Go Back   Cigar Weekly Community Forums and Discussion Groups > Community Centers > Close But No Cigar

Close But No Cigar Discussions about anything BUT cigars.
-> This room is open to all registered members.

Reply
 
Thread Tools Display Modes
Old 08-19-2003, 01:05 PM   #1
Gamle-ged Gamle-ged is online now
Moderator
Herf God
 
Gamle-ged's Avatar
 
Join Date: Aug 2000
Location: Nokomis, Florida
Posts: 27,898
Getting Undeliverable Mail "returned" to my e-mail

... that it claims I sent out... but none of the people are in my address book and I've never heard of them.

Is this the "sobig" worm that's spreading? My system is Win 98 and I believe "sobig" infects XP and 2000, so does this mean that someone with one of those systems and with my name on their address book is infected and sending these "returns" in hope I'll open one of those tempting "paper-clip" attachments to see what I "sent"?...
__________________
==========

I shudder to imagine what's next in “flexible” Obama's "Big Book of Things to F***-up as I Drive America into Fatal Bankruptcy.”"

We've always experienced some weltschmerz, it's just that we're now seeing its geometric intensification...

Obama (5-12-13) “Oh I think that, you know, as president I bear responsibility for everything--to some degree.”
  Reply With Quote
Old 08-19-2003, 01:06 PM   #2
BigO BigO is offline
Editor-At-Large
CW Executive Chef

Moderator
Herf God
 
BigO's Avatar
 
Join Date: Oct 2001
Location: Atlanta.
Posts: 35,054
Yet another spam-spreading/virus-spreading tactic.
__________________
Unconventional wisdom is seldom either.

Every time you think you've become too cynical, the world finds a way to teach you that the real problem is that you haven't become cynical enough

Free speech is free speech is free speech. There is no qualifier.

If you aren't outraged, you aren't paying attention.

Thank you for supporting Big Orson's "Citizen Cajun" Mango-Habanero Salsa. Winner of 23 national awards!

  Reply With Quote
Old 08-19-2003, 01:09 PM   #3
flipflop flipflop is offline
Contributing Editor
Herf God
 
flipflop's Avatar
 
Join Date: Feb 2002
Location: Georgia
Posts: 39,743
I'm getting a few too. Probably someone who has you in their addy book got infected (and it could be thousands of messages removed from you) and it's sending out shit.

Just delete them.

NEVER open any message like that unless you are 100% sure you sent the e-mail.
__________________
"Every normal man must be tempted at times to spit on his hands, hoist the black flag, and begin to slit throats."
-- H. L. Mencken
"I am the punishment of God. If you had not committed great sins, God would not have sent a punishment like me upon you."
-- Ghengis Khan
  Reply With Quote
Old 08-19-2003, 01:14 PM   #4
Gamle-ged Gamle-ged is online now
Moderator
Herf God
 
Gamle-ged's Avatar
 
Join Date: Aug 2000
Location: Nokomis, Florida
Posts: 27,898
A couple of them in the "preview pane," (and yes, I downloaded the "preview pane" bug fix over a year ago!) had the tell-tale mention of "wicked" as in "wicked_scr.scr" and "wicked screen-saver" mentioned in the F-Secure site...
  Reply With Quote
Old 08-19-2003, 01:16 PM   #5
Lagniappe Lagniappe is offline
Club Member
 
Lagniappe's Avatar
 
Join Date: Jan 2002
Location: Tyrone, GA
Posts: 1,062
It very well could be the new version thats going around. I left for lunch today and by the time I got back there was a pile up of around 20 infected e-mails waiting for me.

