07:38:08 -0700 (PDT)
Received: (qmail 2085 invoked by uid 510); 18 Sep 2001 14:36:09 -0000
Received: from n28.groups.yahoo.com (216.115.96.78) by 204.181.12.215 with SMTP; 18 Sep 2001 14:36:09 -0000
X-eGroups-Return: sentto-279987-2015-1000823722-fc=all.net@returns.onelist.com
Received: from [10.1.4.53] by f19.egroups.com with NNFMP; 18 Sep 2001 14:35:22 -0000
X-Sender: fc@big.all.net
X-Apparently-To: iwar@onelist.com
Received: (EGP: mail-7_3_2_2); 18 Sep 2001 14:35:21 -0000
Received: (qmail 22494 invoked from network); 18 Sep 2001 14:35:21 -0000
Received: from unknown (10.1.10.26) by l7.egroups.com with QMQP; 18 Sep 2001 14:35:21 -0000
Received: from unknown (HELO big.all.net) (65.0.156.78) by mta1 with SMTP; 18 Sep 2001 14:35:21 -0000
Received: (from fc@localhost) by big.all.net (8.9.3/8.7.3) id HAA02448 for iwar@onelist.com; Tue, 18 Sep 2001 07:35:21 -0700
Message-Id: <200109181435.HAA02448@big.all.net>
To: iwar@onelist.com (Information Warfare Mailing List)
Organization: I'm not allowed to say
X-Mailer: don't even ask
X-Mailer: ELM [version 2.5 PL1]
From: Fred Cohen <fc@all.net>
Mailing-List: list iwar@yahoogroups.com; contact iwar-owner@yahoogroups.com
Delivered-To: mailing list iwar@yahoogroups.com
Precedence: bulk
List-Unsubscribe: <mailto:iwar-unsubscribe@yahoogroups.com>
Date: Tue, 18 Sep 2001 07:35:20 -0700 (PDT)
Reply-To: iwar@yahoogroups.com
Subject: [iwar] New viruses in town - two seen so far today
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7bit

An email virus and a virus that tries to exploit various executable
shells left from previous viruses and other vulnerabilities have both
shown up for the first time this morning.

The email virus is an executable hiding as a mime attachment indicating
that it is a .wav file.  The second is a virus that appears to penetrate
systems through web servers and exploit remote holes in other web
servers using several different vulnerabilities.

It is very unusual for two such things to show up anew in the same day.

FC
--This communication is confidential to the parties it is intended to serve--
Fred Cohen		Fred Cohen & Associates.........tel/fax:925-454-0171
fc@all.net		The University of New Haven.....http://www.unhca.com/
http://all.net/		Sandia National Laboratories....tel:925-294-2087


------------------------ Yahoo! Groups Sponsor ---------------------~-->
Do you need to encrypt all your online transactions? Secure corporate intranets? Authenticate your Web sites? Whatever
security your site needs, you'll find the perfect solution here!
http://us.click.yahoo.com/wOMkGD/Q56CAA/yigFAA/kgFolB/TM
---------------------------------------------------------------------~->

------------------
http://all.net/ 

Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/ 



This archive was generated by hypermail 2.1.2 : 2001-09-29 21:08:44 PDT