Thoughts Media.com

 


Windows Phone Thoughts

Loading feed...

Digital Home Thoughts

Loading feed...

Apple Thoughts

Loading feed...




Go Back   Thoughts Media Forums > Thoughts Media Off Topic

Reply
 
Thread Tools Display Modes
  #1  
Old 01-28-2004, 12:30 AM
Jason Dunn
Executive Editor
Jason Dunn's Avatar
Join Date: Aug 2006
Posts: 29,160
Default Community Service Warning: What You Should Know About the Mydoom Worm

http://www.microsoft.com/security/a...irus/mydoom.asp

"W32/Mydoom@MM spreads through e-mail. This worm can disguise the sender's address, a tactic known as spoofing, and may generate e-mail messages that appear to have been sent by Microsoft. Many of the addresses Mydoom uses are valid addresses that are being spoofed for malicious purposes.

Technical information about the virus is available from antivirus vendors participating in the Microsoft Virus Information Alliance (VIA). The Mydoom worm is also known by the names Novarg, Shimg, and Mimail.R.

If you ever receive a questionable e-mail message that contains an attachment, do not open the attachment. If you cannot confirm with the sender that the message is valid and that the attachment is safe, delete the message immediately. If you receive a questionable message that purports to be from Microsoft, you should be aware that Microsoft never distributes software through e-mail."
__________________
Want to contact me personally? Use this. Want to read my personal blog? Check it out. Want to follow me on Twitter? Here you go.
 
Reply With Quote
  #2  
Old 01-28-2004, 12:34 AM
rugerx
Ponderer
Join Date: Dec 2003
Posts: 95

You may also recieve a bounce back that the email "you" sent was rejected due to virus.

This does not mean your system sent it. The spoofing involves the virus extracting email addresses from users address book, (which may contain your email address, ie a friend has you in contacts) and then sends multiple emails on your behalf without ever asking you!

Nasty indeed.
 
Reply With Quote
  #3  
Old 01-28-2004, 12:54 AM
Iznot Gold
Intellectual
Join Date: Jul 2002
Posts: 146

Wow after reading this I checked with my anti virus supplier and in the time it took me to read the info on the worm, the reported incidences had increased four-fold in the UK! 8O
Regards
David
 
Reply With Quote
  #4  
Old 01-28-2004, 01:16 AM
Jonathan1
Pontificator
Join Date: Mar 2002
Posts: 1,329

hehe. My e-mail client is setup to auto strip any executable attachments before I even touch them and my filters are setup to ax any HTML e-mails. All my contacts know this. So it's not a problem for me. Thanks anyways.
__________________
PDA History: Palm Pilot 5000 -> Apple Newton 2100 -> Casio E-11 -> iPaq 3650 (64MB Upgrade) -> iPaq 3700 -> Casio EM-500 -> HP Jornada 568 -> HP iPaq hx4705 www.spreadfirefox.com
 
Reply With Quote
  #5  
Old 01-28-2004, 01:17 AM
Jason Dunn
Executive Editor
Jason Dunn's Avatar
Join Date: Aug 2006
Posts: 29,160

Quote:
Originally Posted by Jonathan1
hehe. My e-mail client is setup to auto strip any executable attachments before I even touch them and my filters are setup to ax any HTML e-mails. All my contacts know this. So it's not a problem for me. Thanks anyways.
Why? You obviously have the knowledge to know what to open and what not to open, so why the extreme measures that destroy valid HTML communications?
__________________
Want to contact me personally? Use this. Want to read my personal blog? Check it out. Want to follow me on Twitter? Here you go.
 
Reply With Quote
  #6  
Old 01-28-2004, 01:18 AM
Godsongz
Thinker
Join Date: Aug 2006
Posts: 437

I had over 800 copies of this worm emailed to addresses at my company today. The odd thing was, many of them were sent to addresses that didn't exist. I think the worm, after grabbing a valid address @suchinsuch.com, is also sending messages to common names @suchinsuch.com. I saw lots of first names in these bogus addresses, like bob@, susan@, david@, frank@, etc etc etc... my company doesn't use that scheme.
 
Reply With Quote
  #7  
Old 01-28-2004, 01:23 AM
denivan
Theorist
Join Date: Apr 2004
Posts: 262

Quote:
Originally Posted by Godsongz
I had over 800 copies of this worm emailed to addresses at my company today. The odd thing was, many of them were sent to addresses that didn't exist. I think the worm, after grabbing a valid address @suchinsuch.com, is also sending messages to common names @suchinsuch.com. I saw lots of first names in these bogus addresses, like bob@, susan@, david@, frank@, etc etc etc... my company doesn't use that scheme.
Indeed, a client of mine went crazy because of all the inbound failure notices he got from the virus that was sent to george@... , maria@ .... etc.

Normally inbound notices are helpfull, you would be surprised how many people type an e-mail address wrong, so an inbound failure can tell who tried to contact who within the company, but I decided to automatically delete all inbound failure messages until this blows over...any ideas on a better way to solve this ?

Kind regards,
Ivan
 
Reply With Quote
  #8  
Old 01-28-2004, 01:27 AM
Jason Dunn
Executive Editor
Jason Dunn's Avatar
Join Date: Aug 2006
Posts: 29,160

Quote:
Originally Posted by denivan
Normally inbound notices are helpfull, you would be surprised how many people type an e-mail address wrong, so an inbound failure can tell who tried to contact who within the company, but I decided to automatically delete all inbound failure messages until this blows over...any ideas on a better way to solve this ?
Between viruses and spammers hijacking domains to use as return addresses, inbound notices have become drastically less useful. When a spammer stole my domain name (kensai.com) and started using it as a domain for fake return addresses, I started getting 50+ bounce messages every day, because my domain it set to forward ALL email to me (a blanket forward). I've since had to change that because of the damn spammer...
__________________
Want to contact me personally? Use this. Want to read my personal blog? Check it out. Want to follow me on Twitter? Here you go.
 
Reply With Quote
  #9  
Old 01-28-2004, 01:47 AM
Janak Parekh
Editor Emeritus
Janak Parekh's Avatar
Join Date: Aug 2006
Posts: 15,171

Quote:
Originally Posted by Jason Dunn
Why? You obviously have the knowledge to know what to open and what not to open, so why the extreme measures that destroy valid HTML communications?
I think it just boils down to the fact that people are very polarized about the concept of HTML email.

--janak
 
Reply With Quote
  #10  
Old 01-28-2004, 01:54 AM
Air
Pupil
Join Date: Dec 2003
Posts: 49

people who uses HTML to write email should be prohibited to reproduce. Instant castration I say.
 
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 09:16 PM.


Powered by vBulletin® Version 3.8.9
Copyright ©2000 - 2019, vBulletin Solutions, Inc.
Copyright Thoughts Media Inc. 2009