Re: mymail worm

2004-02-08 Thread s. keeling
Incoming from Mike Fedyk: > On Wed, Feb 04, 2004 at 10:07:22AM -0700, s. keeling wrote: > ># Put A TAB Character Between [] Brackets Below. > > * 1^0 ^[ ]charset=.?Windows-1252.? > > Can't you use "\t" or "$'\t'" there instead of using an actual tab character? Son of a gun. Apparently y

Re: mymail worm

2004-02-08 Thread Mike Fedyk
On Wed, Feb 04, 2004 at 10:07:22AM -0700, s. keeling wrote: ># Put A TAB Character Between [] Brackets Below. > * 1^0 ^[ ]charset=.?Windows-1252.? Can't you use "\t" or "$'\t'" there instead of using an actual tab character? -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subje

Re: mymail worm

2004-02-05 Thread Brian Potkin
On Wed, Feb 04, 2004 at 08:24:52PM -0500, Wayne Topa wrote: > Brian Potkin([EMAIL PROTECTED]) is reported to have said: > > > > Its usefulness in deleting spam and mail associated with the mymail worm > > before downloading it has been offset by the deletion of a small num

Re: mymail worm

2004-02-04 Thread Paul Johnson
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Wed, Feb 04, 2004 at 01:59:32AM +, Antony Gelberg wrote: > Anyone have a similar rule to nuke this new mymail worm? I have some > samples if anyone can tell me how to analyse them to paste the correct > thing in the BD line. Sure

Re: mymail worm

2004-02-04 Thread Wayne Topa
Brian Potkin([EMAIL PROTECTED]) is reported to have said: > On Wed, Feb 04, 2004 at 02:10:55PM +, Pigeon wrote: > > > On Wed, Feb 04, 2004 at 01:59:32AM +, Antony Gelberg wrote: > > [Snip] > > > > Anyone have a similar rule to nuke this new mymail worm?

Re: mymail worm

2004-02-04 Thread Brian Potkin
On Wed, Feb 04, 2004 at 02:10:55PM +, Pigeon wrote: > On Wed, Feb 04, 2004 at 01:59:32AM +, Antony Gelberg wrote: [Snip] > > Anyone have a similar rule to nuke this new mymail worm? I have some > > samples if anyone can tell me how to analyse them to paste the correct &

Re: mymail worm

2004-02-04 Thread Pigeon
s going around: > :0 > * > 14 > * < 165000 > { > :0 BD > * b3IAAABBZG1pbgAAAEdFVCBodHRwOi8vd3cyLmZjZS52dXRici5jei9iaW4vY291bnRlci5naWYv > /dev/null > } > > Anyone have a similar rule to nuke this new mymail worm? I have some > samples if anyone can tell me

Re: mymail worm

2004-02-04 Thread s. keeling
Incoming from Antony Gelberg: > > Anyone have a similar rule to nuke this new mymail worm? I have some Last I heard, this one is morphing itself continuously, meaning signatures aren't going to work. I found (something like) this in comp.mail.misc a few days ago. There are a spac

Re: mymail worm

2004-02-04 Thread Hans du Plooy
On Wednesday 04 February 2004 03:59, Antony Gelberg wrote: > :0 > > * > 14 > * < 165000 > { > > :0 BD > > * > b3IAAABBZG1pbgAAAEdFVCBodHRwOi8vd3cyLmZjZS52dXRici5jei9iaW4vY291bnRlci5naWY >v /dev/null Which virus is this? thanks -- Kind regards Hans du Plooy hansdp at newingtoncs dot co dot za

Re: mymail worm

2004-02-03 Thread Jacob S.
On Wed, 4 Feb 2004 01:59:32 + Antony Gelberg <[EMAIL PROTECTED]> wrote: > Anyone have a similar rule to nuke this new mymail worm? I have some > samples if anyone can tell me how to analyse them to paste the correct > thing in the BD line. Hello Antony, Here's a

mymail worm

2004-02-03 Thread Antony Gelberg
000 { :0 BD * b3IAAABBZG1pbgAAAEdFVCBodHRwOi8vd3cyLmZjZS52dXRici5jei9iaW4vY291bnRlci5naWYv /dev/null } Anyone have a similar rule to nuke this new mymail worm? I have some samples if anyone can tell me how to analyse them to paste the correct thing in the BD line. A -- Please don't CC me. Also _please_ read the following before postin