PDA

View Full Version : spreading a virus thru OE address book


buck52
11-27-2001, 07:46 PM
Howdy

I decided I would put this here instead of in the thread going in Announcements

Might want to read these regarding the spreading of a virus thru Outlook Express address book
http://www.symantec.com/avcenter/venc/data/trick.address.book.entry.html
http://vil.nai.com/vil/virusSummary.asp?virus_k=99213

buck

------------------
just hav'n fun

sea69
11-27-2001, 09:45 PM
read it...... considered the source.... an anti-virus company, they have a product to sell.

I would point out that for as many times as they advise to ignore or not do this, they also say that it can work.

Therefore, for me, while I agree 100% that use of 'trick' is in no way a replacement for anti-virus protection, I still have yet to be convinced where it could be anything but advantageous to use it.

Further, I question the reasoning behind recommending against it.

just my 2¢

**unless- someone can explain a whole lot clearer to me why.


http://www.PCGuide.com/ubb/wink.gif


------------------
sea1_69@hotmail.com

homepage (http://www.seanweb1.homestead.com/3.html)

[This message has been edited by sea69 (edited 11-27-2001).]

YODA74
11-27-2001, 10:12 PM
I agree a hundred percent Sea, I wish my wife (CELICA) did not put my link to the artical That i had posted as a joke in with the virus comments this morning, but she has been told about the inner workings of the "0000" in fact i use it along my NAV.Sorry for creating a problem here (beyond my control) http://www.PCGuide.com/ubb/mad.gif http://www.PCGuide.com/ubb/rolleyes.gif

------------------
Treading,Troden,Trails
HERE (http://www.davematthewsband.com)

sea69
11-27-2001, 10:20 PM
"problem"??

not here

http://www.PCGuide.com/ubb/wink.gif



------------------
sea1_69@hotmail.com

homepage (http://www.seanweb1.homestead.com/3.html)


;)~

buck52
11-27-2001, 10:25 PM
I agree also...Just thought it was worth posting for you all to read http://www.PCGuide.com/ubb/smile.gif

I did apply the "trick" awhile back but have no idea if it works...I am the only one to use this machine and I open nothing before it gets scanned

buck

------------------
just hav'n fun

[This message has been edited by buck52 (edited 11-27-2001).]

ranchdog
11-27-2001, 11:04 PM
When I read/pondered those two links I thought... O.K. the A-V companies have to admit that it can work.

Every little bit helps.

Sheesh. Ain't like we're hacking thier source code or something. http://www.PCGuide.com/ubb/eek.gif

McAfee stated that consumers should'nt be using things like Address Book tricks. And we need to be using M$ patches for security.

Yeah, right . http://www.PCGuide.com/ubb/rolleyes.gif

My .05 (inflation)

------------------
......Indecision may or may not be my problem......
...... Kickin' A Rock....

[This message has been edited by ranchdog (edited 11-27-2001).]

sea69
11-27-2001, 11:10 PM
http://www.PCGuide.com/ubb/biggrin.gif hehe ranchdoggy

you noticed that too??

http://www.PCGuide.com/ubb/wink.gif



------------------
sea1_69@hotmail.com

homepage (http://www.seanweb1.homestead.com/3.html)


;)~

rond36
11-27-2001, 11:44 PM
Just wait till Pete gets over his virus and finds 9 posts in the anouncements forum! When the cat's away...LOL

------------------
Alright who messed it up this time!

[This message has been edited by rond36 (edited 11-27-2001).]

mjc
11-27-2001, 11:57 PM
Ok, what is it worth and what does it do...it forces OE to cough up an error when someone/something tries to mail the entire addressbook....hmmm sounds like a good idea to me. What does it cost....nothing. Does it replace a virus scanner....NO. Is it worth doing...'nuff said.

I don't see what the AV companies have their feathers ruffled about....Although this is technically not a hoax--in theory, it could work with a few older worms and viruses--Symantec Security Response strongly recommends that you ignore it...Also, a hacker could exploit some variants of this message to make you more susceptible to loss of confidential information (huh????)...The !0000 Hoax is mainly circulating in the Netherlands...sheesh....(it's not like someone said AV programs are really the problem or something).

For crying out loud it is just another tool, like running an AV, firewall and any other "sanctioned" line of protection.


------------------
mjc
Links list:Computer Links (http://www.dreamwater.org/tech/mjc/index.htm)

Celts are the men that heaven made mad, For all their battles are merry and their songs are all sad.

Paleo Pete
11-28-2001, 08:34 AM
I pretty much agree with the above, this trick is NOT a replacement for antivirus protection, but it should prevent a virus or trojan from spreading from an individual's computer once it is compromised.

And of course the antivirus producers don't want you to use this trick, they want your money instead...Well, they got mine long ago, but a bit of an extra preventative measure shouldn't be a bad thing...

Just wait till Pete gets over his virus and finds 9 posts in the anouncements forum! When the cat's away...LOL
Guess I got lucky, as far as I can tell my computer is clean. I checked the registry, system.ini, used Find to look for the files this one creates, none were there. I'm almost positive the email I opened carried this trojan and I'm not sure why it didn't install itself, but apparently it was not successful if it did try. I also got the newest DAT files and scanned, nothing found. (Existing DAT files were only a week old, but this one is brand spankin' new...)

