ãæè¿ããšãããSWEN.Aãæµè¡ãå§ããŠãããšãããã®ããã®ã¯ãŒã ãæ·»ä»ãã
ãã¡ãŒã«ã倧éã«ïŒïŒæ¥ïŒïŒéååŸïŒå±ãããã«ãªããŸããã
ããŠã£ã«ã¹å¯Ÿçãœããããã¡ã€ã¢ãŠã©ãŒã«ãããã®ã§ã»ãã¥ãªãã£çã«ã¯åé¡ãª
ãã®ã§ããããããããé§é€ããŠãã¡ãŒã«èªäœãã«ããããŠãããããã§ã¯ãªã
ïŒãŠã£ã«ã¹ãé€å»ããç¶æ
ã§ã¡ãŒã«ã¯å±ãïŒã®ã§ãéªéã§ä»æ¹ãããŸãã^^;
â»WinXPã§ãŠã£ã«ã¹ãã¹ã¿ãŒïŒïŒïŒïŒäœ¿çš
ãã§ããªããšãã¡ãŒã«ã¯ã©ã€ã¢ã³ãã§ãã®ã¯ãŒã ã®ã¡ãŒã«ããŽãç®±è¡ãã«ããã
ãããã¯ïŒ©ïŒ³ïŒ°ã®ãµãŒãã¹ã§ã¡ãŒã«ããã¯ã¹ã«å±ããæç¹ã§åé€ããããããã®
ã§ããããã®ã¯ãŒã ããéãããŠããã¡ãŒã«ã®ãããã§èå¥ããæ¹æ³ã¯ããã®ã§
ããããïŒ
ãSubjectã¯ããªãçš®é¡ãããããã§ããã容æã«å€å¥ã§ãããã®ããããšå©ã
ãã®ã§ããâ¥â¥
ããããã®ãããããåãã®æ¹ãããã£ããããŸãããæããŠé ããŸããšå¹žãã§
ãã
以äž
In article <200310052020...@sfc.ne.jp>, åŸè€è²Žæš¹<go...@sfc.ne.jp> writes
> ãSubjectã¯ããªãçš®é¡ãããããã§ããã容æã«å€å¥ã§ãããã®ããããšå©ã
> ãã®ã§ããâ¥â¥
Subjectã¯ç¡çã¿ããã§ãã
> ïŒãŠã£ã«ã¹ãé€å»ããç¶æ
ã§ã¡ãŒã«ã¯å±ãïŒã®ã§ãéªéã§ä»æ¹ãããŸãã^^;
> â»WinXPã§ãŠã£ã«ã¹ãã¹ã¿ãŒïŒïŒïŒïŒäœ¿çš
ã ãšããã°ããªããã¡ãŒã«ã«ããŒã¯ãä»ããŠãŸããã? ããã§åé€
ãããšè¯ããšæããŸãã
---
Shinji KONO @ Information Engineering, University of the Ryukyus,
æ²³éçæ²» @ çç倧åŠå·¥åŠéšæ
å ±å·¥åŠç§,
> åŸè€ãšç³ããŸãã
>
> ãæè¿ããšãããSWEN.Aãæµè¡ãå§ããŠãããšãããã®ããã®ã¯ãŒã ãæ·»ä»ãã
> ãã¡ãŒã«ã倧éã«ïŒïŒæ¥ïŒïŒéååŸïŒå±ãããã«ãªããŸããã
>
> ããŠã£ã«ã¹å¯Ÿçãœããããã¡ã€ã¢ãŠã©ãŒã«ãããã®ã§ã»ãã¥ãªãã£çã«ã¯åé¡ãª
> ãã®ã§ããããããããé§é€ããŠãã¡ãŒã«èªäœãã«ããããŠãããããã§ã¯ãªã
> ïŒãŠã£ã«ã¹ãé€å»ããç¶æ
ã§ã¡ãŒã«ã¯å±ãïŒã®ã§ãéªéã§ä»æ¹ãããŸãã^^;
> â»WinXPã§ãŠã£ã«ã¹ãã¹ã¿ãŒïŒïŒïŒïŒäœ¿çš
>
> ãã§ããªããšãã¡ãŒã«ã¯ã©ã€ã¢ã³ãã§ãã®ã¯ãŒã ã®ã¡ãŒã«ããŽãç®±è¡ãã«ããã
> ãããã¯ïŒ©ïŒ³ïŒ°ã®ãµãŒãã¹ã§ã¡ãŒã«ããã¯ã¹ã«å±ããæç¹ã§åé€ããããããã®
> ã§ããããã®ã¯ãŒã ããéãããŠããã¡ãŒã«ã®ãããã§èå¥ããæ¹æ³ã¯ããã®ã§
> ããããïŒ
ãããã ãã®æ¡ä»¶ã ãšå³ãããããããŸããã
multipart ãªã¡ãã»ãŒãžã¯å
šãŠæšãŠããšãããèŠæãããã°å¥ã§ããã
ãŠã£ã«ã¹ãã¹ã¿ãŒã¯ç¥ããªãã®ã§èªåã®å Žåãèªåã®ç°å¢ã«åããŠãããŸãã
䜿çšç°å¢ã¯
Windows XP(Pro), NetscapeCommunicator4.8, NortonAntiVirus2003
ã§ãããNetscapeCommunicatorã®Message Filters for Inbox ã«
condition=" OR (body,contains,Norton AntiVirus ãåé€ããŸãã1.txt)"
condition=" OR (body,contains,application/x-msdownload;)"
condition=" OR (body,contains,audio/x-wav;)"
condition=" OR (body,contains,audio/x-midi)"
condition=" OR (body,contains,this is the latest version of security update)"
ã®ããããã«ããããããã®ãã¿ãª ~virus ãã©ã«ããžæ¯ãåãããã
èšå®ããŠããŸããããã§95%ã¯ã«ããŒããããããªãã§ãããã?
ãã ãããã®æ¯ãåãæ¡ä»¶ãæå¹ã«ãããšã¡ã€ã«ããšã£ãŠããã®ããšãŠã
æéããããããã«ãªããŸãã
--
mailto:shi...@dd.iij4u.or.jp æžè°·äŒžæµ©
On Sun, 05 Oct 2003 22:44:18 +0900
"Shibuya, Nobuhiro" <shi...@dd.iij4u.or.jp> wrote:
> ãããã ãã®æ¡ä»¶ã ãšå³ãããããããŸããã
> multipart ãªã¡ãã»ãŒãžã¯å
šãŠæšãŠããšãããèŠæãããã°å¥ã§ããã
ïŒäžç¥ïŒ
> ã®ããããã«ããããããã®ãã¿ãª ~virus ãã©ã«ããžæ¯ãåãããã
> èšå®ããŠããŸããããã§95%ã¯ã«ããŒããããããªãã§ãããã?
> ãã ãããã®æ¯ãåãæ¡ä»¶ãæå¹ã«ãããšã¡ã€ã«ããšã£ãŠããã®ããšãŠã
> æéããããããã«ãªããŸãã
ãªãã»ã©ã
ãŠã£ã«ã¹ãã¹ã¿ãŒïŒïŒïŒïŒã§ã¯ããã«ãããŒãã§
ãã¡ãŒã«æ€çŽ¢æ©èœã«ãããŠã€ã«ã¹ãæ€åºãããæ·»ä»ãã¡ã€ã«ãåé€ãããŸãããã
ãšããããã¹ãã®ããŒãã远å ããã ããªãã§ãããã
ãŠã£ã«ã¹ã¡ãŒã«ãå
šãŠäžæ¬ã§äŸãã°virusãšãã®ãã©ã«ããäœã£ãŠç§»åããŠããŸ
ãã ããªãã§ãããã§ããã
ããã§ã倧äžå€«ãªãã§ããããïŒãäŸãã°SWEN.Aã¯ãããšããŠããä»ã§å®éã«èª°
ããæžããã¡ãŒã«ã«åæã«ãŠã£ã«ã¹ãæ·»ä»ãããããšãã£ããã¡ãŒã«æ¬æã«å
容
ãããã¡ãŒã«ã ã£ããããããšã¯ç¡ãã®ã§ããããïŒ
ããããã®å¿é ããªããã°ãäžæ¬ã§æ¯ãåãã¡ãããŸããã©^^
