Full Disclosure mailing list archives

Re: Infections


From: cdowns <cdowns () drippingdead com>
Date: Tue, 27 Jan 2004 09:12:46 -0600

Not I, arch linux and running strong ;)

~!>D

Jos Osborne wrote:

Okay - I think someone on here's infected. Within a couple of hours of my address first appearing on this list, I got 
the following:


----------------------------------------------

Undeliverable: Delivery Status Notification (Failure)

Your message did not reach some or all of the intended recipients.

     Subject:   Delivery Status Notification (Failure)
     Sent:      27/01/04 14:17

The following recipient(s) could not be reached:

     leo () twkempton co uk on 27/01/04 14:30
           The e-mail account does not exist at the organization this message was sent to.  Check the e-mail address, 
or contact the recipient directly to find out the correct address.
           <kempton.twkempton.co.uk #5.1.1>

     mailbox () twkempton co uk on 27/01/04 14:30
           The e-mail account does not exist at the organization this message was sent to.  Check the e-mail address, 
or contact the recipient directly to find out the correct address.
           <kempton.twkempton.co.uk #5.1.1>

----------------------------------------------


My system clock was reading 14:27 at the time I recieved this - an ever so slight discrepancy...
From the reports I've been getting from users it looks like the virus is spoofing the sent address with a randomly chosen 
address from the host's address list.

Jos

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html



_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: