@RISK Online - The Security Blog
4 user(s) online.
[Previous entry: "Politics... Ugh!"] [Main Index] [Next entry: "SchmooCon 2005 Comes To Washington DC"]
09/28/2004: "JPEG Virus on the loose. Don't Panic... Prepare!"
Reports have come in about a JPEG virus released to USENET earlier this week. This actually appears to be primarily a trojan and not a worm, but future variants could include propogation capabilities. It's reported that the infected computers so far are being controlled by one individual.
The SANS Internet Storm Center has released a tool called GDIScan that will check for any programs that might be using an exploitable version of the GDI driver.
Is this the next Code-Red or Slammer? It's too early to tell. But, Please, don't panic... Prepare!
- Determine your exposure. Are you vulnerable? Use the GDIScan tool and take a look at your systems.
- Apply the appropriate security patches. Start testing and deploying these patches NOW. The exploits are propagating already.
- Update your virus signatures. Do this on a regular basis, but especially at a time when an exploit of this nature has started its life cycle.
- Be alert. Monitor traffic patterns, firewall and IDS logs, etc. Watch for abnormal traffic patterns or surges. Track your Helpdesk support calls. Is there a new trend developing in the calls? Users may not know what the problem is, but they may alert you indirectly.
This is not a complete list... Just a reminder. Keep your eyes and ears open. I'll post updates when there's more news.
|
| September 2004 | | S | M | T | W | T | F | S | | | | 1 | 2 | 3 | 4 |
| 5 | 6 | 7 | 8 | 9 | 10 | 11 |
| 12 | 13 | 14 | 15 | 16 | 17 | 18 |
| 19 | 20 | 21 | 22 | 23 | 24 | 25 |
| 26 | 27 | 28 | 29 | 30 | | |
Blogroll Me!
Navigation:
Home
Archives
About Me
Articles
Email
News Feed
Projects
My Blogroll:
Security Advisories:
Anti-Phishing
AUSCERT
BugBlog
CERIAS
CERT
CIAC
Cisco Advisories
F-Secure
iDefense
ISS XForce
McAfee
Windows Security
Oracle Alerts
Secunia
Security Corporation
Security Focus
Security Tracker
SGI Advisories
Sun Alerts
Symantec
Trend Micro
Zone-H
Defacements Archive:
Zone-H Digital Archive
Security News:
DShield
Help Net Security
Internet Storm Center
Linux Security
NewsNow: Encryption/Security
NewsNow: Hacking
Packet Storm
Securiteam
Security News Portal
Security Stats
Security Focus
Risks Digest
Zone-H
Security Tools:
Packet Storm
Astalavista
Help Net Security
Packet Factory
Security Focus
|