IGS Discussion Forums: Institute of General Semantics Topics: August 3rd, 2008: Caution when visiting IGS's homepage
Author: Ralph E. Kenyon, Jr. (diogenes) Sunday, August 3, 2008 - 11:49 am Link to this messageView profile or send e-mail

This "trojan" is over five (5) years old; to become infected by it you would have to be using a version of Windows and internet explorer that has not been updated since April 22, 2003.

"[This applies to] most versions of Windows and in most versions of Microsoft Internet Explorer [using the Win 23 variation].

The attack ... for this ... issue would likely involve ... a malicious Java applet [in] a Web page... An attacker could then host this malicious Web page on a Web site or could send it to a user in e-mail. The present Microsoft VM has been updated to include a fix."
You're safe if your system does not use windows, does not use internet explorer, or, if you do, has been updated in the last five years.

The hosting site require a website with the infected web page and the java applet, or an infected (web page) email that links to the java applet, and that web page or email is opened using internet explorer.

I use Opera for my browser on my windows machine.

Author: Ralph E. Kenyon, Jr. (diogenes) Sunday, August 3, 2008 - 12:00 pm Link to this messageView profile or send e-mail

Ben,
I see that you've posted a correction to the virus ID. The new viruses you report are also old, vintage 2004-2005, at least three years old, and only someone who has not updated their system in this time would be vunerable. This class of viruses attacks through a web page, or an email that is opened as a web page) designed to exploit a windows and Microsoft Internet explorer design flaw that leaves a security hole.

IF anyone uses Microsoft, update your system regularly. Updates are free from Microsoft. Keep up to date and stay safe.

Author: Ralph E. Kenyon, Jr. (diogenes) Sunday, August 3, 2008 - 10:45 pm Link to this messageView profile or send e-mail

I have created an email filter that reports any email that pretends to come from myself as "from me fraud", and marks it as spam and to be deleted. I do this with MailWasher, which does the job before the whole email is ever downloaded.