Virus massive attack

Z

Zvi Netiv

Bart Bailey said:
Hi Zvi;

Now that you're recommending MMM, I wonder if you are aware of any
precautions surrounding such use, in light of its addition to the Spybot
S&D "tracks" list?
http://www.safer-networking.org/
A recent poster's answer to my similar query was that it keeps what
might be considered potentially dangerous logs, from a security point of
view.

My recollection is that you like (or use) MailWasher. Neither MW/MMM constitute
a risk in that aspect, anymore than any other mail server monitoring
application.

BTW, I tried both MW and MMM and prefer the latter for its simplicity, being
open source, and especially the auto filter feature. A real life saver when you
need something quick on the weekend, or off hours, when the system manager is
doing more pleasant things than develop filter rules for our mail server. ;)

Regards, Zvi
 
B

Bart Bailey

In Message-ID:<[email protected]> posted on
My recollection is that you like (or use) MailWasher. Neither MW/MMM constitute
a risk in that aspect, anymore than any other mail server monitoring
application.

That was my gut feeling, just thought it strange for MMM to be put on a
watch list, but as you and Jim have indicated, it's more of a matter of
how (or where) the program chooses to manage it's databases.
 
B

BoB

Can you explaine it how?

Thank you!

I purchased Agent years ago to avoid using OE, but OE should have
a similar option, to not DL any msg over 50k. Some are not >140k.

You will receive an abbreviated msg that informs you that it was
not DL'd since it exceeded the size specified.

I then use a freeware, Magic Mail Monitor [110k] to access my mail
box and delete all msgs, after a quick review to ensure that none
are legit. MMM can delete 100's msgs from the server in seconds.

http://www.geeba.org/magic/

BoB
For the duration of Swen, my address is inoperative.
 
G

Gabriele Neukam

On that special day, Bart Bailey, ([email protected]) said...
Don't you still get it as residue from
before your munging?

I can't tell, as I didn't *add* but *change* my address. Whoever might
be trying to send me a letter, will get a "no such user" instead of
having his/her mail dropped into a bin, which will never be looked at.


Gabriele Neukam

(e-mail address removed)
 
D

D McAuliffe

Rick Simon said:
That particular address or any email address formulated in a similar
manner?


--
Rick Simon (e-mail address removed)

Include "spam(trap)key" somewhere in the
body of any email to avoid spam filters.

Thanks for the 400+ Swen email addresses that an ISP blocked then sent a
notification to you as the "sender". The infection apparently does not
include Usenet, as there were no munged addresses. You satisfied my
curiosity as to whether Swen takes addresses other than To or From. The
vast majority looked like message IDs
(200109141635.f8egz9y14005-AT-qs86.pair.com). I noticed that the virus not
only used you as the From, but also included you in the To (That's cold). I
hope you were able to track down who it was, or at least get the flood to
stop. If not, I'll offer my thoughts, such as they are:

The infected user may have an (Web Site) account at Yahoo because of the
following addresses - <bizex-billing-AT-yahoo-inc.com>,
<bizex200-AT-yahoo-inc.com>, <my-register-AT-yahoo-inc.com>, and is
receiving mail because of it (billing problem?).

The Address Book entries appear to be the following:
bobsbuckskins-AT-peoplepc.com, edge-AT-usmo.com, dwagner-AT-foxberry.net,
ccason-AT-nemr.net, rio-AT-centurytel.net, mead-AT-midwest.net,
allaqhorses-AT-aol.com, bridarfarm-AT-aol.com, mandymackey-AT-hotmail.com,
trueblueacres-AT-hotmail.com, frstrlty-AT-iowatelecom.net,
hollanddunn-AT-netconx.net, snidercattle-AT-hotmail.com,
terry.powell-AT-gateway.net,
qtrhorse2000-AT-yahoo.com,slidinb-AT-iowatelecom.net,
sharpvalleyfarm-AT-yahoo.com.

Do you know someone who is an animal enthusiast?

I can now understand why people are getting "hundreds" of these mails.
Considering the bounced message IDs which could be coupled with the Usenet
munged addresses, and Swen sending on restart/connect which starts the
process all over.

Thanks again, and Good Luck,
--

~~~~~~~~~~~~~~~~~~
Dave McAuliffe
<Central Mass> USA
To Email-
Replace: mailinator.com
with: email.com
~~~~~~~~~~~~~~~~~~
 
B

Bart Bailey

In Message-ID:<[email protected]> posted on Tue, 21 Oct
On that special day, Bart Bailey, ([email protected]) said...


I can't tell, as I didn't *add* but *change* my address. Whoever might
be trying to send me a letter, will get a "no such user" instead of
having his/her mail dropped into a bin, which will never be looked at.
Doesn't matter what happens now, I was referring to some people still
having your previous valid addy in their now "infected" machine.
As long as it's out there in some old post or addy list, then swen could
find it.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads

New ransomware attack hits Europe 3
virus 1
New type of attack 3
how did this virus get in 15
Scary clowns 19
Virus Infection??? 1
Virus attack? 1
Scan for virus without opening document 6

Top