[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: ADSL keep alive script or virus



On Fri, Dec 07, 2001, solomon@barak-online.net wrote about "Re: ADSL keep alive script or virus":
> In answer to Nadav's message, I actually think this is relevant - not to LINUX
> but to the ILUG mailing list. I also got one of these messages, but the Subject
> was Re: APM problem. So it seems to me that however this worm is being
> transmitted, it somehow **knows** about various subject on the list. Is it
> possible that there is some access to the server or mailing list? I wonder if
> others have recieved similar messages but with different ILUG related subjects.

As I already mentioned in a previous post, this worm (similar to what other
worms in the past did) "evesdrops" on the infected user's TCP connections,
to find "interesting" email addresses to send a copy of the worm to (instead
of just sending itself to people in your addressbook).
When it finds an address on a web page, it sends this address a copy of the
worm with a subject of "Re:" (nothing after the Re:). However, when it takes
an address from a piece of mail, it uses the original subject line of that
email, to make it look like a real reply. This is why many people got such
worms because they posted on linux-il. Apparently we have some Windows-using
traitors on the list ;)

If you have any more questions on how this worm operates, please look up
badtrans-b in your favorite anti-virus site (or look it up in a search engine
if you don't have a favorite anti-virus). The only reason I replied to this
question now was so people stop being afraid that the iglu server was cracked,
or something of this sort.

-- 
Nadav Har'El                        |      Friday, Dec  7 2001, 22 Kislev 5762
nyh@math.technion.ac.il             |-----------------------------------------
Phone: +972-53-245868, ICQ 13349191 |Don't be irreplaceable. If you can't be
http://nadav.harel.org.il           |replaced, you can't be promoted.

=================================================================
To unsubscribe, send mail to linux-il-request@linux.org.il with
the word "unsubscribe" in the message body, e.g., run the command
echo unsubscribe | mail linux-il-request@linux.org.il