[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [cobalt-users] extreme newbie with possible virus
- Subject: Re: [cobalt-users] extreme newbie with possible virus
- From: flash22@xxxxxxx
- Date: Fri Sep 28 11:15:06 2001
- List-id: Mailing list for users to share thoughts on Cobalt products. <cobalt-users.list.cobalt.com>
On Sat, 29 Sep 2001, SM wrote:
> At 16:59 28-09-2001 -0400, Lenore Howe wrote:
> >I am running a Cobalt RAQ3 with OS 5.0. Last Friday, I got an email from
> >someone saying that my server was port-sniffing which probably indicated
> >that I had some sort of virus. Since then, I've heard from different sources
>[...]
> First of all let me assure you that your server is not infected by a virus.
> If a webpage contains a virus...
Also, look for a file named 'readme.eml' , i have already had a poor user
upload pages from an infected machine, it will stuck itself into web
pages apparently, and then try to spread into browsers...which is where
the anti-virus software (hopefully) notices it...If you do find that file
you will also have to find the page(s) that have the hava script loader
that makes the browser grab it...
Will probably look something like this cute little fragment...
... language="JavaScript">window.open("readme.eml", null,
"resizable=no,top=6000,left=6000") /script
(Edited slightly to ensure it won't actually work in the archives -/)
sigh
gsh