Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Lawmakers slam anti-virus biz
Kevin Poulsen, SecurityFocus 2000-05-10

Love Letter worm was an "utter, abject failure" of industry, says one Congressman. Industry blames liberal judges.

Comments Mode:
Virus? 2000-05-11
Anonymous (1 replies)
Virus? 2000-05-11
Anonymous (1 replies)
Not a virus, a feature! 2000-05-12
Anonymous
Well. the industry is *sort* of right.... 2000-05-11
Anonymous (1 replies)
laws 2000-05-11
Anonymous (1 replies)
laws 2000-05-12
Anonymous
There IS a magic bullet, common sense. 2000-05-11
Anonymous (3 replies)
There IS a magic bullet, common sense. 2000-05-11
Anonymous (1 replies)
There IS a magic bullet, common sense. 2000-05-12
Anonymous (1 replies)
not a/v politics to blame 2000-05-11
Anonymous (1 replies)
Put the blame where it belongs 2000-05-11
Anonymous (1 replies)
Put the blame where it belongs 2000-05-11
Anonymous
The US Gov. CAN'T be that stupid! 2000-05-11
Anonymous (1 replies)
The US Gov. CAN'T be that stupid! 2000-05-11
Anonymous
This is ridiculous! 2000-05-11
Anonymous
Valuable Employees 2000-05-11
Anonymous
Listen to the panel 2000-05-11
Anonymous
who does he think he is? 2000-05-11
Anonymous
Virus? 2000-05-11
Anonymous
Civil Rights 2000-05-12
Anonymous
Awareness 2000-05-12
Anonymous
Do you honestly think that heuristics could have detected this thing? 2000-05-12
Anonymous (1 replies)
After the fact, I down-graded my anti-virus definition files (I use both Norton and NAI mainly), turned on the heuristics to their 'highest level' (meaning that I turned them on... the little slide bar with three settings actually has two... off, off, and on.). I then scanned the original lovebug virus, nothing. I ran it, making sure that I had an on-access scanner turned on with heuristics, nothing. I tried this with both Norton and NAI. neither of their heuristic engines caught it. I have yet to find a heuristic engine that is capable of detecting anything but modified boot sector viruses.

Why didn't the anti-virus programs immediately analyze (or better yet, stop) any file with a .txt.vbs extension (or for that matter, a .gif.vbs? how about .mp3.vbs??) It's one of the oldest tricks in the book! The use of double-extensions is an obvious sign that something's wrong. How come the heuristics didn't pick that up?!?

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/32/1828#1828
Misinformed public 2000-05-12
Anonymous
Try this... 2000-05-12
Anonymous
oh my heavens 2000-05-12
Anonymous (1 replies)
oh my heavens 2000-05-12
Anonymous (1 replies)
oh my heavens 2000-05-15
<ntaddict (at) hotmail (dot) com [email concealed]>
Anti-Virus companies to blame? please 2000-05-12
Anonymous (1 replies)
"figured out a way to block this" 2000-05-12
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus