Forum Moderators: open

Message Too Old, No Replies

What's your virus record?

Not actual virii - but bounced mail...

         

RobinC

6:48 pm on Sep 19, 2003 (gmt 0)

10+ Year Member



Basically, some idiot who's virus protection isn't up to date has got infected, and some of my email addresses are in their address book - the virus (or virii maybe) is using that as a spoof From: address, hence everything that has that is bouncing back to me...

Please note, I'm not infected, and don't run any of the software that is the root, my firewall and windoze are both up to date, so I'm not talking about getting "attacked", but about the fallout of someone else's attack... Oh, and from the timestamps I can see they're sending out thousands more of these with other From: addresses...

Anyway - 18 hours, 2500 "bounced" emails and counting...

Thank god I'm not on dialup any more ;-P

Macguru

7:31 pm on Sep 19, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Hi RobinC,

Bounced emails could be caused by a virus. But with such a huge amount of messages bouncing back to you, I suspect it could be some SPAMMER using your adresses in it's forged headers.

It could also be someone using formail exploits from your sites. Did you ask your web hosts about recent suspicious activities on your sites?

pendanticist

7:35 pm on Sep 19, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Yes, and if you can - do a 'find' on the term "formmail" (w/o " marks) of your access_log files to see if that is the case. If nothing else, it'll narrow down the variables a bit.

Pendanticist.

RobinC

7:48 pm on Sep 19, 2003 (gmt 0)

10+ Year Member



It's not anything on the sites - simple reason, I run them on this computer, no mail servers or anything running on here (firewall & website logs were checked very soon after this started) - as for some spammer - about 1/5 of the bounced emails contians the actual content, and it's that old "microsoft update" virus...

What I really hate is that it's making up emails based on my hostnames - but I get every email address to them, so filtering is easy, just makes a *huge* list in the Spam folder ;-)

pendanticist

8:00 pm on Sep 19, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



>it's that old "microsoft update" virus... [webmasterworld.com]

Pendanticist.

RobinC

8:07 pm on Sep 19, 2003 (gmt 0)

10+ Year Member



Just because I'm a world-weary old geek... or something ;-)