lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-Id: <20070219220321.0cb8926f.timo.schoeler@riscworks.net>
Date: Mon, 19 Feb 2007 22:03:21 +0100
From: Timo Schoeler <timo.schoeler@...cworks.net>
To: full-disclosure@...ts.grok.org.uk
Subject: new worm traveling the net? (GNU/Linux)

ahoy,

a friend of mine contacted me because he saw lots of emails (60) to
catchthismail@...ain.tld starting at about 5:00 am (US east coast
time).

so i checked our company's log files (about 300 users) and saw the same
here starting at about 10:45am CET, ending at about 6pm, and about 40
emails of this in total.

there was not pattern except the <catchthismail@...ain.tld> To: header;
interestingly, scanning a few of those hosts immediately (dynamic
assigned IP addresses) showed that it was GNU/Linux hosts.

is this a new worm spreading or something already known?

wbr,

timo

-- 
"Or what? You'll release the dogs? Or the bees? Or the dogs with bees
in their mouths, and when they bark they shot bees at you?" (Homer J.
Simpson)

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