David,

Information such as this is best 'pushed' rather than 'pulled'.  Declude should have a notification list that sends announcements of important things concerning all products such as new interims/betas/releases, new and important bugs, updates on known issues and things that can broadly affect customers such as issues like this one.  I wouldn't expect more than a few messages per month.  There was an earlier list that was to be reserved for the absolute biggest issues that never got used, and the specificity of that list was it's downfall.  I would create a list and opt all customers into it but give them an opt-out message for the first mailing.  Most Declude customers will never hear about things like this issue with McAfee otherwise.  The site doesn't work at all for timely things such as this.

BTW, I believe there are probably scripts linked to or contained on the Declude site for McAfee updates.  You will want to change those before anyone new adds it in to their system.

Thanks,

Matt





David Barker wrote:
I have been monitoring everything that has been said and I agree -  there is a place I had setup on the front page for these kinds of alerts and currently working on the best way to provide this information to our customer base using that area on the website.

David B   


From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] On Behalf Of Matt
Sent: Monday, September 12, 2005 3:58 PM
To: [email protected]
Subject: Re: [Declude.Virus] McAfee DailyDAT download location change.

I changed the subject so that people can be alerted to this.  Announcements of things like this would be useful to the entire Declude customer base.  I am afraid that we are a little over a month behind.  Those with a single scanner would be screwed.

I adjusted my scripts to use the link that you provided and it does in fact work just great...so far :)

Thanks,

Matt



Scott Fisher wrote:
Great catch Matt.
Mine's gone too since August 2....
Thank you Declude for multiple virus scanner option.
 
Try:
 
From:
 
 
----- Original Message -----
From: Matt
Sent: Monday, September 12, 2005 2:26 PM
Subject: Re: [Declude.Virus] Seemingly bad virus this morning

This is a new Bagel variant:

    http://vil.nai.com/vil/content/v_129588.htm

I was wrong about what was detecting it first...it was F-Prot.  I just figured out that my McAfee update script is no longer working.  Does anyone have a newer link to the daily DAT's than http://download.nai.com/products/mcafee-avert/daily_dats/DailyDAT.zip.

Thanks,

Matt



John Tolmachoff (Lists) wrote:
OK, so it is cpl file, which we should all have in our list of banned
extensions including banned if within a zip file, so we should all be safe,
correct?

John T
eServices For You


  
-----Original Message-----
From: [EMAIL PROTECTED]
    
[mailto:[EMAIL PROTECTED]]
  
On Behalf Of Dan Geiser
Sent: Monday, September 12, 2005 11:49 AM
To: [email protected]
Subject: Re: [Declude.Virus] Seemingly bad virus this morning

I opened the zip file and it contained one file called "1.cpl" (without
    
the
  
quotes).  Some sort of malicious Control Panel applet?

----- Original Message -----
From: "John Tolmachoff (Lists)" <[EMAIL PROTECTED]>
To: <[email protected]>
Sent: Monday, September 12, 2005 11:55 AM
Subject: RE: [Declude.Virus] Seemingly bad virus this morning


    
What is the payload inside the zip?

John T
eServices For You


      
-----Original Message-----
From: [EMAIL PROTECTED]
        
[mailto:[EMAIL PROTECTED]]
      
On Behalf Of Matt
Sent: Monday, September 12, 2005 7:52 AM
To: [email protected]
Subject: [Declude.Virus] Seemingly bad virus this morning

FYI, We found a rapidly spreading zip virus beginning at about 8:15
        
a.m.
  
this morning, first coming from Eastern Europe.  McAfee seems to be
detecting all of them now, but F-Prot as of this moment is not on our
system.  Every attachment name seemingly contained the word "price".
Here's a quick filter that I had put together for it:

HEADERS        END    NOTCONTAINS    boundary="--------
BODY        END    NOTCONTAINS    attachment; filename="
BODY        END    NOTCONTAINS    .zip" Content-Transfer-Encoding
BODY        15    CONTAINS     price

Matt
---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.
        
---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.
-------------------------------------------------------------------
E-mail scanned for viruses by Nexus (http://www.ntgrp.com/mailscan)


      
-------------------------------------------------------------------
E-mail scanned for viruses by Nexus (http://www.ntgrp.com/mailscan)

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.
    

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.


  

Reply via email to