Vu sur contribs
Can anyone help me by giving an example how to block port 81 using Muzo's masq-manager or iptables (i'm using sme 5.6u6) ? Seems like there is an explosion of Bagle & Netsky
Quot
Using this exploit, this virus sends an email message, which does not contain an attachment but a link to the virus copy in a remote location. Once the email is viewed, the message body connects to a remote site that contains an .HTA Web page. This Web page contains a Visual Basic (VB) script, which drops a VBScript file in the Windows system folder via port 81. The dropped file, which uses the file name Q.VBS, then accesses a remote location in order to download and execute a copy of PE_BAGLE.Q.
pour anglophbe, vous recevez un mail avec un lien qui pointe vers le virus.. donc l'av de messagerie n'y voit que du feu...
A+