Vulnerability Development mailing list archives

Re: CodeGreen beta release (idq-patcher/antiCodeRed/etc.)


From: Markus Kern <markus-kern () gmx net>
Date: Thu, 06 Sep 2001 13:16:06 +0200


"Alexander Sarras (SEA)" wrote:

It might be discussable installing a - easily uninstallable - routine
which send emails and (broadcast) messages to admin account
accessible from the infected box, stating very clearly what to do 1)
to get rid of the worm 2) to get rid of that utility afterwards. But
surely not another virus.

The only correct way IMHO is to shut of the access to the networks
for offenders. Via the direct ISP or the upstreams. This has been
done before, and this works.

Ron DuFresne's <dufresne () winternet com> post indicates that this method
doesn't always work as well as we'd like it to.

Personally I prefer a technical solution to begging and court orders.
http://www.technocracyinc.org/images/cbusses.jpg illustrates my point
quite accurately.

Markus Kern


Current thread: