Re: So now the list server is somehow being used to send out B64-encoded malware?
Marc Joliet <[email protected]> Thu, 23 Apr 2026 03:06:04 +0200
| Newsgroups | gmane.linux.audio.users |
|---|---|
| Message-ID | <[email protected]> |
(Sorry for forgetting to bottom-post, I will try not to do that again.) Am Donnerstag, 23. April 2026, 01:23:39 Mitteleuropäische Sommerzeit schrieb david: > I looked at it in a text editor. It consisted of two blocks of > Base64-encoded, neither particularly long. > > Oh, well! Email was never designed for real security, anyway. AFAIK base64 encoding is not unusual in emails, or at least standards- compliant. In any case, KMail decoded it and rendered it as a plain-text message here, whose contents amount to an "I've hacked you, now send me bitcoins" type spam mail (of which I've gotten only a handful over the years and which are laughably vague and obviously spam). It doesn't *look* like it contains malware, it's just an email that was rejected by Mailman, so returned to sender (as an attachment), but the sender was spoofed to be this mailing list, therefor that's where Mailman sent it. Or at least that's what I suspect happened. I suppose Jeremy Jongepier will have to verify whether that's in any way accurate or not. (I've gotten rejections from Mailman on occasion and attaching the rejected email is, as far as I can remember, common.) Interesting. I tried to verify my memory on rejected emails being attached and instead found a prior occurrence of such spam from "Thu, 26 Dec 2024 19:56:45 +0100". That email also spoofed its "From" header: From: linux-audio-user-cunTk1MwBs/[email protected] To: info-cunTk1MwBs/[email protected] That one was HTML instead of base64 encoded plain-text. > On 4/22/26 04:50, Marc Joliet wrote: > > I'm no expert on email, but in the case of the one spam message I got > > through this list it looks like the spammer tricked the mailing-list > > software to send the original (rejected!) email to itself. Probably even > > by accident, because lots of the spam I used to get spoofed the sender to > > be identical to the recipient, so I don't think that's unusual by itself. > > > > Am Mittwoch, 22. April 2026, 09:04:50 Mitteleuropäische Sommerzeit schrieb > > > > David Kastrup: > >> david <[email protected]> writes: > >>> Just wondering...sorry to bother you, you may now return to your > >>> regularly scheduled interruption. > >> > >> I find that amusing since less than a week ago a post of mine was > >> rejected because it exceeded something like 50kB of size because of a > >> processed audio attachment (something like 250kB or so). > >> > >> So if the malware manages to stay under that limit, it must be coded > >> comparatively efficient for today's standards. > >> > >> Or it is considered important enough that a moderator explicitly gives > >> their ok.
signature.asc
(application/pgp-signature, 265 B)
-----BEGIN PGP SIGNATURE----- iJEEABYKADkWIQS2YUPDQn1ADQEoj0uXgvYOs+E2oAUCaelwfBsUgAAAAAAEAA5t YW51MiwyLjUrMS4xMiwyLDIACgkQl4L2DrPhNqALVgD/bAMctOrfEJirtMFsJTJk 90o2shYmnMlLdYRnmHXLvOYBAPtF4BBdnChWtx/xklo5+WjblDMpRZjF1v+8aTOe VScM =GQvL -----END PGP SIGNATURE-----