Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [Full-disclosure] Urgent Alert: Possible BlackWorm DDay February3rd (Snort signatures included) |
|---|---|
| Date: | Tue, 24 Jan 2006 14:26:21 -0500 |
this one also spreads via network shares, then creates an AT job that will run itself on the 59th minute of every hour to further propigate. very worm like if you ask me. exibar ----- Original Message ----- From: "Dude VanWinkle" <dudevanwinkle@gmail.com> To: "Gadi Evron" <ge@linuxbox.org> Cc: <funsec@linuxbox.org>; <full-disclosure@lists.grok.org.uk>; <bugtraq@securityfocus.com> Sent: Tuesday, January 24, 2006 1:52 PM Subject: Re: [Full-disclosure] Urgent Alert: Possible BlackWorm DDay February3rd (Snort signatures included) On 1/24/06, Gadi Evron <ge@linuxbox.org> wrote:
now known as the TISF BlackWorm task force.
Why do you call a .scr you have to manually install a "worm"? Why not "BlackVirus" the worm moniker is very misleading (actually got me worried for a sec). The "email worm" is also misleading, because it only propagates through port 25, but that is not the point of entry. The point of entry is the user running a visual basic script _willingly_. Just so I know, what would you guys classify a real worm (blaster, slammer, nimda, etc) as? Or would you just call it an "internet worm" instead of an "email worm" and leave it at that? thanks for the mis-info, -JP "still love ja tho" -JP _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/ _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Full-disclosure] What A Click! [Internet Explorer], mikx |
|---|---|
| Next by Date: | Re: [Full-disclosure] Urgent Alert: Possible BlackWorm DDay February3rd (Snort signatures included), mjcarter |
| Previous by Thread: | Re: [Full-disclosure] Urgent Alert: Possible BlackWorm DDay February 3rd (Snort signatures included), Dude VanWinkle |
| Next by Thread: | Re: [Full-disclosure] Urgent Alert: Possible BlackWorm DDay February 3rd (Snort signatures included), Holger van Lengerich |
| Indexes: | [Date] [Thread] [Top] [All Lists] |