The good news is
1. It is pretty easy to spot
2. It is pretty easy to remove
3. It will deactivate itself on Sept 10th 2003

The bad news is
1. It is spoofing the "From" address which makes tracing it a little more difficult
2. It can download arbitrary files to an infected computer and execute them. The author of the worm has used this functionality to steal confidential system information and to set up spam relay servers on infected computers. This functionality may also be used as a worm self-update feature.

http://securityresponse.symantec.com...reatassessment

Sobig will infect any windows machine except Windows 3.1
__________________
"If they removed all the porn from the internet, there would be just one page left called 'Bring Back The Porn'" - Dr Cox from Scrubs
  Reply With Quote
Old 08-19-2003, 08:19 PM   #6
qajariaq qajariaq is offline
Contributing Editor
Club Member
 
qajariaq's Avatar
 
Join Date: Jun 2001
Posts: 2,678
I got an email today that said an email I sent contained spam in the header (?). The strange part is that I do not know the email address nor have I sent any emails in the past few days!

I hope this is not one of the worms going around. I had problems sending out emails the other day - one kept coming back saying that my message had been stopped because it contained "known spam sources in Recieved: header." WTF??

I use web-based email, and do not open attatchments unless they are from a known source and the file type is actually what they say it is supposed to be. Is there another way to get it?
  Reply With Quote
Old 08-19-2003, 09:21 PM   #7
sambo sambo is offline
Herf Meister
 
sambo's Avatar
 
Join Date: Sep 2001
Location: Senior Lefty, KKKali Djibouti
Posts: 6,791
It's easy enough to see what is going on when you look at the header of one of those emails.

First you will notice your address and you will see he mail server that received your "spam/virus" but then you will also see the IP Address where it originated and the Email Server that it was sent from. You can often see the routers that it stopped at on the way as well.

Armed with that info it is easy to both determine that it is not something that originated from any machine that you use (it's always good to know that it isn't a case of being infected and just not realizing it) and in the event that it is coming from someone that you know, being able to get word to them and help stem the flow of bad emails.

I get this at work all the time and my boss is always telling me that we have some machine or another that is infected and I have to constantly remind him that we are as close to impervious as we can be, but we can't prevent someone or some virus from spoofing us and making it appear to the untrained eye that we are sending out virus replication emails or spam.

Ain't the Information Age Grand?!!!
__________________

Stop ruining my ideology with you logic!
  Reply With Quote
Old 08-20-2003, 05:40 AM   #8
Gamle-ged Gamle-ged is online now
Moderator
Herf God
 
Gamle-ged's Avatar
 
Join Date: Aug 2000
Location: Nokomis, Florida
Posts: 27,898
Quote:
Originally Posted by lotus_dude
I got an email today that said an email I sent contained spam in the header (?). The strange part is that I do not know the email address nor have I sent any emails in the past few days!

I hope this is not one of the worms going around. I had problems sending out emails the other day - one kept coming back saying that my message had been stopped because it contained "known spam sources in Recieved: header." WTF??

I use web-based email, and do not open attatchments unless they are from a known source and the file type is actually what they say it is supposed to be. Is there another way to get it?
I also got two or three of the "spam in the header" e-mails "returned" yesterday. All together I got about a dozen of these "returned" e-mails yesterday evening, but not a one since. I did read in one of the sites that a particular worm operates only from 7:00 PM on or the like, taking a "from" and a "to" addressee from the infected machine's address book, then sending them out to try to propagate... sounds like going out on a date after work!...
  Reply With Quote
Old 08-20-2003, 05:56 AM   #9
Lagniappe Lagniappe is offline
Club Member
 
Lagniappe's Avatar
 
Join Date: Jan 2002
Location: Tyrone, GA
Posts: 1,062
This is the biggest outbreak I've seen here since the last sobig outbreak.
  Reply With Quote
Old 08-20-2003, 06:38 AM   #10
flipflop flipflop is offline
Contributing Editor
Herf God
 
flipflop's Avatar
 
Join Date: Feb 2002
Location: Georgia
Posts: 39,743
Quote:
Originally Posted by Lagniappe
This is the biggest outbreak I've seen here since the last sobig outbreak.
You be right on. I've received 8 infected e-mails already today. Thank God for Norton.
  Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -8. The time now is 06:31 AM.