* This is the modus mailing list *

I think Norman is calling it Bagle, not Beagle. They released a def for it
1/19/04 09:21 CET, whatever that is.

Mark Thornton
San Marcos Internet, Inc
512-393-5300


----- Original Message ----- 
From: "Lewis Watson" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Monday, January 19, 2004 10:46 AM
Subject: [Modus] Checking virus defs?


> * This is the modus mailing list *
>
> Hey Mike,
> Thats good to know! In that case maybe they are just slow to update their
> site. I see nothing about it at norman.com.
> Thanks.
> Lewis
>
> ----- Original Message ----- 
> From: "Mike Herrera" <[EMAIL PROTECTED]>
> To: <[EMAIL PROTECTED]>
> Sent: Monday, January 19, 2004 7:28 AM
> Subject: [Modus] Checking virus defs?
>
>
> > * This is the modus mailing list *
> >
> > FYI, we have been seeing the Bagle worm being caught by the Norman
> engine.
> >
> >
> > Regards,
> >
> > Mike Herrera
> > Access One Online Svcs.
> > http://www.access-one.com
> >
> >
> > -----Original Message-----
> > From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On
> Behalf
> > Of Lewis Watson
> > Sent: Monday, January 19, 2004 12:49 AM
> > To: [EMAIL PROTECTED]
> > Subject: [Modus] Checking virus defs?
> >
> > * This is the modus mailing list *
> >
> > Hi Jon,
> > I would think that the fact Norman.com does not even mention this worm
> would
> > strongly indicate we are not protected. I created a sieve script to try
> and
> > block this new worm. Please improve it if necessary and repost it here
> since
> > my sieve skills are poor at best.
> >
> > Here's Norton's info about it...
> > http://www.sarc.com/avcenter/venc/data/[EMAIL PROTECTED]
> >
> >
> >
> > # To block the Beagle worm..... (it should block any messages that #
> have
> > the subject Hi and that also have an attachment of any sort.
> > #
> >
> > if allof  (
> >     header :contains "subject" "Hi",
> >     attachment :matches "*.*"
> > )    { discard; stop; }
> >
> > Thanks,
> > Lewis
> >
> >
> >
> > ----- Original Message -----
> > From: "Jon Benson" <[EMAIL PROTECTED]>
> > To: "Modus (E-mail)" <[EMAIL PROTECTED]>
> > Sent: Sunday, January 18, 2004 11:42 PM
> > Subject: [Modus] Checking virus defs?
> >
> >
> > * This is the modus mailing list *
> >
> > Hi folks,
> >
> > Would anyone be able to tell me how to check what virus defs I have
> > compared to the Norman website?
> >
> > The update links off to
> > http://www.norman.com/virus_info/virus_info_new.shtml but the number
> given
> > there (currently 0114) doesn't seem to correspond to anything I can find
> > in Modus.
> >
> > Basically I'd like to know if the server is currently detecting the
> > following:
> > http://vil.nai.com/vil/content/v_100965.htm
> >
> >
> > Thanks,
> >
> > Jon Benson
> > Mail/DNS/Linux Administrator
> > OzHosting.com
> >
> > **
> > To unsubscribe, send an Email to: [EMAIL PROTECTED]
> > with the word "UNSUBSCRIBE" in the body or subject line.
> >
> >
> > **
> > To unsubscribe, send an Email to: [EMAIL PROTECTED]
> > with the word "UNSUBSCRIBE" in the body or subject line.
> >
> >
> > **
> > To unsubscribe, send an Email to: [EMAIL PROTECTED]
> > with the word "UNSUBSCRIBE" in the body or subject line.
>
>
> **
> To unsubscribe, send an Email to: [EMAIL PROTECTED]
> with the word "UNSUBSCRIBE" in the body or subject line.


**
To unsubscribe, send an Email to: [EMAIL PROTECTED]
with the word "UNSUBSCRIBE" in the body or subject line.

Reply via email to