View Single Post
  #10   Report Post  
Gary Coffman
 
Posts: n/a
Default OT Gremlins have been busy!

On Thu, 21 Aug 2003 04:50:05 GMT, "Harold & Susan Vordos" wrote:
Booted up tonight after putting in a day of work on the house we're
building. Waiting for me were 67 messages, 28 of which were virus infected.
Our ISP traps them, but we get a report along with anything that wasn't
deleted. Along with the messages were three from other ISP's suggesting
that I am sending mail that is infected, that I should attend to my computer
before re-sending the messages, which they had deleted. Funny thing is,
I'm not the sender. I hadn't even heard of the recipients, all of which
were commercial establishments. Anyone out there having the same "good
luck"?


Sure. Lots of viruses and worms will forge the Reply To field with an
address they got from the infected computer's contact list. So the
virus may actually be spamming from the computer of an aquaintence
who has your email address in his address book.

Some viruses can actually grab an address off a usenet posting and
use that. So you might not even be in the infected machine's address
book. Your address might have been picked up on the fly while the
person with the infected machine was reading this newsgroup with
Outlook Express or a browser. (Shouldn't happen if they're reading
with Agent.)

Or, a commercial spammer's machine might have gotten infected,
and the virus is using the spammer's list of email addresses as
Reply To spoofs as well as targets. (This seems to have happened
with the latest worm making the rounds. The flooding has been too
rapid and too huge for it not to have had access to a major spammer's
address list. At least that's what some network security types are
claiming.)

Gary