Page 1 of 1

VIR/W32.Petch

Posted: Sun Mar 07, 2004 9:04 pm
by PHANTOm

Code: Select all

spamfilter {
	regex "\/britney\.jpg <- uuh, check it out !! :D$";
	target { channel; };
	action viruschan;
	reason "VIR/W32.Petch";
};

Posted: Sun Mar 07, 2004 9:11 pm
by codemastr
That's the same as the "Fagot" worm which we already detect. And actually we detect more than just britney.jpg, there are many varieties. jessica_alba.jpg, jenna_jameson.jpg, etc.

Posted: Sun Mar 07, 2004 9:24 pm
by PHANTOm
i actually agree the regexp provided in spamfilter.conf for this is more comprihensive but may lead to false positives.

Code: Select all

spamfilter {
	regex "^http://www\.angelfire\.com/[a-z0-9]+/[a-z0-9]+/[a-z_]+\.jpg <- .*!";
	target private;
	reason "Infected by fagot worm: see http://www.f-secure.com/v-descs/fagot.shtml";
	action block;
};

Posted: Sun Mar 07, 2004 9:40 pm
by codemastr
Perhaps, but only in very rare incidents.

Posted: Mon Mar 08, 2004 12:44 am
by Syzop
<0.001% (prolly even less) false positives are acceptable to me.
Let's please stay realistic and not pissed at each other if someone else's regex / spamfilter block is better ;).

Posted: Mon Mar 08, 2004 6:24 pm
by Tracer
Couldn't agree more on you Syzop




Cheers! :D