YOU ARE DOWNLOADING DOCUMENT

Please tick the box to continue:

Transcript
Page 1: Klez 101

Klez 101Michael Shumko

Page 2: Klez 101

What’s Coming Up

The Klez Virus/Worm How Klez Gets In Damage Distribution Protection Next Steps To Learn More

Page 3: Klez 101

The Klez Virus/Worm

Klez first appeared in October 2001

Variants are still making the rounds in September 2002

Affects Windows computers Does not affect Macintosh, Unix,

Linux, others

Page 4: Klez 101

How Klez Gets In

Exploits a vulnerability of Microsoft Outlook Microsoft Outlook Express Microsoft Internet Explorer 5.x

No need to execute the attachment Simply open or preview the

message

Page 5: Klez 101

Preview Pane

Page 6: Klez 101

Damage

Infects executable files with itself Copies itself to network shares Disables some common anti-virus

products Sets itself up to start with Windows Drops a copy of the Elkhern virus

Damages files by overwriting with zeros

Page 7: Klez 101

Distribution

Large scale e-mailing Uses its own SMTP engine Subject and attachment name are

random May release confidential data

Page 8: Klez 101

Distribution (cont.)

“To” addresses found in Local files Windows and ICQ address books

“From” address is spoofed Can masquerade as an immunity

tool Can masquerade as “postmaster

bounce” messages

Page 9: Klez 101

Distribution (cont.)

Your PCAnti-Virus

ISPAnti-Virus

Klez worm

Outlook Mail service

FIREWALL

Page 10: Klez 101

Protection

Use basic security “best practices” Keep patch levels up to date Scan incoming mail for viruses Use firewall to stop outbound

Page 11: Klez 101

Next Steps

Page 12: Klez 101

To Learn More

My web site http://members.shaw.ca/mike-

shumko/av/ Microsoft security bulletins

MS01-020 re MIME headers Anti-virus manufacturers

Norton / Symantec McAfee

Page 13: Klez 101

Thank you


Related Documents