ããã®ãããããããåãã§ããã°ãé¡ãããŸããm(..)m
--
åŸè€
> ãã§ããªããšãã¡ãŒã«ã¯ã©ã€ã¢ã³ãã§ãã®ã¯ãŒã ã®ã¡ãŒã«ããŽãç®±è¡ãã«ããã
> ãããã¯ïŒ©ïŒ³ïŒ°ã®ãµãŒãã¹ã§ã¡ãŒã«ããã¯ã¹ã«å±ããæç¹ã§åé€ããããããã®
> ã§ããããã®ã¯ãŒã ããéãããŠããã¡ãŒã«ã®ãããã§èå¥ããæ¹æ³ã¯ããã®ã§
> ããããïŒ
>
> ãSubjectã¯ããªãçš®é¡ãããããã§ããã容æã«å€å¥ã§ãããã®ããããšå©ã
> ãã®ã§ããâ¥â¥
Outlook ã®èªåä»èš³ Wizard ã§ãŽãç®±ã«æŸã蟌ãã§ããã®ã§ããããªããªãã«
é¢åã§ããAnd/Or ã®äž¡æ¹ãåæã«èšè¿°ã§ãããšå€å°ã¯æ¥œãªã®ã§ããã
ç§ã¯ 4 ã€çšã«ãŒã«ãæžããŠããŸãããããã§ãããŸã«ãããããŸãã
- å·®åºäººã®ã¢ãã¬ã¹ãã[a-z]mailprogram@, webform@, emailservice@, smtpform@,
mailform@, mailprogram@, maildaemon@, mailengine@, mailautomat@,
mailservice@, mailroutine@, postrobot@, mailbot@, webengine@,
mailerform@, masterrobot@, postservice@, webdaemon@, postform@,
postdaemon@, masterservice@, masterdaemon@, smtpengine@
ã§æ·»ä»ãã¡ã€ã«ä»ããå®å
ãšCCã«èªåã®ååããªãå Žåã«ã¯åé€ã
# æ¬åœã¯ãäžã® @ ã« aol.com ã american.net, bigfoot.com ãçµã¿åãã
# ãå Žåãšæžãããã®ã§ããããããããŸããã
- å·®åºäººã®ã¢ãã¬ã¹ããmicrosoft.com, msn.com, msdn.com, support.com,
ms.com, newsletters.com, msn.net, advisor.com, technet.com, news.net,
bulletin.com, bulletin.net, confidence.net, confidence.com, msdn.net,
support.net, updates.com, advisor.net, microsoft.akadns.net, ms.net,
microsoft.net, news.com, newsletters.net ã§çµãã£ãŠã
ä»¶åã« Security, Update, Pack, Critical, Upgrade, Internet, Network,
Patch ãå«ãã§ããŠãæ·»ä»ãã¡ã€ã«ãä»ããŠããå Žåãåé€ã
- ã¡ãã»ãŒãžãããã« multipart/mixed ãå«ãŸããŠããŠãä»¶åã«
Pack, Last Net Update, New Internet Security Pack, Network Upgrade,
Network Update, Newest Microsoft Critical Patch, New Net Critical
Upgrade,...
