|
 |

|


|
Virus Alert
26th March, 2003, Submitted by Rusty^Blade
An old worm (wkbot) has been re-released into the wild with
currently a high payload. The majority of people receive this
virus from kazaa/imesh/IRC. As a means to help others infected
with the ident problem Austnet has ignored the idents of affected
users.
The things to look out for are your ident being
set to LL????? (random numbers replace the question marks)
or a file called cmd32.exe or system32.exe. If you or a friend
has found this then might be a good idea to take a visit into
#ava for some assistance. As yet there is no fixfile for this
virus and the online scanners are struggling to remove it
(although they do detect it)
This virus has many malicious functions, some of these include;
Opens
two randomly selected TCP and UDP ports to connect to the
hacker.
Listens
for the commands from the hacker using its own IRC channel.
The commands allow the hacker to perform any of the following
actions:
Upgrade
the worm
Steal
the system/network information and send it to the hacker
Download
and execute files
Perform
Denial of Service (DoS) attacks against the hacker's targets
Send
the worm to other IRC users
More information on this virus can be obtained from #ava or
from Symantec
|
 |
Buffer overflows in IRC-II based clients
22nd March, 2003, Submitted by Blase
If you are using an IRC-II based client, then you should be
aware of the latest reported security threat. A post on Security
focus has listed few vulnerabilities, which could be exploited
if a user connects to a malicious server. However, only users
with the correct authority, such as server administrators can
only make use of these bugs. Regular users are unable to exploit
these bugs. In order to avoid being compromised
users should avoid connecting to un-trusted servers and not
IRC over insecure network links. Author of the post, Timo Sirainen
said: "After seeing the BitchX "DoS"
problem mentioned the n'th time already, I decided to finally
audit ircII based clients to show some worse problems they have.
I had been pretty sure for years that malicious servers can
exploit them in multiple ways, and I think many others have
known it as well. EPIC and ircII authors have been working to
fix these, but looks like their job isn't yet finished."
Timo Sirainen's entire article can be seen HERE.
|
 |
Microsoft issues security alert 20th
March, 2003, Submitted by Lolly
A new security alert highlights a critical security bug in all
Windows® products. This exploit could be used to run malicious
scripts. Affected products are Windows 98, 98SE, ME, NT 4, NT
4 Server edition, 2000 and XP. All users are urged to download
the latest security updates available HERE.
Read the alert HERE.
The attacker would first have to send you an e-mail message
or entice you into visiting a malicious Web site. AustNet would
like to take this opportunity to remind all users to not go
to any links which are sent to you on entry or parting of channels,
or in conversations with strangers. Prevention can often be
better than the cure. |
 |
What to do when you have a virus 6th
March 2003, Submitted by blase
Have a sneaking suspicion that your client is infected with
a virus?
Then it will be wise to leave/part all the channels you've joined,
and join
#AVA. This will ensure that your chances of being banned from
a channel are
minimal, and you will not pose a possible threat to other unsuspecting
users. When you have been checked and cleared of any viruses,
you may
continue with your regular chat. |
 |
General Virus Warning
1st January, 2003, Submitted by ed
Users of Austnet are warned not to visit websites messaged to
them - sadly many contain malicious content which can damage
your computer.
For more information, visit the Austnet
Virus Assistance (AVA) website. |
| |
|
Admin | Channels
| Events | General
| Network | Services | Website
|
|
 |