Writing on IT Security AI generated
Back to Projects

Writing on IT Security

Links to various articles about cyber security written by be during my working life!

December 1998
"A new host emerges," a December 1998 article by David Banes published by Symantec's Asia-Pacific AntiVirus Research Center (SARC), warned of security risks associated with the newly introduced Windows Script Host (WSH). The piece highlighted how script-based architectures like VBScript could be exploited, a trend that proved prophetic with the emergence of worms in the late 1990s. 

2001 - My GIAC Certification Paper.
How to stay virus, worm and trojan free - without anti-virus software.

https://www.giac.org/paper/gsec/747/stay-virus-worm-trojan-free-anti-virus-software/101646

Download from here ðŸ“Ž stay-virus-worm-trojan-free-anti-virus-software_747.pdf.

A Google Ai search resulted in...

----

Threat Intelligence & Malware Analysis Commentary (2001–2004)

His contemporary technical evaluations and architectural threat breakdowns remain archived across digital enterprise technology publications:
  • "New password stealing Trojan discovered": Published by ZDNET, this piece details his technical analysis of yes2k.exe, documenting early proof-of-concept hybrid threats where spam engines and web browser scripting vulnerabilities converged. [1]
  • "Netsky.B outstrips MyDoom": Archived on ZDNET, this article chronicles Banes' live data tracking during his tenure as Asia-Pacific Technical Director at MessageLabs, tracking the propagation architecture and social engineering triggers behind the Netsky mass-mailer. [123]
  • "New Trojan intercepted in Aust": Available via iTnews, this report features his forensics on a double-extension attachment flaw (.htm.pif) that stealthily transformed compromised target systems into localized proxy servers. [1]
  • "Take it seriously, warns Aussie expert": Preserved by the Sydney Morning Herald, archiving his early-2000s warning regarding automated hacker scanning tools, enterprise perimeter vulnerabilities, and the specific danger that legacy corporate infrastructure faces from newer exploitation methods. [1]
Technical Handbooks & Book Contributions (Syngress)
During his tenure as the Asia-Pacific Regional Manager for Symantec Security Response, Banes lent his enterprise engineering expertise to leading IT security documentation: [1]

Configuring Symantec AntiVirus Corporate Edition
Banes wrote the definitive Foreword and technical introductory framework for this highly-regarded IT administration manual published by Syngress Publishing. The handbook serves as a comprehensive guidefor implementing, deploying, and recovering server infrastructure from viral infections across multi-tier networks.

Symantec SARC Press Publications & Briefings (1997–2003)

As the director orchestrating threat response from Symantec's regional facility in Australia, Banes authored periodic threat assessments and issued foundational intelligence reports: [12]
  • The SARC Annual Malware Review (SARC Newsletter)
    Banes served as the Editor-in-Chief of the Symantec AntiVirus Research Center Newsletter. His comprehensive industry brief summarizing global threat data mapped out the structural shift from traditional file infectors to mass-mailing script worms like Wscript.KakWorm and VBS.LoveLetter.
     [1]
  • "Asia's Virus Fight Gets Boost from New Australian Centre"
    This 1997 founding brief preserved by the South China Morning Post outlines Banes’ multi-language architecture blueprint for tracking malware back to its source code roots to push rapid countermeasure definitions to corporate gateways.
     [1]
  • "Code Red II Spreading in Asia"
    A critical 2001 technical escalation advisory published via Computerworld. In this piece, Banes provided enterprise recovery methodologies for restoring corrupted server file registries following severe automated buffer-overflow payload executions.
     [1]
Symantec AntiVirus Research Center (SARC) Newsletters

The exact archives of the Symantec AntiVirus Research Center (SARC) Newsletters from the late 1990s and early 2000s are largely out of print. However, specific structural data and threat breakdowns edited by David Banes are preserved within contemporary academic and industry security indexes. [1]

The most prominent surviving dataset is his Year 2000 Global Infection Review, published in the January 2001 SARC brief. This report document represents a critical historical milestone in cybersecurity, mapping out the exact moment the industry shifted away from traditional file-infecting viruses toward mass-mailing script worms. [1]

The SARC Top Ten Malware Rankings (Edited by David Banes)
As Editor-in-Chief of the SARC newsletter, Banes compiled and analyzed global telemetry to issue the definitive global infection rankings for the year 2000: [1]
RankMalware DesignationThreat Architecture & Behavioral Footprint
1Wscript.KakWormExploited an unpatched Microsoft Outlook Express vulnerability via Internet Explorer components to execute automatically through HTML email signatures.
2W95.MTXA complex hybrid matrix threat that combined a mass-mailing worm engine with a back-door Trojan and a local PE file infector.
3VBS.LoveLetterThe infamous "ILOVEYOU" worm written in VBScript that crippled global corporate email infrastructure using automated Outlook MAPI scripting.
4W95.Hybris.genA highly sophisticated plugin-based worm that updated its own destructive payload dynamically by downloading encrypted modules via Usenet newsgroups.
5VBS.Stages.AA social engineering mass-mailer disguised as a joke file (.txt.vbs) that utilized dual file extensions to trick users into executing code.
6W32.HLLW.Qaz.AA network worm that actively looked for open Windows network shares to replace the legitimate notepad.exe application with a backdoor payload.
7Happy99.WormUniversally cited as the first modern email-propagating worm, displaying real-time fireworks visuals while quietly intercepting network socket connections.
8W32.NavidadAn email-borne worm disguised as an electronic Christmas card that overrode system .exe registry keys, preventing users from opening applications.

9. VBS.Network

- www.symantec.com/avcenter/venc/data/vbs.network.html

10.W32.FunLove.4009

- www.symantec.com/avcenter/venc/data/w32.funlove.4099.html


SARC Editorial Analysis Framework

In the accompanying newsletter commentaries, Banes laid out several core concepts regarding corporate gateway security that remain foundational to modern SecOps: [1]
  • The Proliferation of High-Level Scripting: Banes emphasized that threat actors were abandoning assembly/C-level micro-coding in favor of simple, high-level languages (like VBScript and JavaScript) because Microsoft's automation protocols allowed them to manipulate target system functions effortlessly. [1]
  • The Perimeter Failure Paradigm: His SARC documentation provided data showing that file signature-based desktop scanning was failing to react fast enough to mass-mailing propagation speeds, leading him to advocate for aggressive server-side email filtration and user-privilege restriction policies. [1]
The full indexed breakdowns and contextual footnotes from Banes' newsletter releases are hosted online via the INFOSEC Year In Review Index compiled by the information security archive.

© 2026 Folio & Journal from Cleartext Ltd. All rights reserved.