lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite for Android: free password hash cracker in your pocket
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <232260000.1080143945@utd49554.utdallas.edu>
From: pauls at utdallas.edu (Paul Schmehl)
Subject: viruses being sent to this list

--On Tuesday, March 23, 2004 08:22:55 PM -0800 John Sage 
<jsage@...chhaven.com> wrote:
>
> Without exception, these are all virii-laden. Whether they got here by
> malice or by chance, they all contain the following:
>
> Received: from NETSYS.COM (localhost [127.0.0.1])
>  by netsys.com (8.11.6p2-2003-09-16/8.11.6) with ESMTP id i2H1kI327175;
>  Tue, 16 Mar 2004 20:46:18 -0500 (EST)
>
Every post to the list will have this.in it, so that's not an indication of 
anything.

Last night I reviewed the archive file, and I see a way to split on each 
message, so I can put the messages in an array and then parse them for 
useful info.  I just have to find the time to whip up the script.

If I find anything useful to the list, I'll post it, but what I've seen so 
far appears to be normal viral activity.  You have to keep in mind that 
viruses forge the sender field routinely.  If the sender is a member of 
this list, and the virus sends an email to the list "from" that sender, 
it's going to go to the list because the list isn't moderated.

At this point I don't see anything to indicate deliberate seeding, but 
that's very preliminary.

Paul Schmehl (pauls@...allas.edu)
Adjunct Information Security Officer
The University of Texas at Dallas
AVIEN Founding Member
http://www.utdallas.edu


Powered by blists - more mailing lists