Tis the season to be cracking ...
Not only do we have SirCam and CodeRed, but just tday I started getting a bunch of [what looks like spam] email virii. They're all hitting my filters, but I thought y'all might have noticed similar things. This is two weeks before many Universitys open for business. That's right about the time I drop my EDU filters in place [having kids keeps you aware of these things]. I haven't seen this reported yet. It looks like we have a whole flock of wannabe virus writers out there this year. I'd block EDU permanently, but too many ICANN folks are on EDU addresses. -- R O E L A N D M J M E Y E R Managing Director Morgan Hill Software Company t:01 925 373 3954 c:01 925 352 3615 f:01 925 373 9781
On Yesterday, Roeland Meyer wrote:
Not only do we have SirCam and CodeRed, but just tday I started getting a bunch of [what looks like spam] email virii. They're all hitting my filters, but I thought y'all might have noticed similar things. This is two weeks
This just crept into my mailbox... Received: from dave-pc ([IP Address in Germany]) Date: Fri, 10 Aug 2001 02:32:07 -0400 (EDT) [ Part 1, Application/OCTET-STREAM (Name: "CNJOIMCN.EXE") 28KB. ] [ Cannot display this part. Press "V" then "S" to save in a file. ] Except for date/time and received from, no other headers. -Gordon -------------------------------------------------- Gordon Ewasiuk, Sun Firefighter, Winstar VHC O: 703.889.4035 C: 703.731.4828 IM: wanjunkie The REAL office number is here-----> 703.893.4901 Have you had your Solaris today? -------------------------------------------------- 2:59am up 26 day(s), 4:36, 2 users, load average: 0.00, 0.00, 0.01
On Fri, 10 Aug 2001, Gordon Ewasiuk wrote:
On Yesterday, Roeland Meyer wrote:
Not only do we have SirCam and CodeRed, but just tday I started getting a bunch of [what looks like spam] email virii. They're all hitting my filters, but I thought y'all might have noticed similar things. This is two weeks
This just crept into my mailbox...
Received: from dave-pc ([IP Address in Germany]) Date: Fri, 10 Aug 2001 02:32:07 -0400 (EDT)
[ Part 1, Application/OCTET-STREAM (Name: "CNJOIMCN.EXE") 28KB. ] [ Cannot display this part. Press "V" then "S" to save in a file. ]
Except for date/time and received from, no other headers.
Perhaps this is actually coming from one source, then: Return-Path: <> Delivered-To: james@pil.net Received: (qmail 21095 invoked from network); 10 Aug 2001 06:03:14 -0000 Received: from host-979.i-dial.de (HELO dave-pc) (193.149.52.172) by richard2.pil.net with SMTP; 10 Aug 2001 06:03:14 -0000 MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="--VE16Z8L6JO5" [ Part 1, Application/OCTET-STREAM (Name: "CNJOIMCN.EXE") 28KB. ] [ Cannot display this part. Press "V" then "S" to save in a file. ] James Smallacombe PlantageNet, Inc. CEO and Janitor up@3.am http://3.am =========================================================================
On Today, up@3.am wrote:
On Yesterday, Roeland Meyer wrote:
Not only do we have SirCam and CodeRed, but just tday I started getting a bunch of [what looks like spam] email virii. They're all hitting my filters, but I thought y'all might have noticed similar things. This is two weeks
This just crept into my mailbox...
Received: from dave-pc ([IP Address in Germany]) Date: Fri, 10 Aug 2001 02:32:07 -0400 (EDT)
Perhaps this is actually coming from one source, then:
Return-Path: <> Delivered-To: james@pil.net Received: (qmail 21095 invoked from network); 10 Aug 2001 06:03:14 -0000 Received: from host-979.i-dial.de (HELO dave-pc) (193.149.52.172) by richard2.pil.net with SMTP; 10 Aug 2001 06:03:14 -0000
Yep. Same dude. -G
participants (3)
-
Gordon Ewasiuk
-
Roeland Meyer
-
up@3.am