Welcome to SecurityForumz.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

footprints?

 
   Security Forums (Home) -> General Discussions RSS
Next:  .scr virus!!!!?????  
Author Message
RB

External


Since: Sep 23, 2003
Posts: 3



(Msg. 1) Posted: Tue Sep 23, 2003 10:16 am
Post subject: footprints?
Archived from groups: alt>comp>virus (more info?)

If a person has an virus infected computer that is sending out email using
email addresses harvested from the address book, will it be detectable to
the owner/operator that this is happening? Or, do the little nasties do
their work invisibly so that the operator doesn't have a clue?

I would think there would be file copies of all the outgoing messages in the
"sent" folder.

 >> Stay informed about: footprints? 
Back to top
Login to vote
Thore Schmechtig

External


Since: Sep 23, 2003
Posts: 10



(Msg. 2) Posted: Tue Sep 23, 2003 6:14 pm
Post subject: Re: footprints? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Hi,

> If a person has an virus infected computer that is sending out email using
> email addresses harvested from the address book, will it be detectable to
> the owner/operator that this is happening? Or, do the little nasties do
> their work invisibly so that the operator doesn't have a clue?
> I would think there would be file copies of all the outgoing messages in the
> "sent" folder.

A number of modern critters have their own SMTP engine... they don't
need to use M$OE so you won't find anything in your "sent" folder.


--
Bye

Tocis (commoner AT carcosa DOT de)
Include HI-AK 523 in the subject or your email will be deleted!

 >> Stay informed about: footprints? 
Back to top
Login to vote
RB

External


Since: Sep 23, 2003
Posts: 3



(Msg. 3) Posted: Tue Sep 23, 2003 6:14 pm
Post subject: Re: footprints? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Thanks for confirming. I was beginning to suspect that by the numbers of
pcs out there busily cranking out spam where operators don't seem to have
any idea their computer is doing something naughty.
 >> Stay informed about: footprints? 
Back to top
Login to vote
Thore Schmechtig

External


Since: Sep 23, 2003
Posts: 10



(Msg. 4) Posted: Wed Sep 24, 2003 11:58 am
Post subject: Re: footprints? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Hi,

> Would a firewall (Sygate / ZA) give an indication that this SMTP engine is
> trying to access the internet? It is a program, isn't it?

A firewall may or may not show Swen activity. I admit that I don't use
windoze firewalls anymore (since all my windoze clients connect to the
internet via a Linux server that naturally is a firewall in and of
itself Smile ). Remembering the last version of ZoneAlarm I used, I think
it should notice Swen activity and therefore notify you that something
bad is going on there... but I cannot guarantee that.

By the way, if you want to know whether you got Swen yourself then you
can check this much easier than using a firewall. Try to start regedit
(start menu / execute / type "regedit"). If it opens you're safe as
Swen blocks regedit and some other programs.


--
Bye

Tocis (commoner AT carcosa DOT de)
Include HI-AK 523 in the subject or your email will be deleted!
 >> Stay informed about: footprints? 
Back to top
Login to vote
Thore Schmechtig

External


Since: Sep 23, 2003
Posts: 10



(Msg. 5) Posted: Wed Sep 24, 2003 1:22 pm
Post subject: Re: footprints? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Hi,

> Thanks kindly for your reply. I wanted a clearer understanding of what a
> STMP (just a format rule?) engine (program?) could do and whether my Sygate
> would kick in if I had been infected.

SMTP = Simple Mail Transfer Protocol. The internet protocol for
transfering emails. SMTP engine = program that processes emails from
one machine to another (very simple explanation).
So yes, an SMTP engine is executable code and basically can be caught
by a firewall that recognizes that there is an unknown program wanting
to access the internet. But there may well be ways to disguise these
attempts - Swen unfortunately has been written by a bastard with quite
some creativity when it comes to tormenting innocent users. :/

> don't believe I have the one's that can automatically execute (I'm fully
> patch - W98SE) but where would you look to see how they do that; in the
> headers? by viewing source?

If you have a fully patched system I think the Swen attachments won't
automatically execute when you open the mail itself. But I strongly
suggest you don't take the risk and instead follow the rules of Safer
Hex (Install and keep up-to-date security software - virus scanner and
firewall - and never ever open an attachment unless you absolutely
positively know that it's harmless). With M$OE, among other things,
this includes closing the preview pane because that's de facto the same
as opening the email itself.

> I see your day is half done, enjoy your lunch, and thanks again for your
> help.

No problem Smile
 >> Stay informed about: footprints? 
Back to top
Login to vote
Display posts from previous:   
   Security Forums (Home) -> General Discussions All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]