Off: virus from list member

Guido Vacano nycademon at ATTBI.COM
Sat Dec 8 20:54:14 EST 2001


Dan, if you're going to start pointing fingers and assigning guilt,
maybe you should first make the effort to be informed about what you're
talking about. This virus is not called "humor.mp3.scr" (that's only one
of many names it uses for the attachment), it is called
"W32.Badtrans.B at mm". Please read the following:

"Email messages use the malformed MIME exploit to allow the attachment
to execute in Microsoft Outlook without prompting. For information on
this, go to:

http://www.microsoft.com/technet/security/bulletin/MS01-020.asp "

The critical words are "without prompting". You don't need to open the
attachment, it opens itself. You might also want to read:

http://securityresponse.symantec.com/avcenter/venc/data/w32.badtrans.b@mm.html


and then, assuming you're a reasonable human being, you might want to
apologize to Mark Storer.

You want to blame somebody? Blame Micro$oft, and the people who exploit
their disregard for computer security.

Guido



Dan Witt wrote:

>----- Original Message -----
>From: "Nick Medford" <nick at HERMIT0.DEMON.CO.UK>
>
>
>>free to comment- so c'mon Dan, it's clearly an accident, it's easy to pass
>>
>on
>
>>viruses without realising, stop making a morality play out of it. I've
>>
>received
>
>>email viruses from work colleagues in the past- shit happens. I wouldn't
>>dream of telling them they were "guilty" blah blah. As far as I'm aware
>>
>I've
>
>>never passed a virus on but that's due more to luck than judgement. Even
>>the most effective anti-virus software isn't 100% bomb-proof.
>>
>
>AV software is not to blame, I don't even use it.  When you get an email
>with an attachment and it's an executable, don't execute the damn
>thing(unless you know exactly what it is).  It's really that simple.
>
>Also if you're using outdated software you open yourself up to these
>problems too.  An old MS Outlook express will run the virus for you, without
>you asking it to.  I know some of you fiercely defend you're right to use
>outdated software, so I won't say anymore about it.
>
>The shame comment was only fired off cause I thought he had been careless.
>I thought it was a mild statement.  Anyway no hard feelings to anybody, just
>don't spread viri, please.
>



More information about the boc-l mailing list