Jesse Schultz on Sun, 5 May 2002 19:50:16 +0200


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

Re: [PLUG] Possible Trojan/Virus in the wild?


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Most likely klez.  Its a new version (klez.h I believe)

No danger to Linux mail users.

It does, however also spread through netbios shares.  So although
linux boxes themselves would not be affected, Samba shares could
become carriers.  We ran into this before with the nimda worm.

BTW, If you notice the reply coming from an outlook express client, I
am answering this while messing around from the windows side of a
dual boot system.  Experimenting with a win32 GnuPG outlook plugin.

First attempt using it for a signiture, loogout.

- ----- Original Message ----- 
From: "multiple seriousity" <msimons@slackware.com>
To: <plug@lists.phillylinux.org>
Sent: Sunday, May 05, 2002 2:41 AM
Subject: [PLUG] Possible Trojan/Virus in the wild?


> Greetings, 
>  
>   for about the 4th time in a week or so... I have received odd
> mailings...  generally consisting of 3 or 4 sections, a pretty much
blank
> 4-line html section, a rather large audio section (2 or 3 of the
mailings
> have been 100k midi files, I just received one that was a 0 byte
wav
> section), and then a file, somewhat related to linux.)  
> 
> Oh, another thing is a random meaningless title.
> 
> any ideas whats up??  
> 
> the first one I receveid I actually thougth might have been for
> me... cause it seemed to been a submission for the slackware
graphics
> pages.. but then I couldnt actually save the file due to a = in the
octet
> stream (and ['s in the file names, too, but that I can change..) 
> 
> hmmm, well it's either that or some weird misconfigured email
proggies. 
> 
> -- 
> msimons@slackware.com INFORMATION*MEDIA*PHOTOGRAPHY
msimonsmail@yahoo.com 
> Creative Arts Resource Project : PTMaterials Exchange :
www.pleasetake.org
> A 501(c)3 Non-profit Organization Arts and Environmental Resource
Network
> Shopping Online? Use http://www.igive.com/carp/ make donations at
no cost!
> Do you like what I do? Consider donating resources to CARP; Ask me
how!
> 
> 
>
______________________________________________________________________
> Philadelphia Linux Users Group       -     
http://www.phillylinux.org
>
Announcements-http://lists.phillylinux.org/mail/listinfo/plug-announce
> General Discussion  - 
http://lists.phillylinux.org/mail/listinfo/plug
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (MingW32) - GPGOE 0.4.1
Comment: For info see http://www.gnupg.org

iD8DBQE81WwhK3KGHMBjApYRAl+5AJ9WLbn796YVgsqtbDrsfZK02+RqngCfSXQP
MeiR4mKgy2vTGHsIRUCLsT8=
=Km+v
-----END PGP SIGNATURE-----



______________________________________________________________________
Philadelphia Linux Users Group       -      http://www.phillylinux.org
Announcements-http://lists.phillylinux.org/mail/listinfo/plug-announce
General Discussion  -  http://lists.phillylinux.org/mail/listinfo/plug