The email tried to open Windows Media Player and it popped up a message concerning a redirection error. I didn't try to open the other two.




------------------
Support the right to keep and arm bears.
Note: Please post your questions on the forums, not in my email.

Computer Information Links (http://www.dreamwater.com/paleopete/computer.htm) has been moved, please update your bookmarks.

ErnieK
11-28-2001, 08:14 PM
I agree with everything said here. It is not a substute for AV software. But as has been said it is just like a, for want of a better expression, firewall for the address book. To make doubley sure that it is effective the 0000 should be mixed with aaaaa (0a00aa0) or similar. Because some idiot out there will surely try and write 0000 into a virus. Or am I just being paranoic?

------------------
Ernie

Whyzman
11-28-2001, 10:04 PM
ErnieK,

Posted this earlier today. Not paranoia, logical progression....

Well, do you think that a hacker could write code to circumvent the first address and then proceed from there....they can't be that smart?! http://www.PCGuide.com/ubb/biggrin.gif



------------------
May all your dealings in life be win/win!

Whyzman

sea69
11-28-2001, 11:05 PM
good thinking there ERNIE

bet it's been done.

http://www.PCGuide.com/ubb/wink.gif



------------------
sea1_69@hotmail.com

homepage (http://www.seanweb1.homestead.com/3.html)


;)~

Ass3mbler
12-18-2001, 08:00 AM
This is a HOAX with a capital H. If you want to stop from senidng a virus through Outlook and or Outlook Express. #1 Delete them and get Eudora, if that isn't an option #2 Disable the preview pane, #3 Download and configure Norton to scan your e-mail programs, #4 do NOT open attachements from ANYONE. This hoax has been floating around for some time and does NOT work. Take it from me as I do KNOW virii/trojans, and make my money at stopping them atleast from my ISP's point of view. I would also recomeent going to TOOLS and OPTIONS and choosing SECURITY and putting it on RESTRICTED mode as it is more secure. It is also good to recognize some of the headings of virii/trojans spread through Outlook/Outlook Express as deleting them will activate the virii/trojan such a case is the nimda worm. For my information I check mainly two sites www.norton.com (http://www.norton.com) and http://housecall.antivirus.com. If you get a virii/trojan immediatley go to the block sender option and then look up the removal directions on the norton homepage and go from there it is also important to back up your registry before making any changes as a lot of todays virii/trojans effect it. Just a few words of advice take it or leave, have to love the script kiddies, but there is some nice coding going on out there for example badtrans.

Originally posted by sea69:
good thinking there ERNIE

bet it's been done.

http://www.PCGuide.com/ubb/wink.gif





------------------
Assembler,

Bow before me for I am r00t

mjc
12-18-2001, 11:45 AM
Ass3mbler,

I tend to disagree with you about it being a hoax, it (the dead end address),misrepresented in what it can do--yes, it is not and should not be anyone's first line of defense against infection, but as far as being able to stop some malware from spreading, it does have a benefit. It is like covering you mouth when you sneeze, no it isn't going to help you get over the cold, but it just may help prevent someone else from getting it. It is also, small, free and does no harm being there (heck, it will also protect some users from accidentally sending the same thing to everyone...), but above all it is not and should not be considered the only protection against malware (especially trojans), but more like the hankie when you sneeze!

------------------
mjc
Links list:Computer Links (http://www.dreamwater.org/tech/mjc/index.htm)

Celts are the men that heaven made mad, For all their battles are merry and their songs are all sad.

Ass3mbler
12-18-2001, 09:32 PM
If you have got the little trick to work more power to you, I have tried both at work and here at home on my PC and it doesn't work. If you want a more reilable FREE way to protect your machine against all virii/troajns. I would recommend and have to many of the customers of my ISP going to Trend Micro,http://housecall.anitvirus.com. There you can click on scan w/o registering, it is in the first paragraph. After that it will take you to a page that ask you to choose your country of origin, do this and click go. The next step in the process may take a few minutes as the server is scanning your machine to gather information. After that is done it will take you to another page, there you need to click inside My Computer until all the drives have a green check mark in them. Then you need to click on the Auto Fix and put a checkmark in there and click Auto Scan. Voolaaa it will scan your enitre computer, report any virii/trojans that you may have and any reslotuions in either getting rid of them or fixing them. As a bonus you receive PCillin (sp) from Trend-Micro. I have used this for years as a back up to my Norton and am very pleased with it.

Originally posted by mjc:
Ass3mbler,

I tend to disagree with you about it being a hoax, it (the dead end address),misrepresented in what it can do--yes, it is not and should not be anyone's first line of defense against infection, but as far as being able to stop some malware from spreading, it does have a benefit. It is like covering you mouth when you sneeze, no it isn't going to help you get over the cold, but it just may help prevent someone else from getting it. It is also, small, free and does no harm being there (heck, it will also protect some users from accidentally sending the same thing to everyone...), but above all it is not and should not be considered the only protection against malware (especially trojans), but more like the hankie when you sneeze!





------------------
Assembler,

Bow before me for I am r00t