View Single Post
  #9   Report Post  
Mark Rand
 
Posts: n/a
Default OT Gremlins have been busy!

On 21 Aug 2003 15:16:05 -0400, (DoN. Nichols) wrote:

snip

The victim who is sending these is probably a reader of the
rec.crafts.metalworking newsgroup, whether active or a lurker, which
explains how your address (and mine) came to be used.

You *do* have all the security patches up to date, don't you?
Not the ones from two days ago, but from *today*? (Microsoft has opened
new holes with some of the patches closing the old ones, so staying
up-to-date will help. Using a non-Microsoft OS will help a lot more. :-)

I've added about a half-dozen IP addresses of infected machines
to my blocklist, to slow down the flow that I've been getting. As a
result, I've not been getting them direct, but the bounces from ISPs who
filter out virii show the same IP addresses that I'm blocking as the
source (with my e-mail address forged).

The virus will usually send out a number under one forged
"From: " address, then move on to the next.

Good Luck,
DoN.


Spent last night checking the anti-virus updates on the 6 micro$oft machines
in the house and checking log files on the two linux machines. Didn't find any
infections but felt good about the work I'd done. At work, one of our sites
took themselves of the Wide Area Network yesterday because the had been got
:-(

Mark Rand
RTFM