Exactly, if the servers are known, why doesn't the upstream providers be pro-active and block those ip's from being accessed ?
---------- Original Message ---------------------------------- From: "Andy Schmidt" <[EMAIL PROTECTED]> Reply-To: [EMAIL PROTECTED] Date: Fri, 22 Aug 2003 14:20:53 -0400 >No only that - but what's this "web address" that will be updated. > >If it's an IP - then it should be easy to contact the upstream provider. > >If it's a FQDN - then it should be easy for the registrar to "lock" this >particular domain against updates > >I don't see why this is supposedly so difficult to accomplish? > >Best Regards >Andy Schmidt > >H&M Systems Software, Inc. >600 East Crescent Avenue, Suite 203 >Upper Saddle River, NJ 07458-1846 > >Phone: +1 201 934-3414 x20 (Business) >Fax: +1 201 934-9206 > >http://www.HM-Software.com/ > > >-----Original Message----- >From: [EMAIL PROTECTED] >[mailto:[EMAIL PROTECTED] On Behalf Of Mark Smith >Sent: Friday, August 22, 2003 01:23 PM >To: [EMAIL PROTECTED] >Subject: RE: [Declude.Virus] Sobig- Phase II bombardment > > >"The worm connects to one of these 20 servers and authenticates itself with >a secret 8-byte code. The servers respond with a web address. Infected >machines download a program from this address - and run it. At this moment <<snipped>> -- Avolve Support Get High Speed Internet - Go Wireless ! http://www.avolvewireless.net -- --- [This E-mail scanned for viruses by Declude Virus By Avolve.net] --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". The archives can be found at http://www.mail-archive.com.
