Re:virus: Re: does it?

From: rhinoceros (rhinoceros@freemail.gr)
Date: Mon Mar 22 2004 - 09:51:08 MST

  • Next message: Michelle Anderson: "RE: virus: IM client status"

    [Walter]
    I didn't send this.
    How do these virus kids and spammers and other assholes spoof your address like this?

    I NEVER open attachments, not from anybody, so it didn't affect me.

    I hope no one else was affected.

    [rhinoceros]
    The attachment seems to contain the "I-Worm/Netsky.C" virus. (Lucifer, you might want to remove that attachment from the BBS).

    The way it works is rather simple. Assuming Walter's computer is clean, someone else was infected, who had both Walter's and the mailing list's email adresses in their address book. Then the virus started sending out emails from that person's machine, putting random addresses found in the address book in the "To" and "Reply to" fields of the messages.

    The account from which the message was really sent can be traced, to some degree, by examining the full headers of the message (which are not visible here).

    ----
    This message was posted by rhinoceros to the Virus 2004 board on Church of Virus BBS.
    <http://virus.lucifer.com/bbs/index.php?board=61;action=display;threadid=30069>
    ---
    To unsubscribe from the Virus list go to <http://www.lucifer.com/cgi-bin/virus-l>
    


    This archive was generated by hypermail 2.1.5 : Mon Mar 22 2004 - 09:52:06 MST