[Dshield] Sobig Help

Allan Liska allan at allan.org
Thu Aug 21 02:39:22 GMT 2003


-----BEGIN PGP SIGNED MESSAGE-----
Hash: MD5

Hello John,

Wednesday, August 20, 2003, 9:16:14 PM, you wrote:

JD> http://www.lurhq.com/sobig.html

JD> Go here - and it should give you instructions for removal...  but if you
JD> really want to catch the person who infected your mother-in-law,  you could install an IDS on your network,  and using the Snort rule in the URL above,  you can catch the perpetrator the next
JD> time they try to log into her computer.

Thanks for the link.  As far as who infected her, she did that
herself.  Like millions of other people today, she received a ton of
messages with infected attachments and just made the mistake of
clicking on one :).  No need for IDS's etc on her network, unless you
have a pebcak IDS ;).


allan
- --
Allan Liska
allan at allan.org
http://www.allan.org
http://www.hosthideout.com

-----BEGIN PGP SIGNATURE-----
Version: 2.6

iQCVAwUAP0Qw4Ckg6TAvIBeFAQGf4QQAtBq4zRjVHWWE4U5fCvmakVmdq0Je9N10
iNKg5W8tNpaehS7wQboyDpBwSjPM1nuxD4mR4Gzx0kTpWWoPDZYKUNnKa+1HNDht
M2zv5J30MesgbRb2G8jHtxJlQHLSdFqetf6ZOOIzrQY/VlNvMFC+ZZDlOeFa6WQn
V8vZMz716F4=
=Lstt
-----END PGP SIGNATURE-----





More information about the list mailing list