PermaLink Another reason not to use port 25 for message submission
F-Secure reports:

When application in infected system sends data to network [sic], Feebs [the malware being described here] makes some extra checks. If it detects traffic to port 25 (SMTP default port) which looks like e-mail with MIME attachment, it generates the HTA script and injects it in e-mail as extra attachment.

This is a sophisticated trick designed to inject malware into an otherwise legitimate email rather than the usual trick of creating an email specifically for the purpose of delivering malware.

Of course any Notes/Domino shop eschews SMTP completely for message submission and internal transfers, doesn't it? We all use NRPC (TCP:1352) for those things. Right?

Category: Viruses and Worms
Technorati:

Comments :

1. Nathan T. Freeman19/01/2006 15:25:51


I do. I've never understood why people do Notes-to-Notes via SMTP. It just seems retarded to me.




2. Simon Barratt20/01/2006 20:48:38
Homepage: http://apps.fmc.com/blog.nsf


Of course we do, why use SMTP for Domino server to server?




Unable to post a comment? Please read this for a possible explanation...
Add Manual Trackback
Please enter the details of the trackback post. Your trackback will not appear on the site until it has been verified. This won't be immediate, as trackbacks are validated on a scheduled basis. Be patient.











Search
Popular Categories
Monthly Archive
Other stuff
ClustrMaps
Contact Me
Meta
Proudly powered by IBM Lotus Domino 8 Proudly powered by IBM Lotus Domino 8

Subscribe to articles Subscribe to articles feed

Subscribe to comments Subscribe to comments feed

ROR info ROR info


My Amazon wish list Wishlist


Wikio - Top Blogs - Technology
Like what I do?
Research Autism Then please consider a donation to support the work of Research Autism.
Idea Jam
Planet Lotus
Dilbert