I don't know if this is a ruse to get someone to open a virus or not, but 
here is a message that I recently received:

. > I just want to first and foremost say that we are extremely sorry for
. > inconvenience the virus that infected our computer in the Morro Bay 
. > Office has caused.  We have been able to fix the problem and I have 
. > attached a fix to this email if you also accidentally open this virus. 
. > The email is very basic 

. > Hi! How are you?
. > I send you this file in order to have your advice
. > See you later. Thanks

. > DO NOT OPEN THE ATTACHMENT!!!


. > but please see the information provided by Pac Bell to get a better
. > understanding of it.

. > > For a complete description of this virus, please refer to the bulletin
. > available at http://www.cert.org/advisories/CA-2001-22.html.

. > Thank you.

There *was* an attachment which required windoze to run, but I had not 
previously received the virus from the originator of this message.  The 
contradictory nature of this message makes my suspicous mind think that this 
is a ruse to get the recipient to open the virus.

Roger Turk
Tucson, Arizona  USA

Steve wrote:

. > On Fri, 3 Aug 2001, Steve wrote:

. > >   During this round of Code Red, I've been hit 53
. > > times already.  3 times in just the last 5 minutes.
. > > Believe it or not, you're being hit too.  It's just
. > > that your machines don't log that fact.

. >   Code Red I was spreading at an increasing pace:

. > 01 Aug - 15
. > 02 Aug - 23
. > 03 Aug - 30
. > 04 Aug - 36

. >   But since Code Red II came out late yesterday, it 
. > seems to have taken another jump in its ability to 
. > reach more machines faster.  On 05 Aug as of 10:52 am, 
. > I'd already had 27 hits consisting of 4 Code Red I 
. > hits and 23 Code Red II hits.

. >   Code Red II leaves a back door into the compromised
. > machine, allowing almost anyone to have root access 
. > to it.

. > http://www.incidents.org/diary/diary.php

. > >   There IS a MickeyMouseSoft patch for this worm.  I 
. > > suppose after a few months enough people will have 
. > > downloaded and applied it, that the Code Red furor will 
. > > die down... but guess what.  Another exploit in IIS 
. > > will be discovered by some other cracker, and the next 
. > > worm could be even more devastating.  

. >   Wow, and so soon too.  The patch for Code Red I is 
. > neatly sidestepped by Code Red II, so those dedicated 
. > M$ admins who applied the first patch must now apply 
. > yet another.  It baffles me no end why any webmaster
. > or any kind of sysadmin would put up with this 
. > security-by-patch mentality.

. >   Of course, being released on the weekend as it was,
. > many webmins won't even realize they're compromised 
. > until Monday morning, giving this worm a really great
. > 2-day window of spreading unabated.

Reply via email to