Rockbox mail archiveSubject: Re: WARNING: possible virus on this list
Re: WARNING: possible virus on this list
From: Claus Helbing <claus.helbing_at_descom-consulting.ch>
Date: Tue, 8 Jul 2003 09:53:26 +0200
Analysing the mail's head ...
The curious thing is that the mail seems to be a _real_ bounce of a wrong Yahoo Group Name
that was chosen at random.
In that way the original mail header is lost at Yahoo ... very cool approach ...
----- Original Message -----
From: "Brian Wolven" <brian.wolven_at_verizon.net>
Sent: Tuesday, July 08, 2003 12:38 AM
Subject: Re: WARNING: possible virus on this list
> Bradley M Alexander wrote:
> > It is entirely possible that nobody on the list is infected. sobig.E
> > does address spoofing. I have gotten several hate mails from people
> > around the world telling me to stop sending them infected
> > files...Even though my workstation and the two upstream mail servers
> > (one of which is in my basement) are all running Linux. Go figure.
> It spoofs the "from" address, but the addresses it sends *to* are taken
> from the address book (.wab file for OE) on the infected PC. If someone
> gets the virus sent to an address they use *only* for this list, it's
> likely because that list address was present in the infected someone's
> address book. There are other ways it could happen of course, but the OP
> probably pointed this out and posted the info to the list in the first
> place because it is the most *likely* way for that to happen. Your hate
> mails came from people who got a copy with your spoofed "from" address -
> even though you could not have sent them, being a User of a Superior OS.
Received on 2003-07-08