Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Disguised worm evades antivirus software
CNN.com ^ | August 2, 2003

Posted on 08/02/2003 11:00:18 AM PDT by Sweet_Sunflower29

Edited on 04/29/2004 2:02:54 AM PDT by Jim Robinson. [history]

Computer experts have warned of a computer worm that takes advantage of a flaw in Microsoft's Internet Explorer browser.

The latest problem is called "worm/MiMail.A," also known as W32.Mimail.A@mm.

It's a mass-mailing Internet worm that started spreading late Friday afternoon, and according to Central Command, a computer security company, caught many computer systems administrators by surprise.


(Excerpt) Read more at cnn.com ...


TOPICS: Crime/Corruption; Culture/Society; Miscellaneous; News/Current Events; Technical
KEYWORDS: techindex; worms

1 posted on 08/02/2003 11:00:18 AM PDT by Sweet_Sunflower29
[ Post Reply | Private Reply | View Replies]

To: Sweet_Sunflower29
My company has been getting slammed with this thing. Its amazing, no matter how many times we tell users not to open attachments, sure enough..
2 posted on 08/02/2003 11:07:55 AM PDT by paul544 (3D-Joy OH Boy!!!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: paul544
Scripts which open the attachments automatically can be embedded in IE-based email clients.
3 posted on 08/02/2003 11:10:56 AM PDT by Jeff Chandler (This tagline has been suspended or banned.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Sweet_Sunflower29
I saw this mentioned late last week, and updated my OS and anti-virus profiles this morning. Additionally, I never open ANY executable I receive in email, no matter where it comes from.
4 posted on 08/02/2003 11:10:59 AM PDT by strela ("Each of us can find a maggot in our past which will happily devour our futures." Horatio Hornblower)
[ Post Reply | Private Reply | To 1 | View Replies]

To: paul544
A guy I work with had the habit of opening every attachment. After the 4th time he infected the network, we threatended to disconnect him from the network.
5 posted on 08/02/2003 11:13:56 AM PDT by Chancellor Palpatine (it's posts like yours that are killing FR and driving away the base [ /whining paleo impersonation ])
[ Post Reply | Private Reply | To 2 | View Replies]

To: strela
Especially ZIP files. Even in the '80's, malicious virus senders would deliberately archive a virus along with a document or picture.

ZIP, exe,scr,pif,com,vb, and all Base 64 are Kill On Site on my server. If someone wants to send me something, they will write me first.

6 posted on 08/02/2003 11:15:15 AM PDT by Gorzaloon (Contents may have settled during shipping, but this tagline contains the stated product weight.)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Sweet_Sunflower29; *tech_index; MizSterious; shadowman99; Sparta; freedom9; martin_fierro; ...
Thanks for posting this!

OFFICIAL BUMP(TOPIC)LIST

7 posted on 08/02/2003 11:22:59 AM PDT by Ernest_at_the_Beach (All we need from a Governor is a VETO PEN!!!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Gorzaloon
ZIP, exe,scr,pif,com,vb, and all Base 64 are Kill On Site on my server. If someone wants to send me something, they will write me first.

A wise policy.

8 posted on 08/02/2003 11:27:32 AM PDT by strela ("Each of us can find a maggot in our past which will happily devour our futures." Horatio Hornblower)
[ Post Reply | Private Reply | To 6 | View Replies]

To: Gorzaloon
Ditto on ours. Firewall strips them before they ever get to the virus checker. We have one isolated address where we can have such a file sent and accepted but only after receiving clearance from us for it to be sent.
9 posted on 08/02/2003 11:35:54 AM PDT by NerdDad
[ Post Reply | Private Reply | To 6 | View Replies]

To: Sweet_Sunflower29
I had five of those on my pc (home, not networked). Norton didn't catch them coming in but did in a scan. They were all zip files and I don't open attachments so I guess I'm safe.

That's a first for me so it might behoove all to run a scan.

10 posted on 08/02/2003 11:38:03 AM PDT by decimon
[ Post Reply | Private Reply | To 1 | View Replies]

To: Sweet_Sunflower29
FWIW, I loaded the latest Norton Antivirus definitions last night (8/1) and W32.Mimail.A@mm is covered.

Here^ is NAV's specific info on this virus (includes a link to Microsloth for the patch).

11 posted on 08/02/2003 4:41:30 PM PDT by upchuck (A living example of the Peter Principle since 1983.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Sweet_Sunflower29
Yet another worm courtesy of Micro$loth crapware.

Color me oh-so-UNsurprised.

-Jay
12 posted on 08/02/2003 7:49:27 PM PDT by Jay D. Dyson (But I can't get nothin' that can be bought, so I'll just live with what I got... Lord, forgive me.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Sweet_Sunflower29
CERT advisory is here: http://www.cert.org/incident_notes/IN-2003-02.html.

Ho-hum... another Microsoft patch for another worm.

13 posted on 08/02/2003 8:31:20 PM PDT by TechJunkYard (because... so much is riding on your wires.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Sweet_Sunflower29
When do we finally bring out the firing squads and fix this problem once and for all?
14 posted on 08/02/2003 9:21:19 PM PDT by RichardW
[ Post Reply | Private Reply | To 1 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson