Re: Linux and Virii

mylar <[email protected]> Sun, 08 Feb 2004 23:31:51 -0500
Newsgroups gmane.linux.redhat.ppp
Organization MicroService Co.
Message-ID <[email protected]>
On Sat, 7 Feb 2004 17:12:13 -0800 (PST), Mark S. Ness <[email protected]> 
wrote:

>
>
> I have just never heard of Linux getting infected. Is it p[ossible that
> the messages I didn't send was actually sent from one of those friends of
> friends, but with my address? (Rhetorical question).
>
YES!!! Exactly this is what most likely happened. A infected windows box 
most likely sent out an email with your address as the "from" address and 
hence you get the returned message. It is probably the result of MyDOOM 
which does not infect Linux boxes.



> Eljon Curry said:
>> While i've never used this mail client I do know of the new worm that's
>> going around.  It will spoof emails like the ones you are receiving in 
>> an
>> attemp to get you to open them.  It will read your contacts, spoof them
>> with
>> an address from 4 _contact_scans_ago_ as a way of generating email
>> addresses.  I'd check out viruslist.com for some information about
>> detection
>> and removal.  My firm guess is this is what's going on.  Either you're
>> infected and sending to those in your list or you're receiving the 
>> spoofed
>> mails.  The subject content is usually something about either Failed
>> Daemon
>> or Returned in some way.  Follow up if you can.  I'd like to know if i'm
>> way
>> off or dead on.  Good luck.
>>
>> Eljon Curry
>>
>> -----Original Message-----
>> From: [email protected]
>> [mailto:[email protected]]On Behalf Of Mark Ness
>> Sent: Friday, February 06, 2004 8:09 PM
>> To: [email protected]
>> Subject: Linux and Virii
>>
>>
>> This may be OT, but I guess it could be concidered in the realm of ppp.
>>
>> I have a stripped down RH9.0 for for internet connection, and a Mandrake
>> 9 connected by LAN. Dial-up ISP with dynamic IP, and realitively short
>> on-line time per connection (by choice, with no dedicated line, can't
>> tie up the phone).
>>
>> I've been hit with several infected emails in the last week or so.
>> Recieving these virus' is not the problem, getting "returned" or 
>> "refused"
>> mail from people and places I HAVE NOT SENT MAIL TO is the problem.
>>
>> A friend of mine has just finished setting up Squirrel mail on his Linux
>> system. He's been hosting my "domain" mail for some time now, and I have
>> had no problems. It's just since I started using his Squirrel that I
>> started getting these returned mails. Is it possible that Squirrel mail
>> has some vulnerability to infections? Or has someone just finally gotten
>> around to "stealing" my address (it's one of many addresses, but it is
>> my "main" address).
>>
>> FYI I have never put my Windoze on line, and I never check suspect mail
>> (that Linux can't display properly) with Windoze. If it won't display on
>> Linux, I delete them. If I don't know the sender, I usually go ahead and
>> check them out then delete them.
>>
>> Has anybody ever heard of Linux being infected, at least to the extent
>> of someons home dir?
>>
>> One more point. Alot of the mail I get is from friends who for some
>> reason or another never cut and paste messages, but just forward them
>> and forward them etc until the header is actually larger than the file
>> itself.
>>
>> --
>> --------------------------------------------------------------------------
>> [email protected]                                             
>> www.noneinc.us
>>
>>
>> _______________________________________________
>> Redhat-ppp-list mailing list
>> [email protected]
>> https://www.redhat.com/mailman/listinfo/redhat-ppp-list
>>
>>
>>
>>
>>
>>
>
>
> _______________________________________________
> Redhat-ppp-list mailing list
> [email protected]
> https://www.redhat.com/mailman/listinfo/redhat-ppp-list



-- 
Using M2, Opera's revolutionary e-mail client: http://www.opera.com/m2/