Uh oh. Looks like someone (24.78.137.10) has the Bagle.c virus... ---------- Forwarded message ---------- Return-Path: <cyrus@mail1> Received: from mail1 ([unix socket]) by mail1 (Cyrus v2.1.15) with LMTP; Fri, 27 Feb 2004 18:02:28 -0500 X-Sieve: CMU Sieve 2.2 Return-Path: <wlug-bounces@mail.wlug.org> Received: from mcafee.wpi.edu (mcafee.WPI.EDU [130.215.36.86]) by mail1.WPI.EDU (8.12.11/8.12.11) with SMTP id i1RN2SN0008669; Fri, 27 Feb 2004 18:02:28 -0500 Received: from smtp.WPI.EDU(130.215.36.186) by mcafee.wpi.edu via csmap id 8665; Fri, 27 Feb 2004 18:00:55 -0500 (EST) Received: from paramount.ind.WPI.EDU (paramount.ind.WPI.EDU [130.215.130.22]) by smtp.WPI.EDU (8.12.11/8.12.11) with ESMTP id i1RN2DkQ009310; Fri, 27 Feb 2004 18:02:17 -0500 Received: from paramount.ind.WPI.EDU (localhost.localdomain [127.0.0.1]) by paramount.ind.WPI.EDU (8.12.8/8.12.8) with ESMTP id i1RN7ReN017460; Fri, 27 Feb 2004 18:07:28 -0500 Received: from mail1.WPI.EDU (mail1.WPI.EDU [130.215.36.102]) by paramount.ind.WPI.EDU (8.12.8/8.12.8) with ESMTP id i1RN7OeN017454 for <wlug@mail.wlug.org>; Fri, 27 Feb 2004 18:07:24 -0500 Received: from mcafee.wpi.edu (mcafee.WPI.EDU [130.215.36.86]) by mail1.WPI.EDU (8.12.11/8.12.11) with SMTP id i1RN26tU008313 for <wlug@mail.wlug.org>; Fri, 27 Feb 2004 18:02:06 -0500 Received: from smtp.WPI.EDU(130.215.36.186) by mcafee.wpi.edu via csmap id 8665; Fri, 27 Feb 2004 18:00:42 -0500 (EST) Received: from mojo (h24-78-137-10.ss.shawcable.net [24.78.137.10]) by smtp.WPI.EDU (8.12.11/8.12.11) with SMTP id i1RN213S009269 for <wlug@mail.wlug.org>; Fri, 27 Feb 2004 18:02:02 -0500 Date: Fri, 27 Feb 2004 17:11:59 -0800 To: wlug@mail.wlug.org From: cra@WPI.EDU Message-ID: <fbaympsoepeuinmkuvc@WPI.EDU> MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="--------hgdtfwokiwdsmymogaqa" Subject: [Wlug] Jenny X-BeenThere: wlug@mail.wlug.org X-Mailman-Version: 2.1.1 Precedence: list Reply-To: Worcester Linux Users Group <wlug@mail.wlug.org> List-Id: Worcester Linux Users Group <wlug.mail.wlug.org> List-Unsubscribe: <http://mail.wlug.org/mailman/listinfo/wlug>, <mailto:wlug-request@mail.wlug.org?subject=unsubscribe> List-Archive: <http://paramount.ind.wpi.edu/pipermail/wlug> List-Post: <mailto:wlug@mail.wlug.org> List-Help: <mailto:wlug-request@mail.wlug.org?subject=help> List-Subscribe: <http://mail.wlug.org/mailman/listinfo/wlug>, <mailto:wlug-request@mail.wlug.org?subject=subscribe> Sender: wlug-bounces@mail.wlug.org Errors-To: wlug-bounces@mail.wlug.org
frank p <fspoz3@WPI.EDU> wrote:
Uh oh. Looks like someone (24.78.137.10) has the Bagle.c virus...
Hmm... even more interesting that bitdefender (BDC/Linux-Console v7.0 (build 2492) under debian), updated a few minutes ago, doesn't seem to detect it. Fortunately, ClamAV (clamdscan / ClamAV version 0.60+BugFixesFromCVS-20030916) does after forcing an update. I think I'll update my clamav update cycle "just a bit." - Bob (Testing linux-based AV under procmail)
On Fri, Feb 27, 2004 at 07:50:26PM -0500, Bob George wrote:
frank p <fspoz3@WPI.EDU> wrote:
Uh oh. Looks like someone (24.78.137.10) has the Bagle.c virus...
Hmm... even more interesting that bitdefender (BDC/Linux-Console v7.0 (build 2492) under debian), updated a few minutes ago, doesn't seem to detect it. Fortunately, ClamAV (clamdscan / ClamAV version 0.60+BugFixesFromCVS-20030916) does after forcing an update. I think I'll update my clamav update cycle "just a bit."
WPI's mail system filters out virii.
On Fri, Feb 27, 2004 at 09:31:01PM -0500, Bob George wrote:
Charles R. Anderson <cra@WPI.EDU> wrote:
[...] WPI's mail system filters out virii.
Clam found bagle in the attachments, as did f-prot.
This virus is sufficiently new that the campus mail filter didn't have the appropriate signature. I've contacted one of the people who administers it, and he's updated the signatures. No more of this virus should make it through any WPI campus mail. -- Frank Sweetser fs at wpi.edu WPI Network Engineer
participants (4)
-
Bob George
-
Charles R. Anderson
-
frank p
-
Frank Sweetser