Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
What the F.............
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
sabre66
n00b
n00b


Joined: 23 Jun 2002
Posts: 52

PostPosted: Sat Sep 25, 2004 4:30 pm    Post subject: What the F............. Reply with quote

Well this seems weird aparently I sent an email with a virus attached to it

Code:
Return-Path: <>
Received: from mail.sercm.org ([202.71.144.240]) by
        priv-edtnes81.telusplanet.net (InterMail vM.6.01.03.02
        201-2131-111-104-20040324) with ESMTP id
        <20040924020156.MDEN22088.priv-edtnes81.telusplanet.net@mail.sercm.org> for
        <xxxxxxx@telus.net>; Thu, 23 Sep 2004 20:01:56 -0600
Received: from exim by mail.sercm.org with local (Exim 3.22 #1) id
        1CAfHm-0000op-00 for xxxxxx@telus.net; Fri, 24 Sep 2004 07:24:10 +0530
X-Failed-Recipients: -0001j7-00@sercm.org
From: Mail Delivery System <Mailer-Daemon@sercm.org>
To: xxxxxx@telus.net
Subject: Mail delivery failed: returning message to sender
Message-Id: <E1CAfHm-0000op-00@mail.sercm.org>
Date: Fri, 24 Sep 2004 07:24:10 +0530
X-Evolution-Source: pop://xxxxxxx@pop.telus.net
Mime-Version: 1.0

This message was created automatically by mail delivery software (Exim).

A message that you sent could not be delivered to one or more of its
recipients. This is a permanent error. The following address(es) failed:

  -0001j7-00@sercm.org
    unknown local-part "-0001j7-00" in domain "sercm.org"

------ This is a copy of the message, including all the headers. ------

Return-path: <xxxxxx@telus.net>
Received: from ser ([127.0.0.1] helo=sercm.org)
        by mail.sercm.org with esmtp (Exim 3.22 #1)
        id 1CAfHm-0000ol-00
        for -0001j7-00@sercm.org; Fri, 24 Sep 2004 07:24:10 +0530
From: xxxxxx@telus.net
To: -0001j7-00@sercm.org
Subject: Re: My details
Date: Thu, 23 Sep 2004 19:05:13 -0600
MIME-Version: 1.0
Content-Type: multipart/mixed;
        boundary="----=_NextPart_000_0011_00000F1E.00007958"
X-Priority: 3
X-MSMail-Priority: Normal
Message-Id: <E1CAfHm-0000ol-00@mail.sercm.org>

This is a multi-part message in MIME format.

------=_NextPart_000_0011_00000F1E.00007958
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit

------------------  Virus Warning Message (on ser)

Found virus WORM_NETSKY.D in file my_details.pif
The uncleanable file is deleted.

---------------------------------------------------------

------=_NextPart_000_0011_00000F1E.00007958
Content-Type: text/plain;
        charset="Windows-1252"
Content-Transfer-Encoding: 7bit

Here is the file.

------=_NextPart_000_0011_00000F1E.00007958
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit


------------------  Virus Warning Message (on ser)

my_details.pif is removed from here because it contains a virus.

---------------------------------------------------------
------=_NextPart_000_0011_00000F1E.00007958--


Can this be true? how can this be? I didn't even send any email out in the last week, especially to that address. Is it possiblle Im being screwed with and if so how to find out.
_________________
By gazing upon the image of the McMartyr, you too have become *permanently* and *irrevokably* redeemed. You are now officially a Melchizedek Priest of McChurch.
Back to top
View user's profile Send private message
Tsonn
Guru
Guru


Joined: 03 Jun 2004
Posts: 550

PostPosted: Sat Sep 25, 2004 4:49 pm    Post subject: Reply with quote

Sadly this still isn't common knowledge... it should be.

Viruses have been spoofing email addresses for a long time. You can find a lot of information on the topic if you google for it.

A lot of admins are out of touch... they still bounce virus emails even when they usually end up going to the wrong person because the address is spoofed.

Anyway. What it means is, someone who has your address in their address book has a virus. You can sometimes figure out who it is by looking at the mail headers; I've tracked down the infected computer a few times. Try reading some of the information google turns up if you want to learn how to do that.
_________________
If your question was answered, please edit the first post and add [SOLVED] to the title. Thanks!
Back to top
View user's profile Send private message
pjp
Administrator
Administrator


Joined: 16 Apr 2002
Posts: 20585

PostPosted: Sat Sep 25, 2004 8:44 pm    Post subject: Reply with quote

Similar thread title even: wtf is this?
_________________
Quis separabit? Quo animo?
Back to top
View user's profile Send private message
nobspangle
Veteran
Veteran


Joined: 23 Mar 2004
Posts: 1318
Location: Manchester, UK

PostPosted: Sat Sep 25, 2004 11:05 pm    Post subject: Reply with quote

26199 wrote:
Anyway. What it means is, someone who has your address in their address book has a virus.
It can be even more random than that. Most viruses these days can scan any text file on a system for email addresses, this means email addresses can be read from other emails (like chained forwards where one person sends a mail to a load of people and they send it to their mates and every time it get's forwarded everybodies email is added to the top) and also from cached web pages.
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum