|
This didn't make it through the first time, so I am sending it along
again without the content that probably tripped the filters. Matt -------- Original Message -------- IPLINKED is of course a custom filter and not a standard feature of Declude. That filter would score points on this pattern, but it wouldn't be useful in blocking these viruses on it's own because it is scored low. I haven't seen the headers for this message, but I assume there is a pattern there. The body displays the following code: http://www.auscert.org.au/render.html?it=3957 (see the body code on this page)You could pick 2 or three reliable elements and construct a combo filter using the same technique that I did with the ZOMBIE filter. In this case, you could choose "DATA="" class="moz-txt-link-rfc2396E" href="http://%5B0-9%5D">"http://[0-9]" for one filter (shorthanded), and "[0-9]:81/" for the other filter, plus maybe something from the header code which I assume has some scripting embedded within it, containing code elements that you could use reliably, and a combination of all three in a combo filter would prevent you from FPing on legitimate discussions of the virus. Note that there is presently no reason to do this right now, so it's not worth it to come up with a fully functional set of filters for this example. Matt Bill Naber wrote: Sorry about the slip of the mouse that caused the prior reply with no new message ...My question regards the comment below: "it's easy to write a filter to block something that is IP linked to port 81". Is this referring to the IPLINKED feature in JM? If so, could you provide a brief example of how to use it in this manner? I've looked through the JM archives and haven't found anything that is clear (to me) on how to use the filtering in this manner. Thanks, -Bill Naber -----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of Matt Sent: Friday, March 19, 2004 4:43 PM To: [EMAIL PROTECTED] Subject: Re: [Declude.Virus] How do we block the next Bagle? Heuristics! This was a novel, but lame attempt at exploiting a download vulnerability. This would have been 1,000 times worse if the virus dynamically provided a list of IP's from known infected computers. This can be done, and eventually it will be done. The kid writing Bagle has shown that he has some talent for coming up with new tricks, and so far he has come up with the best human engineering attempt, and new exploits for password protected files and hiding the payload outside of the E-mail. It's clear to me that a person that knows this stuff has some experience with E-mail systems and he almost definitely works for spammers. If he was to mix some human engineering with remotely hosted code, the result could be disastrous. This attempt was lame because the exploit was old, long-past patched, easily detectable, and it relied on hard coded IP's. Pete from Sniffer has been coding up new rules for this stuff (not all of his clients use Declude Virus), and if you have JunkMail Pro, it's easy to write a filter to block something that is IP linked to port 81. In the future, there will likely be little difference between what is necessary to block spam and viruses, and I could see when it might make sense to merge functionality between Declude Virus and Declude JunkMail to achieve a higher level of heuristics. Full MIME parsing in JunkMail may very well give us many useful capabilities. For now, I don't see the need as being urgent, but I've thought that such a thing as you described was possible for some time, and I've been wondering why it didn't happen. Maybe the AV scanner companies will come out with command line functionality that includes content heuristics some time in the future. FYI, I've found Declude JunkMail on my system tends to catch most all of the undetected variants that slip through in normal ZIP files early on. Matt Greg Little wrote: -- ===================================================== MailPure custom filters for Declude JunkMail Pro. http://www.mailpure.com/software/ ===================================================== |
