Beyond the beyond, and not in a good way

*Even a boiled frog has to realize that

it's getting hot every once in a while.

Look at this reportage here. This

is worldwide viral chaos. People,

this just isn't going to do.

*From SANS. I read them all the time.

Just lately, it's been like watching a truck head for

a precipice.

VULNERABILITY UPDATES AND EFFECTS

–Malicious "Witty" Worm Exploits Firewall Holes and Overwrites Data on Hard Drives

(21 March 2004)

http://www.theregister.co.uk/content/56/36413.html

http://www.washingtonpost.com/ac2/wp-dyn/A11310-2004Mar20?language=printer

[Editor's Note (Tan): If you are running the vulnerable BlackICE version and you have not corrected the problem, you will be infected immediately when you connect your system to the Internet. Imagine trusting the firewall to protect your system from attacks, but the firewall actually causes the damage. This worm spreads like Slammer, fast and destructive, through UDP. And being memory resident, most anti-virus scanners are not able to detect it. From what I have seen, SANS Internet Storm Center is the first site that reported this worm. Johannes Ullrich has done a great job in getting the alert out and elevating to yellow infocon level.]

–Bagle Variants Q, R, S & T Exploit IE Object Data Remote Execution Vulnerability

(19/18 March 2004)

http://www.computerworld.com/printthis/2004/0,4814,91408,00.html

http://www.theregister.co.uk/content/56/36362.html

http://news.com.com/2102-7355_3-5175727.html?tag=st.util.print

http://www.techweb.com/wire/story/TWB20040318S0009

[Editor's Note (Tan): This is going to be a record. Hitting Z soon, so

what is the letter after Z?]

–Bagle Variants N, O & P Hide Zip File Password in Graphic File, Seek to Destroy Netsky

(16/15 March 2004)

http://www.zdnet.co.uk/print/?TYPE=story&AT=39149030-39020330t-10000025c

http://www.zdnet.co.uk/print/?TYPE=story&AT=39149316-39020375t-10000025c

–Phatbot Trojan Spreads via P2P Technology, Launch DDoS Attacks and Steals Data

(21/18/17 March 2004)

http://www.computerworld.com/printthis/2004/0,4814,91365,00.html

http://news.com.com/2102-1009_3-5175025.html?tag=st.util.print

http://www.theregister.co.uk/content/6/36414.html