Bug#765069: Possible malware or viruses included as attachments in message 86 & 91

2016-09-02 Thread Simon McVittie
On Thu, 01 Sep 2016 at 15:05:45 -0400, William L. DeRieux IV wrote:
> These two messages for bug #765069
> https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=765069
> 
> Message 86: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=765069#86
> Message 91: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=765069#91
> 
> File: PO645788.ace and air way bill.jar may possibly contain malware or
> other malicious code (ie ransomeware) since PO645788.ace is a zip file
> containing an
> obfuscated C# executable for windows.

Thanks. In general, all correspondance to a bug should be about fixing that
specific bug, otherwise we'll lose track of the various conversation
threads. Please report any other spam/viruses/malware/etc. in the BTS to
the "Send a report that this bug log contains spam" link at the bottom
of every bug's web interface (which I have now done for this one), or to
the BTS administrators  (cc'd here).

> These messages should be removed as soon as possible to prevent users from
> downloading infected

I would hope that users know by now not to download and run attachments
from obvious spam; if not, they are going to get some sort of virus
sooner or later.

Ordinary developers cannot remove these messages; only the BTS
administrators can do that, and they do not read all the bug mail
(nobody could, there's just too much of it).

S



Bug#765069: Possible malware or viruses included as attachments in message 86 & 91

2016-09-01 Thread William L. DeRieux IV

These two messages for bug #765069
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=765069

Message 86: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=765069#86
Message 91: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=765069#91

File: PO645788.ace and air way bill.jar may possibly contain malware or
other malicious code (ie ransomeware) since PO645788.ace is a zip file 
containing an

obfuscated C# executable for windows.

I can only assume that 'air way bill.jar' is the same code only written
in java.

These messages should be removed as soon as possible to prevent users from
downloading infected