someone sent me a virus/worm


Page 1 of 3 123 LastLast
Results 1 to 15 of 35

Thread: someone sent me a virus/worm

  1. #1
    Join Date
    Dec 2000
    Location
    Panorama, CA, USA
    Posts
    1,053

    someone sent me a virus/worm

    someone sent me an email titled:

    "re That movie" with an application.pif attachment ....no problem, I'm always in Linux anyway, but here was my reply:

    It appears that you have sent a virus or worm to me as an attachment to an
    email titled "re That Movie". I am not affected because I use the Linux
    operating system. I am sending you this return email as a courtesy to let you
    know. You may not even be aware that your system is sending out these
    emails.
    CMonster says, "You can't choose the right OS if you don't have a choice."

  2. #2
    Join Date
    Jul 2002
    Location
    Colorado USA
    Posts
    3,070

    Re: someone sent me a virus/worm

    Originally posted by CMonster
    someone sent me an email titled:

    "re That movie" with an application.pif attachment ....no problem, I'm always in Linux anyway, but here was my reply:
    nice very nice
    Some of my favorite links

    search engine's
    G4L & JL forum search
    one of the best Debian based distro's for new hardware
    registered Linux user # 288225

  3. #3
    Join Date
    Dec 1999
    Location
    Clinton WI
    Posts
    327
    Looks like the new SoBig. FYI, the new sobig uses a false return address that it gets off of it's victim's computer, so the person that your mail client said the message was from was not really the person who sent it.
    UT, Tactical Ops alias: DrStrangluv

  4. #4
    Join Date
    Apr 2001
    Location
    SF Bay Area, CA
    Posts
    14,936
    Anybody know if email worm writers have figured out how to spoof the routing headers yet? If not (and I don't think they have), you could always use that info to narrow down the person that it did actually come from...

    But yeah, this is SoBig. We've gotten about five hundred of them at work since early Thursday morning. Interestingly, every single one was to one of two addresses; nobody else was getting it. Of course, it was stopped at the mail gateway, so no harm done, but it sure is annoying.

    My sister also complained to me yesterday: "I'm getting a whole crapload of these cheesy emails! What are they?" After I told her "you're in some idiot's inbox or address book, and they were dumb enough to run the attachment when they first got it", she says "OK, so how do I stop it?" Boy, I wish I knew...

  5. #5
    Join Date
    Nov 2002
    Location
    Pennsylvania, USA
    Posts
    171
    Isn't running linuux so much nicer than windows when it comes to the majority of viruses & trojans - like one of the last ones (MSBlast) which only affects windows 2000 & XP

  6. #6
    Join Date
    Dec 2002
    Location
    127.0.0.1
    Posts
    165
    Originally posted by bones996
    like one of the last ones (MSBlast) which only affects windows 2000 & XP
    Doesn't affect my computers data speaking but I still feel effects of the worms and trojans. Apacha log files filling up, iptables log files filling up, internet connection slowing down (especially codered and nimda). First two can be fixed numerous ways but until people patch their machines there's no real way to fix number 3.

  7. #7
    Join Date
    Apr 2002
    Location
    Canada
    Posts
    82
    What I, don't understand is why do people open e-mails from people that they do not know?

  8. #8
    Join Date
    Jan 2003
    Location
    Ontario, Canada
    Posts
    310
    Because the emails come from people they do know. That's the problem.

  9. #9
    Join Date
    May 2002
    Location
    Philippines
    Posts
    1,377
    I've been getting automatic reply messages of failed sending of an email (w/ a virus) with my email address on it... now how did that get there?? could my email add. be spoofed ? cause I don't think sylpheed/evolution could be sending out those things
    "SEARCH FIRST... ASK SECOND" -mdwatts-

  10. #10
    Join Date
    Apr 2002
    Location
    Canada
    Posts
    82
    I, know they come people they know. But why do this friends send it to their friends?

  11. #11
    Join Date
    Sep 2000
    Location
    So. Cal
    Posts
    652
    Originally posted by rwtoften
    I, know they come people they know. But why do this friends send it to their friends?
    Here's how modern Outlook viruses work.

    The first virus is sent to multiple people in hopes that at least one will open it and run the attachment. Once this happens, the virus will send itself to everyone in the affected users address book. As the virus is coming from someone that the users knows, they throw all cuation to the wind and open it. Wash, rinse, repeat.

    All it takes is one person to infect the world.

    Makes for an interesting social experiment

  12. #12
    Join Date
    Sep 2002
    Posts
    218
    bwkaz they figured it out a while back, I think with the love bug they had it figured out.

    The problem is though, is that the ISP's kept their spool files and didn't pass it on to the email headers, that's how they figured out who it was.

    Sobig though has a definite trail, the trail is just so huge though it's like 100 farmers dropping off train cars full of hay, and sorting out each needle through about 500 tons of hay.
    Specs:
    Dually Opteron 246's
    1GB DDRDRAM (400)
    OS - Gentoo 1.4 KDE 2.6 test9 64-bit kernel
    games - UT2k3, Q3A, SSE/2, RtCw,UT, Tribes 2, Homeworld - natively

    Under Wine - HalfLife, Homeworld Cataclysm, Max Payne

    Registered user 292384

  13. #13
    Join Date
    Apr 2002
    Location
    Canada
    Posts
    82
    Well I, guess people can't resist opening mail that they have no clue as to who really sent it! In my case, if you haven't told me personally that you're sending it, it gets friggin trashed, no questions asked!

  14. #14
    Join Date
    Sep 2002
    Posts
    218
    One more reason to convert people to Linux though.

    I am free to open up any klez, sobig, or blaster emails I want.

    In fact I have seen alot of reports that symantec prefers to take virii on a Linux machine and then simulate a windows environment, I hear it's the most effective way to reverse engineer a worm.

    Silly windows people...so vulnerable like little children.

    Yet I'm sure that if Linux was the majority people would write worms for it instead.

    Funny thing is though, it would do absolutely nothing to a root account

    A properly used Linux system is always far more secure, maybe not your files, but your system is pretty much guaranteed to be ok.
    Specs:
    Dually Opteron 246's
    1GB DDRDRAM (400)
    OS - Gentoo 1.4 KDE 2.6 test9 64-bit kernel
    games - UT2k3, Q3A, SSE/2, RtCw,UT, Tribes 2, Homeworld - natively

    Under Wine - HalfLife, Homeworld Cataclysm, Max Payne

    Registered user 292384

  15. #15
    Join Date
    Sep 2000
    Location
    So. Cal
    Posts
    652
    A properly used Linux system is always far more secure, maybe not your files, but your system is pretty much guaranteed to be ok.
    A properly used Windows system is always far more secure, maybe not your files, but your system is pretty much guaranteed to be ok.


Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •