Mainly, I want to observe the behavior of web script viruses on a
server that is not connected to the Internet. This is for research
purposes only.
Thus, I need two things to do this.
One:
----
I would like to find source code for major viruses, (such as Nimda,
Code Red,
Klez, etc.) that I can embed within HTML "<Script>" tags. I would
prefer
Javascript viruses, but VB/other scripts are ok, if you can append the
tags
onto them, so all I have to do is cut and paste.
There are three pages I have already been to (which are a semi-decent
example
of what I want... (you can omit these pages, though not necessarily
the entire site from your search).
a. http://www.olen.net/LOVE-LETTER-FOR-YOU.TXT
b. http://securityfocus.com/archive/1/136474
c. http://www.searchlores.org/realicra/illov.htm
Two:
----
I would like to find websites that actually contain infected (viral or
worm) scripts. Or contain embedded HTML 'GET' requests that attempt
to
dessiminate the contents of a webserver... (i.e. the very well-known
Code
Red 'GET' request... GET /default.idaxxxxxxxxxxxx)
To be useful to me, would I need to be able to "View Page Source" to
be
able to utilize the page, or would I need byte code, email
attachments,
etc.?
I would appreciate any other ideas you would have about creating a
collection
that I can place on my sacrificial server to observe this behavior.
Please
note, my search is primarily confined that that which can be observed
through
an HTTP site... and through HTTP traffic... I'm not looking for e-mail
viruses
per se. (As my sacrificial server will be a web server, not an email
server).
Any other suggestions on how to go about finding concrete examples
would
be much appreciated!
Thank you very much! |