Hello Allie,

Monday, July 12, 2004, 5:43:17 AM, you wrote:
Allie> A worm or something that edits the file, and uses TB! to fetch
Allie> its payload or whatever else it needs to complete its task.

It's possible. Anything is possible. What if a worm infects TB and
uses TB on port 25 or 110 or 143 to download what it needs. There's
really no difference. Granted there are checksum fingerprints in most
good firewalls that would detect a change to TBs code, but if a
virus generated an e-mail and only used TB as the transport mechanism
for that e-mail, the e-mail could go to an address that auto-responds
with a file the virus needs to complete its nasty work.

The firewall wouldn't detect this as there was no change to the TB
executable, and since the virus isn't directly accessing the internet,
the firewall wouldn't detect that either (in most firewalls).

Allie> Is that silly? Unnecessary? Impractical for someone to exploit.
Allie> I don't know really but it seems concerning.

It ranks right there with anything else we do on a computer. If
someone is determined to hack you, it's gonna happen. It's only a
matter of time.

Allie> I don't see how this can be compared to POP3 or IMAP, the idea
Allie> being that TB! fetches from those servers.

I explained that above. Paul and I already proved TB wouldn't execute
an executable when referenced by the smileys system.

Allie> The difference is that rogue service would be doing simple file
Allie> fetching. Does it do a simple extension check?

It does on the server, and it's something that could be added I think
easily enough by RITLabs within TB. Heck, it might even be able to be
tied in with the TB security concerning extensions when you try to
launch an attachment.



-- 
Leif Gregory (TB list moderator and fellow end user).

Tagline of the day:
Spleen:  The OTHER purple meat!

Using The Bat! 2.12 RC/3 under Windows 2000 5.0
Build 2195 Service Pack 4 on a Pentium 4 2GHz with 512MB






________________________________________________________
 Current beta is v2.12 RC/1 | 'Using TBBETA' information:
http://www.silverstones.com/thebat/TBUDLInfo.html
IMPORTANT: To register as a Beta tester, use this link first -
http://www.ritlabs.com/en/partners/testers/

Reply via email to