Cosmin Nicolaescu on 6 Jul 2005 12:49:45 -0000 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Wed, July 6, 2005 8:30 am, Rebecca Ore said: > All these means that someone on an infected machine had addresses and > spoofed both the sender (I've gotten email from clueless admins telling > me that my machine was sending bot spam when that highly unlikely > (running Mac or Linux, not opening email with attachments I wasn't > expecting). Some of the bots even harvested email addresses from > Usenet. It's possible that the current bot has a web crawler. Nobody > on this list is necessarily infected -- the bot can get addresses in > many way. > > True. Usually the emails that we get at work like that fit this profile have Received: from cs.drexel.edu (exchange.dclweb.org [196.192.64.252]) or some other server, just _not_ the one it actually claims it is. spamprobe is tagging those as spam w/o any problems though :) - -Cos - -- GPG key fingerprint = DE9F 4664 E666 2BD1 903E 4F4D EA31 5FB1 C7F9 08C1 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.1 (GNU/Linux) iD8DBQFCy9PE6jFfscf5CMERAuUlAJ4n+IUORdYBEEBXPYzlKQI3QjHqzACg5pDb OYDiKtcSULoI6d2rAB/srJE= =PR4Z -----END PGP SIGNATURE----- ___________________________________________________________________________ Philadelphia Linux Users Group -- http://www.phillylinux.org Announcements - http://lists.phillylinux.org/mailman/listinfo/plug-announce General Discussion -- http://lists.phillylinux.org/mailman/listinfo/plug
|
|