Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Calling all techies - viral e-mail questions

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » The DU Lounge Donate to DU
 
sybylla Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 02:15 PM
Original message
Calling all techies - viral e-mail questions
I am part owner of a computer controls firm so I have some knowledge of this but as a tech writer, I have to admit I don't know it all so I have a couple of questions.

Since 8am this morning I have received 25 (and they are still coming) viral emails with .scr or .pif attachments. The interesting part is that they are coming in on my local dem party address. I use this for all party correspondence and it gets published in the paper so I do get trash once in a while. But in 8 years of being connected to the internet, I have never received 25 of these in one day and they are nearly all duplicates of the same 3 or 4 viral e-mails with different phony senders, most of them dems or dem orgs, and a slight variation in the subject line.

Question 1: is it possible that this is coming from just one computer?

Question 2: is it possible that I am being targeted?

Question 3: Or is this just what happens when viral e-mails bounce around between friends in a dem group. That would mean that the e-mails have caught 25 of my acquaintances and my acquaintances' acquaintances so far - right?

I've sent out warnings to my entire list of dems and offered assistance to anyone suffering from quick fingers or exploder's "auto-open" feature.

Any other suggestions - help? My chief engineer is out of town and I could really use your answers and advise.
Printer Friendly | Permalink |  | Top
Kellanved Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 02:17 PM
Response to Original message
1. Most likely three
But neither one nor two are impossible.
Printer Friendly | Permalink |  | Top
 
Liberal Veteran Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 02:18 PM
Response to Original message
2. The answer to all your questions are "Yes"....
Edited on Tue Aug-19-03 02:19 PM by liberal_veteran
It is possible that one machine is doing this.
It is possible you are being targeted specifically.
It is possible that a few people are bouncing it amongst one another. (had to edit on re-reading).

I'd say it's probably just one infected person that the virus is co-opting the address book to mail virii to everyone in the address book over and over again.
Printer Friendly | Permalink |  | Top
 
Kellanved Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 02:24 PM
Response to Reply #2
7. Sobig brings its' own SMTP server
And if I understand the question correctly the "to" is the same in all mails, not the "from".

In any case: sobig fakes the sender field; it uses a few hardcoded addresses and all it can find on the infected machine to fill it.
Printer Friendly | Permalink |  | Top
 
AnnabelLee Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 02:20 PM
Response to Original message
3. Locking-Dupe
Printer Friendly | Permalink |  | Top
 
KC Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 02:21 PM
Response to Original message
4. It is
the new virus/worm going around. You aren't the only one getting those emails

KC
Printer Friendly | Permalink |  | Top
 
sybylla Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 02:21 PM
Response to Original message
5. Thanks everyone
EarlG beat me to this with a thread on a huge number of viral e-mails spreading around today. I figured since it was only on my local dem party address that it was a local problem.

It does seem odd, though, that I'm not getting this on any of the five other e-mail addresses I monitor. Anyone know if they are talking about the same viral e-mail problems in freeperland?
Printer Friendly | Permalink |  | Top
 
AntiCoup2K4 Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 02:21 PM
Response to Original message
6. When a worm hits a computer....
...first thing it does is to hit your address book and send itself to every addy it finds. Then it goes to each one of those computers and does the exact same thing (if not blocked). If you are also in the address book of all of those computers, you will also get a copy of the virus from each of them. The reason worms slow down a network is by the sheer volume of traffic they generate by merely mailing themselves.

Bottom line, if you are on a number of mailing lists and some of those lists have recipients in commmon, you will get a copy of the infected file from every single computer on that list which is not protected from the worm.
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Fri May 10th 2024, 09:53 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » The DU Lounge Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC