[ale] question about sobig
John Marasco
john at marasco.net
Wed Aug 20 07:55:08 EDT 2003
Selected quote about the SoBIG virus...
But even those who werenÂt directly infected with the virus were
struggling with it. When it replicates, the virus Âspoofs the sending
e-mail address. That means the ÂFrom:Â line is faked, selected from a
list of e-mail addresses culled off the Internet. Users unlucky enough
to be used in SoBigÂs ÂFrom line can get hundreds of SoBig-related
complaints, including automated bounce messages saying the virus didnÂt
reach its recipient, or irate messages from recipients who think theyÂve
been sent a computer virus.
John Wells wrote:
>This morning, my inbox was filled with sobig. I expected that. However,
>I found a number of supposedly returned mail carrying sobig that appeared
>to have been originally sent from my wife's and my email addresses.
>
>I assume, since I run linux exclusively and my wife only emails through
>squirrel mail, that this means someone out there that has received mail
>from us is infected and the worm is trying to send out with our email
>addresses as source address, which then get bounced by certain smart
>servers back to us. Is this a good assumption?
>
>Is there any way to track down an infected box?
>
>Thanks for the input.
>
>John
>
>
>
>_______________________________________________
>Ale mailing list
>Ale at ale.org
>http://www.ale.org/mailman/listinfo/ale
>
>
>
_______________________________________________
Ale mailing list
Ale at ale.org
http://www.ale.org/mailman/listinfo/ale
More information about the Ale
mailing list