About us | Advertising | SecurityWatch
Home   Articles   Blog   Reviews   Press Releases   Security Tools   Sponsored Solutions
Press Releases
First security product to block encrypted Zip file viruses at the gateway
Thursday, 4 March 2004 20:06 EST

Stops ploy used by Bagle virus

4th March 2004

Network Box, an Internet security vendor, today announced an industry first: gateway-level anti-virus protection to scan inside password-protected Zip files. This blocks a technique used by the Bagle virus to infect the computers of unsuspecting users.

By blocking the infected Zip files at the gateway to the network, viruses are stopped before they enter a company’s IT systems, rather than having to trust that desktop anti-virus protection can catch them once they’re inside.

While it has become common to place anti-virus protection at the Internet gateway or the ISP (Internet Service Provider), these systems have not previously been able to scan inside encrypted content.

Recently, the I-Worm.Bagle.h and I-Worm.Bagle.i viruses cleverly exploited this vulnerability by distributing copies of themselves in password-protected Zip archive files. As the viral content is encrypted, the anti-virus software running at the gateway cannot scan inside and see it. The password is provided in the email, allowing a user to decrypt the Zip file.

“This is like having the world's best airport X-ray scanner but letting passengers use lead-lined luggage,” said Simon Heron, managing director of Network Box (UK). “The success of Bagle has shown that users are still not heeding advice to avoid opening executable attachments without being sure of their source. Our Zip file protection adds a much-needed defence against this latest ploy from virus writers.”

As the Network Box appliance is remotely-managed by the company, all of its UK customers will be automatically updated with this new level of protection by Friday (5th).

Network Box can already configure its appliances to quarantine any encrypted Zip files where the password is not present in the same email. This will provide an extra level of protection, in case virus writers try sending the passwords on separate emails in the future. Further developments are pending and will be implemented as they become available.

About Network Box:
Network Box (www.network-box.co.uk) provides small and medium sized businesses with affordable, simple and effective protection against Internet threats. It integrates a full range of protection technologies into a single package; including virus and Spam protection, a firewall, content filtering, VPN support for remote access, and intrusion detection and prevention. The device is continuously maintained and updated to provide high levels of protection, without requiring user intervention or configuration.

Press enquiries:
Aruna Sharma
Audax Communications
7


Technical enquiries:
Simon Heron
Network Box (UK) Ltd,
The Business Park, Technology Drive,
Beeston, Nottingham, NG9 2ND



Featured Articles

Tribal thinking in today’s IT
George Santayana once famously observed; “Those who cannot remember the past are condemned to repeat it.”. But when it comes to IT security, a better way of thinking might be; “those who fail to understand the impact of the past on their thinking may find themselves somewhat exposed”…

You can’t manage what you can’t see!
Security threats have grown more menacing with the appearance of the likes of Sober, Mytob, and Bagle. Along with the newer trends of spyware, phishing and key logging the implications of ineffective information security have become potentially debilitating to business operations and indeed strategy.

The development and execution of an endpoint security strategy is an increasingly important and urgent issue for businesses of all sizes. Many are executing – or wanting to execute - flexible working practices and organisation models that leverage contemporary technology.

Scan all company email for viruses, Trojans and worms with 4 virus engines, all in one package - GFI MailSecurity for Exchange/SMTP! Download your free 60-day trial today!

Check your website security with Acunetix Web Vulnerability Scanner. Audit your web applications for SQL injection, cross site scripting & more. Download trial!

Network Security Tools

SpyDefense
SpyDefense protects your computer against annoying, and harmful software such as Spyware, Adware, Trojan horses, etc. SpyDefense is anti-spyware software that prides itself on a very user friendly environment.


Proactive Security Auditor
Proactive Password Auditor is a password security test tool that's designed to allow Windows NT, Windows 2000, Windows XP and and Windows Server 2003-based systems administrators to identify and close security holes in their networks.


File Securer
File Securer is a powerful tool designed to protect your sensitive folder and personal file. With strong security, File Securer embeds the protect into windows system kernel, both on command mode and window mode, all work professionally.




What's up, IT? Blog

Phishing By The Numbers: 41,000 Blocked Sites in 2005
Top 7 PHP Security Blunders
The human factor and information security
Why I Love Vulnerability Analysis In 2005
IT security fear factor: Tape backups
Uncovering Cyber Flaws
State of the security mart
When the hardware gets smart
Security for SMBs
Four Security Resolutions For The New Year

Copyright © IT-Observer.com 2000 - 2006    Privacy Policy | RSS Feeds
Site Meter