On Friday 06 Jun 2003 3:01 am, Stephen Kuhn wrote: > On Fri, 2003-06-06 at 10:53, Chris wrote: > > Has anyone else gotten an email today with the subject: > > > > Re: [newbie] OT - PCLO offline because of SCO! > > It's either Bugbear.B or Sobig.H doing it - so someone's been not > only using an M$ mail package, but they're infected as well...(and > they won't know they're sending it because it's got it's own SMTP > server built into the code....hehehehe)
I don't know much detail about how these things work but several things struck me. First, it seems that it is a list member that is infected on his windows partition (or work machine?), since it is obviously sending to addresses that have been gathered from list traffic. Secondly, is it coincidence that it uses 'derek' as the person asking you to look at the link? That would give it an air of respectability on this list. I have been fortunate in my long association with computers to never actually catch a virus (though not just luck, I always took a lot of precautions), but I've been shocked at the fact that over the past 2 weeks I must have had about 10 coming onto this box. Although I'm safe myself, it seems that the ways of entrapping are becoming much more sophisticated. We may not be infected, but if our isps go down under the pressure of infected traffic we still suffer. Anne
Want to buy your Pack or Services from MandrakeSoft? Go to http://www.mandrakestore.com