- Feature Articles
- CodeSOD
- Error'd
- Forums
-
Other Articles
- Random Article
- Other Series
- Alex's Soapbox
- Announcements
- Best of…
- Best of Email
- Best of the Sidebar
- Bring Your Own Code
- Coded Smorgasbord
- Mandatory Fun Day
- Off Topic
- Representative Line
- News Roundup
- Editor's Soapbox
- Software on the Rocks
- Souvenir Potpourri
- Sponsor Post
- Tales from the Interview
- The Daily WTF: Live
- Virtudyne
Admin
Admin
Whiskey? Where???
Admin
Admin
I'd sooner kiss a pig.
(or perhaps that was what you had in mind)
Admin
Admin
That definitely qualifies as "improbable".
Admin
I thought it was a Vin Diesel movie.
Admin
Admin
Admin
Admin
Exactly. My theory for this bastard pluralization is that it comes from radius, radii. Except that virus isn't virius.
Admin
Admin
From whence springs "virile" and hence "Viagra".
Admin
What's a moran? I had a professor Moran once. He was a moron.
Admin
Admin
Admin
Admin
Even if he hit Del not Enter, he still gets prompted, "Are you sure you want to mess up the universe?", right? Plus recycle Bin.
Or is Exchange Server different to my every day Windoze experience?
Admin
Admin
Admin
Admin
This is why some of the smarter anti-virus systems hide the quarantine and only allow you to delete or restore using their interface.
Admin
"Command not found" "Command not found" "Command not found" "Command not found" "Command not found" "Command not found" "Command not found" "Command not found" "Command not found"
Admin
Admin
Right Click the article and select "View SOurce". There is an explanation....
Admin
So hotxxx.jpg = Hot, very spicy food photos.
Guillermo must work in the food industry.
/I'm telling you Akismet, this is not spam!/
Admin
Admin
(Besides, I kind of like the default being the way it is, since it makes it harder for clients to rename a Photoshop file to a .jpg. Power users can always change the option.)
Admin
Why doesn't the virus scanner mark all files moved to the quarantine folder as deny-execute-all?
....
captcha: validus, as in, this is a validus question.
Admin
The real WTF is even scanning for stuff in email messages.
What the user doesn't have a virus scanning program on is system? And don't say defense in depth. It's not the same thing. Having 5 check points to get into a protected area and at all five you have the same idiot making the same mistakes is not defense in depth.
How about if the email is not going to a windows machine, ever. Send all the windows malware you want, it's meaningless.
How about you reject mal from known known spam sources on the fly, then you never have to scan it to start with. Oh, I forgot, Exchange, you can't put 3 lines in your sendmail.cf that will check a dynamic black hole list. It simple almost no cost and dumps close to 99% of spam and malware.
Oh I forgot, no money in selling that solution, since you don't have to buy software. None of the "experts" will tell you about a free thing.
Admin
All virus scanners I've seen renames files placed in quarantine (e.g. adding .vir to the file names) if they're accessible through the file system. Furthermore some of them might also prevent execution through NTFS deny permissions.
Now, if the point is that he was executing the 10k virus exes, so what? The scanner could already detect those, else they wouldn't be quarantined.
And if the point is "wow, 10k files executed simultaneously bogs the server down", I'd say "so what? That shouldn't take long. If it actually made the server perform bad for more than a few minutes, the customer has other, much worse problems....
Something's wrong here.
TRWTF is the performance of NTFS, especially in folders with 30k+ files...
Admin
Well, it'd be pretty stupid to enter a command like that in the first place, but even if you did it would ask you for your password and then only execute it if you had permissions to use sudo :)
However, I'm wondering what really happened here. As several people have already pointed out, Windows would ask if you really wanted to open 10,000 files. Also, is there any virus scanner which doesn't encrypt / mangle the files before archiving / quarantining them?
Admin
While I wouldn't recommend opening up 10,000 suspicious-looking attachments, we should be aware that the only stuff that goes into the quarantine folder is the stuff that the virus scanner has already caught.
So there's wasn't much risk of infection here.
Admin
Not only is the plural of "virus" not "virii", there is no word in the entire English language -- or Latin language -- where -us becomes -ii in the plural. People are probably thinking of radius -> radii, but it's only the -us that changes: radi-us, radi-i.
CAPTCHA: vindico. Seems fitting somehow.
Admin
Sometimes they conspire with accounts to do an end run around IT and stupidly get a laptop via "salary sacrifice" instead of the company providing it to them for free. Then they have either no antivirus or nothing after a trial period.
Sometimes they have antivirus and delete it in an attempt to speed up thier computers.
Sometimes they deliberately download something that contains malware which nukes their antivirus. In some cases the useful appearing malware vector will have installation instructions that include turning off antivirus, so it doesn't matter how good or bad the antivirus is, it still gets nuked.
Sometimes the mail servers antivirus is all the users have between them and all the malware on the net.
Admin
(which is why you alias rm=rm -i, but anyway...)
Admin
We scan for viruses in emails for the same reason we scan for spam: it's a waste of time to receive them. And, viruses are pretty low-hanging fruit in this regard as the majority can be efficiently detected with very low overheads and almost no chance of a false positive. The "cost" of doing this is tiny compared to the time it saves.
Additionally, it's quite possible to use a different virus scanner for your email than you install on desktops, which does provide some measure of "defense in depth". If one vendor misses the virus, another might not.
Admin
Admin
Admin
On Linux I just can install bumblebee http://www.sysadmin.im/2011/06/20/47.html
Admin
423,827 Viruses found!
Admin
It's Exchange. You type the dynamic black list url into the appropriate text-entry field.
The TWTF is Lusers who think that they understand Exchange and network admin because they've installed sendmail once.
Admin
"The Plural of Virus is not Virii"
Next you're going to tell us that tha plural of box is not boxen???
Admin
Admin
Not Virii. If it would be a latin word, it would be virus - viri (one i).
As it was not known in ancient times and hence not a latin word, we use the english way of pluralization : viruses. But someone else said that already I reckon...
Admin
It's a seriously beautiful and cool place to live, though.
As for opening thousands of files... once, on an Windows NT 4.0 system, I accidentally pressed 'Enter' after I'd selected some 6000 folders. Mind, this was in the mid nineties, when computers were still steam-powered.
Rather than crashing, what you'd expect from Windows, it dutifully started opening 6000 windows, and went paging like mad. I think that eventually we just rebooted the damn thing, because it took too long.
Admin
Some people might argue that there's not much of a difference between Amsterdam and any other city in the world on this matter, apart from the presentation.
Admin
If in doubt, be evasive.
And so on.
Admin
Umm, no you can't do it in sendmail.cf, but you can do it in message delivery options. In fact you can set up blacklists, whitelists, set up different return codes and rejections criteria, exceptions . . . .
Admin