| General This forum is for non-technical general discussion which can include both Linux and non-Linux topics. Have fun! |
| Notices |
Welcome to LinuxQuestions.org, a friendly and active Linux Community.
You are currently viewing LQ as a guest. By joining our community you will have the ability to post topics, receive our newsletter, use the advanced search, subscribe to threads and access many other special features. Registration is quick, simple and absolutely free. Join our community today!
Note that registered members see fewer ads, and ContentLink is completely disabled once you log in.
Are you new to LinuxQuestions.org? Visit the following links:
Site Howto |
Site FAQ |
Sitemap |
Register Now
If you have any problems with the registration process or your account login, please contact us. If you need to reset your password, click here.
Having a problem logging in? Please visit this page to clear all LQ-related cookies.
 |
GNU/Linux Basic Guide
This 255-page guide will provide you with the keys to understand the philosophy of free software, teach you how to use and handle it, and give you the tools required to move easily in the world of GNU/Linux. Many users and administrators will be taking their first steps with this GNU/Linux Basic guide and it will show you how to approach and solve the problems you encounter.
Click Here to receive this Complete Guide absolutely free. |
|
 |
|
01-26-2004, 10:10 PM
|
#1
|
|
Member
Registered: Jan 2004
Location: Miami FL
Distribution: Mac OS X 10.4.11 Ubuntu 12.04 LTS
Posts: 427
Rep:
|
new worm KEYSTROKE LOGGER
Tricky 'MyDoom' e-mail worm spreading quickly
Worm launches attack on site for Unix-owner SCO Group
it has a keystroke logger!
|
|
|
|
01-26-2004, 10:53 PM
|
#3
|
|
Member
Registered: Oct 2002
Location: Lower Alabama
Distribution: Slackware, OpenBSD 3.9
Posts: 344
Rep:
|
Wow! I went to work today, and when I came back, I had blocked 6 of these, and had reports in my mail! I'm glad I installed that virus scanner in my mail server now!
Ian
|
|
|
|
01-27-2004, 07:48 AM
|
#4
|
|
Member
Registered: Dec 2003
Distribution: Slackware 9.1
Posts: 309
Rep:
|
Wow, I feel like getting myself a .edu email address. 
|
|
|
|
01-27-2004, 05:29 PM
|
#5
|
|
Senior Member
Registered: Nov 2003
Location: Knoxville, TN
Distribution: Kubuntu 9.04
Posts: 1,168
Rep:
|
|
|
|
|
01-27-2004, 05:47 PM
|
#6
|
|
Member
Registered: Jan 2004
Location: The land of the free and the home of the brave
Distribution: Slack 10
Posts: 239
Rep:
|
Quote:
Originally posted by natalinasmpf
Wow, I feel like getting myself a .edu email address.
|
yeah, i guess the virus writer had SOME heart. I don't know why people open these emails anyway, they're just asking for a virus.
|
|
|
|
01-28-2004, 09:59 AM
|
#7
|
|
Member
Registered: Jan 2004
Distribution: OS X; FreeBSD; Debian
Posts: 172
Rep:
|
MyDoom originated in Russia!
Hehe, another Windows virus...
But why does everybody blame it on the Linux community?
MessageLabs says it originated in Russia
where nobody would care about a US lawsuit.
www.groklaw.com
|
|
|
|
01-28-2004, 10:43 AM
|
#8
|
|
Member
Registered: Feb 2003
Location: god's judge
Posts: 376
Rep:
|
contemplating getting it on purpose...
|
|
|
|
01-28-2004, 11:48 AM
|
#9
|
|
Member
Registered: Jan 2004
Distribution: OS X; FreeBSD; Debian
Posts: 172
Rep:
|
Uh, williamwbishop, you might not want to do that. It takes over your internet connection by using all its bandwith.
|
|
|
|
01-28-2004, 12:11 PM
|
#10
|
|
Member
Registered: Feb 2003
Location: god's judge
Posts: 376
Rep:
|
It's for a good cause, and I can always clean it tomorrow....
|
|
|
|
01-28-2004, 05:14 PM
|
#11
|
|
Member
Registered: Dec 2003
Distribution: Slackware 9.1
Posts: 309
Rep:
|
Heck, I want a more friendly app. Ie. I could start it before I go to school and stop it when I need to use the net.
|
|
|
|
01-28-2004, 08:06 PM
|
#12
|
|
Senior Member
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658
Rep:
|
You should not ever use wget to do anything like that.
|
|
|
|
01-28-2004, 08:59 PM
|
#13
|
|
HCL Maintainer
Registered: Jun 2003
Location: Tupelo, MS
Distribution: Gentoo
Posts: 6,926
Rep: 
|
Quote:
Originally posted by williamwbishop
contemplating getting it on purpose...
|
I opened it with Ark in a /tmp subdirectory when the first document.zip made it to my Inbox. Then looked at the document.exe file. If I am correct, it can't do anything to a Linux box because this is what it does...
Quote:
When W32.Novarg.A@mm is executed, it does the following:
1. Creates the following files:
* %System%\Shimgapi.dll: Shimgapi.dll acts as a proxy server, opening TCP listening ports in the range of 3127 to 3198. The backdoor also has the ability to download and execute arbitrary files.
* %Temp%\Message: This file contains random letters and is displayed using Notepad.
* %System%\Taskmon.exe:
|
I'm no Linux expert, but if I'm correct, this particular worm can't do anything to a Linux system. Is this correct?
|
|
|
|
01-28-2004, 09:10 PM
|
#14
|
|
Member
Registered: Jan 2004
Location: Miami FL
Distribution: Mac OS X 10.4.11 Ubuntu 12.04 LTS
Posts: 427
Original Poster
Rep:
|
apparently not any threat to Linux/Mac/Unix. even win3.1 seems unthreatened 
|
|
|
|
01-29-2004, 12:14 AM
|
#15
|
|
Senior Member
Registered: Oct 2003
Location: hopefully not here
Distribution: Gentoo
Posts: 2,038
Rep:
|
u think these worms would get smarts, a smart worm would srat and attack in like only hours after it was relaesed, long b4 anyone could alert the worl of a new worm, thus acutaly doing somthing that is meaningful, like dos attack sco and ms? (not realy meaningful, but it is to the virus wirters who are no doupt just out to hurt them)
|
|
|
|
| Thread Tools |
Search this Thread |
|
|
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT -5. The time now is 01:55 AM.
|
|
LinuxQuestions.org is looking for people interested in writing
Editorials, Articles, Reviews, and more. If you'd like to contribute
content, let us know.
|
Latest Threads
LQ News
|
|