logo Welcome, Guest. Please Login or Register.
2024-05-11 06:25:31 CoV Wiki
Learn more about the Church of Virus
Home Help Search Login Register
News: Read the first edition of the Ideohazard

  Church of Virus BBS
  Mailing List
  Virus 2004

  virus: could we get it off of our CoV chat server
« previous next »
Pages: [1] Reply Notify of replies Send the topic Print 
   Author  Topic: virus: could we get it off of our CoV chat server  (Read 915 times)
Walter Watts
Archon
*****

Gender: Male
Posts: 1571
Reputation: 8.88
Rate Walter Watts



Just when I thought I was out-they pull me back in

View Profile WWW E-Mail
virus: could we get it off of our CoV chat server
« on: 2004-03-23 17:16:34 »
Reply with quote

Does this propagate only on IRC servers and if so, could we get it off
of our CoV chat server.

malware.bkdr_ircflood.x



--

Walter Watts
Tulsa Network Solutions, Inc.

"Pursue the small utopias... nature, music, friendship, love"
--Kupferberg--


---
To unsubscribe from the Virus list go to <http://www.lucifer.com/cgi-bin/virus-l>

Report to moderator   Logged

Walter Watts
Tulsa Network Solutions, Inc.


No one gets to see the Wizard! Not nobody! Not no how!
Walter Watts
Archon
*****

Gender: Male
Posts: 1571
Reputation: 8.88
Rate Walter Watts



Just when I thought I was out-they pull me back in

View Profile WWW E-Mail
Re: virus: could we get it off of our CoV chat server
« Reply #1 on: 2004-03-23 19:40:49 »
Reply with quote

Sorry, it was mIRC's problem. Reinfection occurs until you do the crap outlined here:

http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?vname=bkdr_ircflood.y&vsect=t

Walter
<who will be busy doing this on TWO pc's in time for tonight's chat, so I don't have
to use the BBS interface>

<<any suggestions on secure IRC clients, or is there such a thing>>

Walter

Walter Watts wrote:

> Does this propagate only on IRC servers and if so, could we get it off
> of our CoV chat server.
>
> malware.bkdr_ircflood.x
>
> --
>
> Walter Watts
> Tulsa Network Solutions, Inc.
>
> "Pursue the small utopias... nature, music, friendship, love"
> --Kupferberg--
>
> ---
> To unsubscribe from the Virus list go to <http://www.lucifer.com/cgi-bin/virus-l>

--

Walter Watts
Tulsa Network Solutions, Inc.

"Pursue the small utopias... nature, music, friendship, love"
--Kupferberg--


---
To unsubscribe from the Virus list go to <http://www.lucifer.com/cgi-bin/virus-l>

Report to moderator   Logged

Walter Watts
Tulsa Network Solutions, Inc.


No one gets to see the Wizard! Not nobody! Not no how!
rhinoceros
Archon
*****

Gender: Male
Posts: 1318
Reputation: 8.34
Rate rhinoceros



My point is ...

View Profile WWW E-Mail
Re:virus: could we get it off of our CoV chat server
« Reply #2 on: 2004-03-23 20:18:41 »
Reply with quote

[Walter]
Sorry, it was mIRC's problem. Reinfection occurs until you do the crap outlined here:

http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?vname=bkdr_ircflood.y&vsect=t

Walter
<who will be busy doing this on TWO pc's in time for tonight's chat, so I don't have
to use the BBS interface>


[rhinoceros]
How the hell did you get infected? I wonder... is it possible to get infected, even if you accept all DCC, if you don't run any executable file that you downloaded? Did you accept candy err... a script from a stranger or what?

Myself, I have been using VIRC, which seems pretty neat, and I never had any problem -- or if I had one it was never reported

Report to moderator   Logged
Walter Watts
Archon
*****

Gender: Male
Posts: 1571
Reputation: 8.88
Rate Walter Watts



Just when I thought I was out-they pull me back in

View Profile WWW E-Mail
Re: virus: could we get it off of our CoV chat server
« Reply #3 on: 2004-03-24 01:13:17 »
Reply with quote

Thanks, rhino. I wish I had read this 4 hours earlier and I wouldn't have wasted 3.5 hours on Trillian    ;->  What a giant hairball!

I really like the VIRC. It's like a tighter, simpler, leaner mIRC without malware problems.

It's what I'll be using.

Thanks,
Walter

rhinoceros wrote:

> [Walter]
> Sorry, it was mIRC's problem. Reinfection occurs until you do the crap outlined here:
>
> http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?vname=bkdr_ircflood.y&vsect=t
>
> Walter
> <who will be busy doing this on TWO pc's in time for tonight's chat, so I don't have
> to use the BBS interface>
>
> [rhinoceros]
> How the hell did you get infected? I wonder... is it possible to get infected, even if you accept all DCC, if you don't run any executable file that you downloaded? Did you accept candy err... a script from a stranger or what?
>
> Myself, I have been using VIRC, which seems pretty neat, and I never had any problem -- or if I had one it was never reported
>
> ----
> This message was posted by rhinoceros to the Virus 2004 board on Church of Virus BBS.
> <http://virus.lucifer.com/bbs/index.php?board=61;action=display;threadid=30078>
> ---
> To unsubscribe from the Virus list go to <http://www.lucifer.com/cgi-bin/virus-l>

--

Walter Watts
Tulsa Network Solutions, Inc.

"Pursue the small utopias... nature, music, friendship, love"
--Kupferberg--


---
To unsubscribe from the Virus list go to <http://www.lucifer.com/cgi-bin/virus-l>

Report to moderator   Logged

Walter Watts
Tulsa Network Solutions, Inc.


No one gets to see the Wizard! Not nobody! Not no how!
Walter Watts
Archon
*****

Gender: Male
Posts: 1571
Reputation: 8.88
Rate Walter Watts



Just when I thought I was out-they pull me back in

View Profile WWW E-Mail
Re: virus: could we get it off of our CoV chat server
« Reply #4 on: 2004-03-24 01:17:46 »
Reply with quote

Because I bragged about never having a computer virus yesterday.

Walter
<HUMBLED and looking at resident antivirus software reviews>

rhinoceros wrote:

> How the hell did you get infected? I wonder... is it possible to get infected, even if you accept all DCC, if you don't run any executable file that you downloaded? Did you accept candy err... a script from a stranger or what?
>

--

Walter Watts
Tulsa Network Solutions, Inc.

"Pursue the small utopias... nature, music, friendship, love"
--Kupferberg--


---
To unsubscribe from the Virus list go to <http://www.lucifer.com/cgi-bin/virus-l>

Report to moderator   Logged

Walter Watts
Tulsa Network Solutions, Inc.


No one gets to see the Wizard! Not nobody! Not no how!
rhinoceros
Archon
*****

Gender: Male
Posts: 1318
Reputation: 8.34
Rate rhinoceros



My point is ...

View Profile WWW E-Mail
Re: virus: could we get it off of our CoV chat server
« Reply #5 on: 2004-03-24 04:36:36 »
Reply with quote

[Walter]
Thanks, rhino. I wish I had read this 4 hours earlier and I wouldn't
have wasted 3.5 hours on Trillian    ;->  What a giant hairball!

I really like the VIRC. It's like a tighter, simpler, leaner mIRC
without malware problems.


[rhinoceros]
In fact VIRC (http://www.visualirc.net) was Hermit's suggestion, and it
was the first one I ever used and the only one I ever needed.

Lately the more techie guys in #virus suggest another program called
HydraIRC (http://www.hydrairc.com/). So, if you feel lucky you may want
to learn a fifth one


____________________________________________________________________
http://www.freemail.gr - δωρεάν υπηρεσία ηλεκτρονικού ταχυδρομείου.
http://www.freemail.gr - free email service for the Greek-speaking.
---
To unsubscribe from the Virus list go to <http://www.lucifer.com/cgi-bin/virus-l>

Report to moderator   Logged
simul
Adept
****

Gender: Male
Posts: 614
Reputation: 7.85
Rate simul



I am a lama.
simultaneous zoneediterik
View Profile WWW
Re: virus: could we get it off of our CoV chat server
« Reply #6 on: 2004-03-24 08:38:29 »
Reply with quote

I've never had a problem with Trillian.  I'l look at VIRC though.
---
To unsubscribe from the Virus list go to <http://www.lucifer.com/cgi-bin/virus-l>

Report to moderator   Logged

First, read Bruce Sterling's "Distraction", and then read http://electionmethods.org.
simul
Adept
****

Gender: Male
Posts: 614
Reputation: 7.85
Rate simul



I am a lama.
simultaneous zoneediterik
View Profile WWW
Re: virus: could we get it off of our CoV chat server
« Reply #7 on: 2004-03-24 08:42:13 »
Reply with quote

One way to get infected is to run active-x controls on a web page, which are inherently insecure.  Another is to use a program, like outlook express, that autoruns scripts by default.

I wrote a web page detailing some basic windows security measures:

http://www.zoneedit.com/msvirus.html
---
To unsubscribe from the Virus list go to <http://www.lucifer.com/cgi-bin/virus-l>

Report to moderator   Logged

First, read Bruce Sterling's "Distraction", and then read http://electionmethods.org.
Walter Watts
Archon
*****

Gender: Male
Posts: 1571
Reputation: 8.88
Rate Walter Watts



Just when I thought I was out-they pull me back in

View Profile WWW E-Mail
Re: virus: could we get it off of our CoV chat server
« Reply #8 on: 2004-03-24 15:01:16 »
Reply with quote

Outstanding advice, Erik. I guess one reason I've never had a virus until now was I still use Netscape's email, an old ver. 4.7. Been browsing with IE for a long time and will lock it
down now according to your instructions:
"4. How To Lock Down Your System".

I use Windows update regularly on both machine (98SE & XP Pro), but I only get critical updates.

Also, I have a Linksys 4 port Cable/DSL ROUTER between my lan and the net, but not a firewall. Are there some settings in the router I need to tighten up on?

Thanks alot for your advice,
Walter

Erik Aronesty wrote:

> One way to get infected is to run active-x controls on a web page, which are inherently insecure.  Another is to use a program, like outlook express, that autoruns scripts by default.
>
> I wrote a web page detailing some basic windows security measures:
>
> http://www.zoneedit.com/msvirus.html
> ---
> To unsubscribe from the Virus list go to <http://www.lucifer.com/cgi-bin/virus-l>

--

Walter Watts
Tulsa Network Solutions, Inc.

"Pursue the small utopias... nature, music, friendship, love"
--Kupferberg--


---
To unsubscribe from the Virus list go to <http://www.lucifer.com/cgi-bin/virus-l>

Report to moderator   Logged

Walter Watts
Tulsa Network Solutions, Inc.


No one gets to see the Wizard! Not nobody! Not no how!
Bill Mackinnon
Neophyte
**

Posts: 43
Reputation: 0.00



I love YaBB SE!

View Profile
Re: virus: could we get it off of our CoV chat server
« Reply #9 on: 2004-03-24 16:19:55 »
Reply with quote

[[ author reputation (0.00) beneath threshold (3)... display message ]]

Report to moderator   Logged
JD
Adept
****

Gender: Male
Posts: 542
Reputation: 7.32
Rate JD





View Profile
RE: virus: could we get it off of our CoV chat server
« Reply #10 on: 2004-03-24 19:22:19 »
Reply with quote

Hi Walter,

Sorry to hear about your recent troubles old dog. I know Sebby is behind it.
It is because of those unkind comments you made about his night driving.

Look, have you tried Opera? I rate it s the absolute best browser and many
swear that its mail client is magnificent too. Also, it has a beautiful IRC
interface (see
http://www.limbicnutrition.com/images/misc/walter_scr_shot.jpg - skin is
called "Fresh").

Incidentally, very good security primer Erik. Thanks.

Fond regards

Jonathan

-----Original Message-----
From: owner-virus@lucifer.com [mailto:owner-virus@lucifer.com] On Behalf Of
Walter Watts
Sent: 24 March 2004 20:01
To: virus@lucifer.com
Subject: Re: virus: could we get it off of our CoV chat server

Outstanding advice, Erik. I guess one reason I've never had a virus until
now was I still use Netscape's email, an old ver. 4.7. Been browsing with IE
for a long time and will lock it down now according to your instructions:
"4. How To Lock Down Your System".

I use Windows update regularly on both machine (98SE & XP Pro), but I only
get critical updates.

Also, I have a Linksys 4 port Cable/DSL ROUTER between my lan and the net,
but not a firewall. Are there some settings in the router I need to tighten
up on?

Thanks alot for your advice,
Walter

Erik Aronesty wrote:

> One way to get infected is to run active-x controls on a web page, which
are inherently insecure.  Another is to use a program, like outlook express,
that autoruns scripts by default.
>
> I wrote a web page detailing some basic windows security measures:
>
> http://www.zoneedit.com/msvirus.html
> ---
> To unsubscribe from the Virus list go to
> <http://www.lucifer.com/cgi-bin/virus-l>

--

Walter Watts
Tulsa Network Solutions, Inc.

"Pursue the small utopias... nature, music, friendship, love"
--Kupferberg--


---
To unsubscribe from the Virus list go to
<http://www.lucifer.com/cgi-bin/virus-l>

---
To unsubscribe from the Virus list go to <http://www.lucifer.com/cgi-bin/virus-l>

Report to moderator   Logged
Walter Watts
Archon
*****

Gender: Male
Posts: 1571
Reputation: 8.88
Rate Walter Watts



Just when I thought I was out-they pull me back in

View Profile WWW E-Mail
Re: virus: could we get it off of our CoV chat server
« Reply #11 on: 2004-03-24 20:30:59 »
Reply with quote

Thanks, Jonathan.
    I've heard many good things about Opera. I'll check it out. Nice to hear from
you.

Your Okie bud,
Walter


Jonathan Davis wrote:

> Hi Walter,
>
> Sorry to hear about your recent troubles old dog. I know Sebby is behind it.

<snip>
--

Walter Watts
Tulsa Network Solutions, Inc.

"Pursue the small utopias... nature, music, friendship, love"
--Kupferberg--


---
To unsubscribe from the Virus list go to <http://www.lucifer.com/cgi-bin/virus-l>

Report to moderator   Logged

Walter Watts
Tulsa Network Solutions, Inc.


No one gets to see the Wizard! Not nobody! Not no how!
DrSebby
Archon
***

Gender: Male
Posts: 456
Reputation: 8.07
Rate DrSebby



...Oh, you smell of lambs!
18680476 18680476    dr_sebby drsebby
View Profile WWW E-Mail
RE: virus: could we get it off of our CoV chat server
« Reply #12 on: 2004-03-25 22:10:13 »
Reply with quote

...as it turns out i DID have a virus!!!  something called "Duster_a" or
some such thing.  it's been cleaned.  not sure if it was responsible for
anything, but i'm hoping not.  it didnt have much effect on my end anyways. 
i can credit Kazaa and a certain screenwriting program for it....though i
might add that the program works wonderfully.



DrSebby.
"Courage...and shuffle the cards".





----Original Message Follows----
From: "Jonathan Davis" <jonathan.davis@lineone.net>
Reply-To: virus@lucifer.com
To: <virus@lucifer.com>
Subject: RE: virus: could we get it off of our CoV chat server
Date: Thu, 25 Mar 2004 00:22:19 -0000

Hi Walter,

Sorry to hear about your recent troubles old dog. I know Sebby is behind it.
It is because of those unkind comments you made about his night driving.

Look, have you tried Opera? I rate it s the absolute best browser and many
swear that its mail client is magnificent too. Also, it has a beautiful IRC
interface (see
http://www.limbicnutrition.com/images/misc/walter_scr_shot.jpg - skin is
called "Fresh").

Incidentally, very good security primer Erik. Thanks.

Fond regards

Jonathan

-----Original Message-----
From: owner-virus@lucifer.com [mailto:owner-virus@lucifer.com] On Behalf Of
Walter Watts
Sent: 24 March 2004 20:01
To: virus@lucifer.com
Subject: Re: virus: could we get it off of our CoV chat server

Outstanding advice, Erik. I guess one reason I've never had a virus until
now was I still use Netscape's email, an old ver. 4.7. Been browsing with IE
for a long time and will lock it down now according to your instructions:
"4. How To Lock Down Your System".

I use Windows update regularly on both machine (98SE & XP Pro), but I only
get critical updates.

Also, I have a Linksys 4 port Cable/DSL ROUTER between my lan and the net,
but not a firewall. Are there some settings in the router I need to tighten
up on?

Thanks alot for your advice,
Walter

Erik Aronesty wrote:

> One way to get infected is to run active-x controls on a web page, which
are inherently insecure.  Another is to use a program, like outlook express,
that autoruns scripts by default.
>
> I wrote a web page detailing some basic windows security measures:
>
> http://www.zoneedit.com/msvirus.html
> ---
> To unsubscribe from the Virus list go to
> <http://www.lucifer.com/cgi-bin/virus-l>

--

Walter Watts
Tulsa Network Solutions, Inc.

"Pursue the small utopias... nature, music, friendship, love"
--Kupferberg--


---
To unsubscribe from the Virus list go to
<http://www.lucifer.com/cgi-bin/virus-l>

---
To unsubscribe from the Virus list go to
<http://www.lucifer.com/cgi-bin/virus-l>

_________________________________________________________________
The new MSN 8: smart spam protection and 2 months FREE* 
http://join.msn.com/?page=features/junkmail

---
To unsubscribe from the Virus list go to <http://www.lucifer.com/cgi-bin/virus-l>

Report to moderator   Logged

"courage and shuffle the cards..."
simul
Adept
****

Gender: Male
Posts: 614
Reputation: 7.85
Rate simul



I am a lama.
simultaneous zoneediterik
View Profile WWW
Re: virus: could we get it off of our CoV chat server
« Reply #13 on: 2004-03-28 12:48:56 »
Reply with quote

Regarding your Linksys...  don't use the DMZ setting.

Instead, permission each service explicitly using port forwarding.

------Original Message------
From: Walter Watts
Sender: owner-virus@lucifer.com
To: Church of Virus
ReplyTo: Church of Virus
Sent: Mar 24, 2004 3:01 PM
Subject: Re: virus: could we get it off of our CoV chat server

Outstanding advice, Erik. I guess one reason I've never had a virus until now was I still use Netscape's email, an old ver. 4.7. Been browsing with IE for a long time and will lock it
down now according to your instructions:
"4. How To Lock Down Your System".

I use Windows update regularly on both machine (98SE & XP Pro), but I only get critical updates.

Also, I have a Linksys 4 port Cable/DSL ROUTER between my lan and the net, but not a firewall. Are there some settings in the router I need to tighten up on?

Thanks alot for your advice,
Walter

Erik Aronesty wrote:

> One way to get infected is to run active-x controls on a web page, which are inherently insecure.  Another is to use a program, like outlook express, that autoruns scripts by default.
>
> I wrote a web page detailing some basic windows security measures:
>
> http://www.zoneedit.com/msvirus.html
> ---
> To unsubscribe from the Virus list go to <http://www.lucifer.com/cgi-bin/virus-l>

--

Walter Watts
Tulsa Network Solutions, Inc.

"Pursue the small utopias... nature, music, friendship, love"
--Kupferberg--


---
To unsubscribe from the Virus list go to <http://www.lucifer.com/cgi-bin/virus-l>


---
To unsubscribe from the Virus list go to <http://www.lucifer.com/cgi-bin/virus-l>

Report to moderator   Logged

First, read Bruce Sterling's "Distraction", and then read http://electionmethods.org.
Walter Watts
Archon
*****

Gender: Male
Posts: 1571
Reputation: 8.88
Rate Walter Watts



Just when I thought I was out-they pull me back in

View Profile WWW E-Mail
Re: virus: could we get it off of our CoV chat server
« Reply #14 on: 2004-03-28 14:39:57 »
Reply with quote

Thanks, I've always kept that option off.

I sent the following to the webmaster at Hollywood Video's site. Feel free to cut 'n paste it and use it often. Just change a couple of variables.
------------------------------------

Looking for a title I got "%JavaScript% is required to see this menu"
It's not required to search %BLOCKBUSTER'S% titles.  :-p
It's a security issue. I don't know you, so why would I put you in my "trusted sites" zone?
It's not necessary to run %javascripts% or %active-x-scripts% to run an effective commercial website.

Get a clue.

A former customer
------------------------------------

Erik Aronesty wrote:

> Regarding your Linksys...  don't use the DMZ setting.
> <snip>

--

Walter Watts
Tulsa Network Solutions, Inc.

"Pursue the small utopias... nature, music, friendship, love"
--Kupferberg--


---
To unsubscribe from the Virus list go to <http://www.lucifer.com/cgi-bin/virus-l>

Report to moderator   Logged

Walter Watts
Tulsa Network Solutions, Inc.


No one gets to see the Wizard! Not nobody! Not no how!
Pages: [1] Reply Notify of replies Send the topic Print 
Jump to:


Powered by MySQL Powered by PHP Church of Virus BBS | Powered by YaBB SE
© 2001-2002, YaBB SE Dev Team. All Rights Reserved.

Please support the CoV.
Valid HTML 4.01! Valid CSS! RSS feed