Adopting David's idea on beastie.frontfree.net
With more and more aaazzz’s received on beastie.frontfree.net, it makes me to seriously consider the possiblity to set up a set of early filter on postfix.
共 234 篇文章。
With more and more aaazzz’s received on beastie.frontfree.net, it makes me to seriously consider the possiblity to set up a set of early filter on postfix.
From my statistics on beastie.frontfree.net, the winner is Worm.SomeFool family.
There are two common way to process unaccepted letters: One is bounce, a.k.a. give the sender a message saying “Your letter is bounced.” Another is discard, in other words, drop the letter silently.
It’s really necessary to train a new security officer lead for Frontfree, if I must leave the campaus. While it will be reasonable if I will invest some of my time maintaing the server, they must deal some real-world problems theirselves, as I may be unable to reach these boxes in time.
Gibe is still the first place, and MyDoom(here, it was called Worm.SCO.A) drastically dropped down.
beastie# bzcat maillog.0.bz2 | grep INFECT | awk ‘{print $8;}’ | sort | uniq -c | sort -rn
181 (Worm.Gibe.F),
86 (Worm.SCO.A),
2 (Worm.Dumaru.Y),
1 (Worm.Sobig.F),
Gibe and its variants are still dominant, and MyDoom is approaching to catch up:
beastie# cat drwebd.log | grep infect | grep MyDoom | wc -l
243
beastie# cat drwebd.log | grep infect | grep Gibe | wc -l
257
beastie# cat drwebd.log | grep infect | grep -v Gibe | grep -v MyDoom | wc -l
0
It’s interesting that there’s no viruses without a name “Gibe” nor “MyDoom”…
Thanks junsu and I have got a copy of MyDoom now.
Its MD5 is: 39A7D2BB 5652C9D1 05C0D64A 640C5A9D [UPX unpacked]
Unfortunatelly he said it’s not valuable to research it because a previous analyze done by his colleague indicates that this is not a “skilled” worm.
I’ll keep this for some time. For security reasons I have denied my own execute privilege of that file.
From my Dr.Web log, it seems mydoom is getting its peak. Today it replaced the Win32.HLLM.Gibe.2, to be the king of virus on my mail server :)
It’s to my interest that the virus seemed to be < 32K. So if you have a sample, please send it to me (REMEMBER: Please encrypt it by adding a password in your ZIP or RAR archive, so I will be able to receive it without having the DrWeb to block it.)