PowWeb Forums - The Perfect Community for the Perfect Host  

Register now to interact with over 11,000 members! Registered users have Posting Privileges, free access to Private Messaging, Email Notifications and more.

Go Back   PowWeb Community Forums > Other Forums > Computer Help
User Name
Password
Register FAQ Members List Search Today's Posts Mark Forums Read

Closed Thread
 
Thread Tools
Old 10-7-02, 04:32 PM   #1
johnw
Guest
 
Posts: n/a
Daily virus attacks making me look bad . . .

Hi everyone

One of our cients is suffering regular daily email virus attacks . . . and he's hosted here on PowWeb. I've had a quick look round and understand there's no anti-virus protection provided by PowWeb, basically because they don't wish to be involved in deciding what is, or is not, a 'good attachment.'

Fair enough. I guess I'd be of the same mind if I was operating in litigious ole US of A. But my client still has his problem, and he expects me to solve it.

Bear in mind I'm a graphic designer, not a techie. I simply installed Nortons on the network server. I figured, "stop the viruses before they reach anyone's machine."

Problem is, when infected emails arrive they often cause interruptions to other users on the network, even crashes, as Norton does his job.

Any other solutions I might try?

Thanks in advance

John

PS: I'm posting this on a couple of other PowWeb forums, as I need an answer, quick smart, on this.
 
Old 10-7-02, 06:36 PM   #2
paulselhi
Cockney Red
 
paulselhi's Avatar
 
Join Date: Feb 2002
Location: London UK
Posts: 2,875
Reputation: 15
what o/s are they using ?

and do you have a firewall in place? what mail servers are they using if any, and are these in a DMZ (demiliterized zone)

unfortunately virus attacks are a part of life when you connect to the net and some companies will attract more attention than others

if you think your company is particulary a target then you would be well advised to bring in a third party security consultancy not only for viral attacks but also for general anti-hacker security

if the firm is being "targeted" for viral attacks then it may well be targeted by hackers as well

if the number of attacks is exceptionally high as in your case you may well have been compromised already and i would strongly suggest getting some outside security advice
paulselhi is offline  
Old 10-7-02, 07:36 PM   #3
teamantivir
Living at command prompt
 
teamantivir's Avatar
 
Join Date: Feb 2002
Posts: 157
Reputation: 5
Re: Daily virus attacks making me look bad . . .

Quote:
Originally posted by johnw
Hi everyone

One of our cients is suffering regular daily email virus attacks . . . and he's hosted here on PowWeb. I've had a quick look round and understand there's no anti-virus protection provided by PowWeb, basically because they don't wish to be involved in deciding what is, or is not, a 'good attachment.'

Please see my advice in the Utilities section. Again as well intentioned as many people are, beware of False Authority Syndrom (See http://www.vmyths.com for a definition).
__________________
Kenneth L, Bechtel, II
Team Anti-Virus
PGP Footprint: 969E 2A27 3042 EE52 AEFB 6FF0 2711 9467 D38C 5C0F
teamantivir is offline  
Old 10-7-02, 07:46 PM   #4
paulselhi
Cockney Red
 
paulselhi's Avatar
 
Join Date: Feb 2002
Location: London UK
Posts: 2,875
Reputation: 15
i take it you refer to this:

"Most people who claim to speak with authority about computer viruses have little or no genuine expertise. Some virus experts describe it as "False Authority Syndrome" -- the person feels competent to discuss viruses because of his job title, or because of his expertise in another computer field, or simply because he knows how to use a computer."

i was only suggesting that if he feels that he is getting an abnormal amount of virus alerts he would be well advised to have a third party security analyses, i don't see this as FAS but as SPaSA- sensible proactive security advice !!!!
paulselhi is offline  
Old 10-8-02, 08:03 AM   #5
teamantivir
Living at command prompt
 
teamantivir's Avatar
 
Join Date: Feb 2002
Posts: 157
Reputation: 5
Re: i take it you refer to this:

Quote:
Originally posted by paulselhi
i was only suggesting that if he feels that he is getting an abnormal amount of virus alerts he would be well advised to have a third party security analyses, i don't see this as FAS but as SPaSA- sensible proactive security advice !!!!
I wasn't addressing you specifically, you gave some good advice, I was just waning him some people are going to try to give him some detailed advice with out knowing the facts. I can almost hear it, "I use Scuzzy Scan, and have never had a virus, Your client should use it, because nothing else is as good", or "install the following rules on your mail server, and it will fix everything." I really get a sick feeling when I see that advice. Yours was right on target.
__________________
Kenneth L, Bechtel, II
Team Anti-Virus
PGP Footprint: 969E 2A27 3042 EE52 AEFB 6FF0 2711 9467 D38C 5C0F
teamantivir is offline  
Old 10-8-02, 10:02 AM   #6
paulselhi
Cockney Red
 
paulselhi's Avatar
 
Join Date: Feb 2002
Location: London UK
Posts: 2,875
Reputation: 15
i thank you

i am at this very moment removing the needles from your wax effigy
paulselhi is offline  
Old 10-8-02, 10:12 AM   #7
paulselhi
Cockney Red
 
paulselhi's Avatar
 
Join Date: Feb 2002
Location: London UK
Posts: 2,875
Reputation: 15
Now why would we be a target ?

i was once called in to a large synagouge in london to sort out their exchange 5.5mail problems

they had their WHOLE operation running on one NT server- it was the pdc, mail server, application server (including all their financial data),webserver

They had already been compromised and i asked where their back up device was,. Backup? no we don't have one as yet

I asked them if they had a firewall, no we have several extinguishers and buckets of sand

i told them that i wouldn't touch their setup untill they had a backup in place and that unfortunately they had already been compromised, the web page had become colorfull to say the least

i also suggested thet they at least get another machine as a BDC and probably a seperate member server for their finnacial data and kept this on it's own network

they suggested that i was trying to hoodwink them into buying more kit, and anyway why should they be a target !!!!!!!
paulselhi is offline  
Old 10-8-02, 12:15 PM   #8
teamantivir
Living at command prompt
 
teamantivir's Avatar
 
Join Date: Feb 2002
Posts: 157
Reputation: 5
Re: Now why would we be a target ?

Quote:
Originally posted by paulselhi
They had already been compromised and i asked where their back up device was,. Backup? no we don't have one as yet

I asked them if they had a firewall, no we have several extinguishers and buckets of sand

i told them that i wouldn't touch their setup untill they had a backup in place and that unfortunately they had already been compromised, the web page had become colorfull to say the least

i also suggested thet they at least get another machine as a BDC and probably a seperate member server for their finnacial data and kept this on it's own network
Been there done that, went for the t-shirt and they were back ordered. It gets worse when you have the reply well we paid XXXX Consultancy, they said this was enough. Never mind the fact it was 10 years ago, and thing change, but the original colsultancy is out of business and specialize in stand-alone systems, so why should MY answer be any different from the original?
__________________
Kenneth L, Bechtel, II
Team Anti-Virus
PGP Footprint: 969E 2A27 3042 EE52 AEFB 6FF0 2711 9467 D38C 5C0F
teamantivir is offline  
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 06:15 PM.


Contents ©PowWeb, Inc. ~ vBulletin, Copyright © 2000-2007 Jelsoft Enterprises Limited.