Page 1 of 1
VIR/W32.Petch
Posted: Sun Mar 07, 2004 9:04 pm
by PHANTOm
Code: Select all
spamfilter {
regex "\/britney\.jpg <- uuh, check it out !! :D$";
target { channel; };
action viruschan;
reason "VIR/W32.Petch";
};
Posted: Sun Mar 07, 2004 9:11 pm
by codemastr
That's the same as the "Fagot" worm which we already detect. And actually we detect more than just britney.jpg, there are many varieties. jessica_alba.jpg, jenna_jameson.jpg, etc.
Posted: Sun Mar 07, 2004 9:24 pm
by PHANTOm
i actually agree the regexp provided in spamfilter.conf for this is more comprihensive but may lead to false positives.
Code: Select all
spamfilter {
regex "^http://www\.angelfire\.com/[a-z0-9]+/[a-z0-9]+/[a-z_]+\.jpg <- .*!";
target private;
reason "Infected by fagot worm: see http://www.f-secure.com/v-descs/fagot.shtml";
action block;
};
Posted: Sun Mar 07, 2004 9:40 pm
by codemastr
Perhaps, but only in very rare incidents.
Posted: Mon Mar 08, 2004 12:44 am
by Syzop
<0.001% (prolly even less) false positives are acceptable to me.
Let's please stay realistic and not pissed at each other if someone else's regex / spamfilter block is better ;).
Posted: Mon Mar 08, 2004 6:24 pm
by Tracer
Couldn't agree more on you Syzop
Cheers!