# æ£èŠè¡šçŸãæžããã°æ¥œã«ãªãã®ã§ãã > Outlook
# (Last|Latest|New|Newest|Current|Last)
# (Net|Internet|Network|Microsoft)
# (Security)
# (Critical)(Update|Upgrade|Pack|Patch)
# ã®çµã¿åããã§ãããã ãããã¯ç§ã®ãšããã«å±ãããµã³ãã«ãªã®ã§
# æãã¯å€ã
ãããšæããŸãã
- åä¿¡è
ã®ã¢ãã¬ã¹ããrecipient@, user@, receiver@, client@, customer@ ã§
ãããã« multipart/alternative ãå«ãŸããŠããŠãå®å
ã«èªåã®ååããªã
å Žåãåé€ã
From, Subject ã空ãšããã«ãŒã«ãæžããªãã®ã§ããã®ã¿ã€ãã®ã¡ãŒã«ã¯
ã¯ãããŸããã
--
---
Takashi SAKAMOTO(PXG0...@nifty.ne.jp)
> ãŠã£ã«ã¹ãã¹ã¿ãŒïŒïŒïŒïŒã§ã¯ããã«ãããŒãã§
> ãã¡ãŒã«æ€çŽ¢æ©èœã«ãããŠã€ã«ã¹ãæ€åºãããæ·»ä»ãã¡ã€ã«ãåé€ãããŸãããã
> ãšããããã¹ãã®ããŒãã远å ããã ããªãã§ãããã
ãã£ãšäŒŒããããªä»çµã¿ã«éããªããšæã£ãŠãŸãããäºæ³ãããã£ãã¿ããã§ãã
> ããã§ã倧äžå€«ãªãã§ããããïŒãäŸãã°SWEN.Aã¯ãããšããŠããä»ã§å®éã«èª°
> ããæžããã¡ãŒã«ã«åæã«ãŠã£ã«ã¹ãæ·»ä»ãããããšãã£ããã¡ãŒã«æ¬æã«å
容
> ãããã¡ãŒã«ã ã£ããããããšã¯ç¡ãã®ã§ããããïŒ
NortonAntiVirus ã§æ€ç«ããŠãã«ãããŒãã®ãŠã£ã«ã¹ãåŒã£ãºããããã¡ã€ã«ã§ãã
>> condition=" OR (body,contains,Norton AntiVirus ãåé€ããŸãã1.txt)"
ã§ ~virus ãã©ã«ãéãã«ãããã®ã¯ãå
·äœçã«ã¯ãã㪠mime ããŒããæã£ãŠãŸãã
ã€ãŸãæ·»ä»ãããŠãããŠã£ã«ã¹éšåã眮æããå
容ã§ãã
--qnxjybvgjsqj
Content-Type: plain/text;æ·»ä»ãã¡ã€ã«ã« W32.Swen.A@mm ãŠã€ã«ã¹ãææããŠããŸããã
name="Norton AntiVirus ãåé€ããŸãã1.txt"
Content-Transfer-Encoding: base64
Content-Id: <acczblpenf>
Tm9ydG9uIEFudGlWaXJ1cyCCqpNZlXSDdINAg0ODi4Lwje2PnIK1gtyCtYK9OiBnZmlmdi5l
eGUuDQqTWZV0g3SDQINDg4uCySBXMzIuU3dlbi5BQG1tIINFg0ODi4NYgqqKtJD1grWCxIKi
gtyCtYK9gUI=
--qnxjybvgjsqj--
ããã€ããã³ãŒãããŠã¿ããš
==nkf -mB ã§
Norton AntiVirus ãæ·»ä»ãã¡ã€ã«ãåé€ããŸãã: gfifv.exe.
æ·»ä»ãã¡ã€ã«ã« W32.Swen.A@mm ãŠã€ã«ã¹ãææããŠããŸããã
==ããã« od -c ãžãã€ã
0000000 N o r t o n A n t i V i r u s
0000020 033 $ B $ , E : I U % U % ! % $
0000040 % k $ r : o = | $ 7 $ ^ $ 7 $ ?
0000060 033 ( B : g f i f v . e x e . \r
0000100 \n 033 $ B E : I U % U % ! % $ % k
0000120 $ K 033 ( B W 3 2 . S w e n . A
0000140 @ m m 033 $ B % & % $ % k % 9 $
0000160 , 4 6 @ w $ 7 $ F $ $ $ ^ $ 7 $
0000200 ? ! # 033 ( B
0000206
==
(泚: 2è¡ç®ã®è¡æ«ã«åŸ©æ¹ã³ãŒãã¯ãããŸãã)
ãšããããã§ã¢ã³ããŠã£ã«ã¹ã®ãœãããŠã§ã¢ãã¡ãŒã«åçºä¿¡æã«
Swen以å€ã®ãŠã£ã«ã¹ã«ãã¡ãããšæ©èœããŠããéã
ãå¿é
ã®ä»¶ã¯ãŽãç®±ãã©ã«ããªããªããªãã«ç§»åããããšã§
å®å
šã«ç¢ºèªã§ãããšå€æããŠããã®ã§ã¯ãªãã§ãããã?
--
mailto:shi...@dd.iij4u.or.jp
Nobuhiro Shibuya at Office
Tokyo Japan
> ãæè¿ããšãããSWEN.Aãæµè¡ãå§ããŠãããšãããã®ããã®ã¯ãŒã ãæ·»ä»ãã
> ãã¡ãŒã«ã倧éã«ïŒïŒæ¥ïŒïŒéååŸïŒå±ãããã«ãªããŸããã
...
> ãã§ããªããšãã¡ãŒã«ã¯ã©ã€ã¢ã³ãã§ãã®ã¯ãŒã ã®ã¡ãŒã«ããŽãç®±è¡ãã«ããã
> ãããã¯ïŒ©ïŒ³ïŒ°ã®ãµãŒãã¹ã§ã¡ãŒã«ããã¯ã¹ã«å±ããæç¹ã§åé€ããããããã®
> ã§ããããã®ã¯ãŒã ããéãããŠããã¡ãŒã«ã®ãããã§èå¥ããæ¹æ³ã¯ããã®ã§
> ããããïŒ
>
> ãSubjectã¯ããªãçš®é¡ãããããã§ããã容æã«å€å¥ã§ãããã®ããããšå©ã
> ãã®ã§ããâ¥â¥
ãããã§èå¥ããã®ã¯ç§ã¯è«ŠããŸããã
ãã ãæ¬æã«ç¹åŸŽçãªæååãããã®ã§ããµãŒããŒã¬ãã«ã§ procmail ãšãããœã
ãã䜿ã£ãŠã
ïœïœïœïœãïœïœãïœïœïœ
ãïœïœïœïœ
ïœïœãïœïœ
ïœïœïœïœïœãïœïœãïœïœ
ïœïœïœïœïœïœãïœïœïœïœïœïœ
ïœïœïœïœïœïœïœïœïœ
ãïœïœïœïœâãïœïœïœïœïœïœ
ãïœïœïœïœïœ
ïœïœïœïœïœãïœïœ
ïœïœïœïœïœïœãïœïœïœïœïœ
ïœïœïœïœïœïœïœïœãïœïœïœïœ
ïœïœïœïœïœ
ãšããïŒã€ã®æååãåè§ã§å«ããã®ã¯ãããã ãæ®ããŠæ¬æã¯æšãŠãŠããŸãã
ããšã¯ãé³ã®é³Žãèšå®ã®ïŒã«èŠããããŠåæã«å®è¡ãã¡ã€ã«ãå®è¡ããïŒã¡ãŒã«
ããããã ãæ®ããŠæ¬æã¯æšãŠãŠãŸãããã¡ãã¯
ãã<iframe src=3D"cid:*********" height=3D0 width=3D0></iframe>
ã§ãã¡ã€ã«ã貌ã蟌ãã§ããŠã
ããContent-Type: audio/
ã§å§ãŸãæ·»ä»ãã¡ã€ã«ãã€ããŠãããã®ãæé€ããŠããŸãã
æ¡åŒµå㯠exe ã®ã»ãã« pif ãšã scr ãšãããããããã®ã§äžåŸããã®æé¢ã
䜿ã£ãŠåæã«é³ã鳎ããèšå®ã®ãã®ã¯æé€ã§ãã
ãããã¯ãå®è¡åœ¢åŒã®æ·»ä»ãã¡ã€ã«ãã€ãããã®ã¯äžåŸæé€ãã§ãããã§ãããã
ãã® 2 ã€ã®æ¡ä»¶ãšãããšã¯äžè¬ç㪠SPAM 察çïŒããããåœè£
ããŠãããã®ã
äžå¿ã«æé€ïŒã§ããã
詳现ã¯ãã¡ãã®èšå®ãã¡ã€ã«ãããããã ããã
http://www.ht.sakura.ne.jp/~delmonta/anmerkungen/.procmailrc
========================================================================
é£¯å¶ æµ©å
/ ã§ããããã»ããã㟠http://www.ht.sakura.ne.jp/~delmonta/
IIJIMA Hiromitsu, aka Delmonta mailto:delm...@ht.sakura.ne.jp
ãäžèšã®å
容ãèŠãŸããšãã¯çœ®æåŸã®ããŒãã«ããŠã£ã«ã¹åãæžããŠãã
ãŠããŸãããããã ãšèŠªåã ãªãããšããããSWEN.Aã ããæé€ãããæãMIME
ã®ãã®ããŒãã®æ¬æã«SWEN.Aã®ååããããã©ãããã§ãã¯ããã°æ¯ãåããã
ãŸãããã
ããšãããããŠã£ã«ã¹ãã¹ã¿ãŒïŒïŒïŒïŒã¯ãåçŽã«åé€ããŸãããšã ã衚瀺ãã
ãŠããŠã£ã«ã¹åã衚瀺ãããªããã§ããã
ãå
šéšã®ãŠã£ã«ã¹æ·»ä»ã¡ãŒã«ãäžæ¬ã§æ¯ãåãã¡ãããšãå®éã«èª°ããæžããã¡ãŒ
ã«ã«ãŠã£ã«ã¹ãæ·»ä»ãããŠããããã®ãŸã§äžç·ã«æ¯ãåãããã¡ãããŸãããã
ããã¯ããã§ç¢ºèªãé¢åã ãªãâ¥â¥ãšã
ããããšãããŠã£ã«ã¹ãæ·»ä»ãããŠãã¡ãŒã«ã£ãŠãå
šãŠãŠã£ã«ã¹ãçæããã¡ãŒ
ã«ã§ãã®ïŒ°ïŒ£ã®æã¡äž»ãäœãæžããå
容ãå«ãŸããŠãã£ãŠããšã¯ç¡ãã®ããªïŒïŒ
-----
grep -il "this is the latest version of security update" *.alm > $delist1
grep -il "^<iframe src=.*"cid:.*" .*iframe" *.alm > $delist2
sed "s/^\(.*\)$/move \1 d\:\\foo\\MAILBOX\\ACCOUNT1\\USER011\.BOX/g" $delist1 >
00move.bat
sed "s/^\(.*\)$/move \1 d\:\\foo\\MAILBOX\\ACCOUNT1\\USER012\.BOX/g" $delist2
>> 00move.bat
del $delist1
del $delist2
command /c 00move.bat
del 00move.bat
-----
念ã®ããmoveããŠãã確èªåŸdeleteããŸããAL-Mail32ã§ã¯ããã©ã«ãã®æ€æ»ã
ã³ãã³ãã§æŽæ°ããŸããèªååŠçã§ã¯ãããŸãããããããªãã«äœ¿ããŠããŸãã
--
Shuichi YAMAGAMI, Kyoto, JAPAN
yam...@mbox.kyoto-inet.or.jp
b3IAAABBZG1pbgAAAEdFVCBodHRwOi8vd3cyLmZjZS52dXRici5jei9iaW4vY291bnRlci5naWYv
ãšããè¡ãå®å
šäžèŽã§å«ããã®ã Swen ãšã¿ãªããŠããŸãã
ä»ã®ãšãã誀å€å®ãŒãã§ãã
<3F8117C9...@ht.sakura.ne.jp>ã«ãŠ IIJIMA Hiromitsu ããæ°ãïŒ
>詳现ã¯ãã¡ãã®èšå®ãã¡ã€ã«ãããããã ããã
>http://www.ht.sakura.ne.jp/~delmonta/anmerkungen/.procmailrc
ãããªã¬ã·ãããããŸãã
http://agriroot.aua.gr/~nikant/nkvir/