Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Lawmakers slam anti-virus biz
Kevin Poulsen, SecurityFocus 2000-05-10

Love Letter worm was an "utter, abject failure" of industry, says one Congressman. Industry blames liberal judges.

Comments Mode:
Virus? 2000-05-11
Anonymous (1 replies)
Virus? 2000-05-11
Anonymous (1 replies)
Not a virus, a feature! 2000-05-12
Anonymous
Well. the industry is *sort* of right.... 2000-05-11
Anonymous (1 replies)
laws 2000-05-11
Anonymous (1 replies)
laws 2000-05-12
Anonymous
There IS a magic bullet, common sense. 2000-05-11
Anonymous (3 replies)
There IS a magic bullet, common sense. 2000-05-11
Anonymous (1 replies)
There IS a magic bullet, common sense. 2000-05-12
Anonymous (1 replies)
not a/v politics to blame 2000-05-11
Anonymous (1 replies)
Put the blame where it belongs 2000-05-11
Anonymous (1 replies)
Put the blame where it belongs 2000-05-11
Anonymous
The US Gov. CAN'T be that stupid! 2000-05-11
Anonymous (1 replies)
The US Gov. CAN'T be that stupid! 2000-05-11
Anonymous
This is ridiculous! 2000-05-11
Anonymous
Valuable Employees 2000-05-11
Anonymous
Listen to the panel 2000-05-11
Anonymous
who does he think he is? 2000-05-11
Anonymous
Virus? 2000-05-11
Anonymous
Civil Rights 2000-05-12
Anonymous
Awareness 2000-05-12
Anonymous
Misinformed public 2000-05-12
Anonymous
Try this... 2000-05-12
Anonymous
Role of the Businesses Who got Sacked 2000-05-12
Anonymous
Yes, ignorance was the helping factor for ILU. And as much as I blame naive users for clicking blindly, and also Microsoft for allowing vb scripts to run unseen and unwarned, there is another group that I'm astounded by for their blatent lack of help: the so-called IT professionals or sys-admins who run their business' (or orginization)'s e-mail servers.

In our orginization (unnamed), we had about 15 IT professionals and "admins" running around in panic, trying to tell everyone not to open this e-mail... or in fact, not to check their e-mail for awhile, because our mail server was being flooded to the point of death.

Funny enough, in our division, we had placed a simple filter rule in our mail server to block any e-mail with the ILU title(s) and any e-mail with a VBS attachement. The would-be recipient was then notified that their e-mail was filtered and should contact the named sender to see if the e-mail might have been a valid (non ILU) e-mail. Within an hour, our traffic had fallen back down to near-normal levels. Why? The vbs file was not being broadcast out every 30 seconds from our mail server, which gave us some breathing room to go remove the script from people's machines.

My point is this. The other IT "pros" and admins, had no clue that such a filter was even possible.... not to mention they had never stopped to consider that they could actually HELP the scenario. If more admins would have at least tried to add some kind of filter, the exponential growth of traffic on the internet would have at lest been lessened.

These "clickme" scripts (I won't call it a virus, it's not) will just keep coming, and I expect that there will always be unsuspecting users who fall prey to the trick. But come on professionals!! Where are your witts? Let's get beyond that 2 day conference from a year ago where you learned how to boot your MS Exchange server! Become a real admin and become VALUABLE to your company!

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/32/1836#1836
oh my heavens 2000-05-12
Anonymous (1 replies)
oh my heavens 2000-05-12
Anonymous (1 replies)
oh my heavens 2000-05-15
<ntaddict (at) hotmail (dot) com [email concealed]>
Anti-Virus companies to blame? please 2000-05-12
Anonymous (1 replies)
"figured out a way to block this" 2000-05-12
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus