Search the archive:
YaBB - Yet another Bulletin Board
 
   
 
Pages: 1 2 3 4
Send Topic Print
VERY IMPORTANT - VIRUS ALERT (Read 1501 times)
Aug 20th, 2003 at 4:51am
RollerBall   Ex Member

 
Here we go again.

My website is currently under attack from yet another low-life piece of sh*t by dozens of virus containing emails.

I am sure I'm not alone but as the emails contain the (forged) identities of many well and less well known names in FS it looks as though the FS community is being targetted.

SO BE WARNED ESPECIALLY IF YOU HAVE A WEBSITE OF YOUR OWN.

The idiot behind it is not very clever and is using a simple attachment method. It's easy to spot and look for the following giveaways.

- Any subject line that starts Re: Re:
- Any attachment that contains a file ending in {xyz}.bat
- Any attachment ending in {xyz}.pif
- Any attachment ending in {xyz}.scr
- Any attachment ending in {xyz).exe

(where {xyz} is a file name)

In any case you should NEVER open any such attachment even when they come from someone you APPEAR to know.

The emails have subjects like

Re: Thank you
Re: Your details
Re: Approved
Re: That Movie  and so on

ANYWAY, YOU HAVE BEEN WARNED Angry

Roger
 
IP Logged
 
Reply #1 - Aug 20th, 2003 at 4:56am

Craig.   Offline
Colonel
Birmingham

Gender: male
Posts: 18590
*****
 
yep already dealing with this one. total now upto 100 recieved.
 
IP Logged
 
Reply #2 - Aug 20th, 2003 at 5:30am

Paz   Offline
Colonel
USA

Gender: male
Posts: 1922
*****
 
  I've got about 15 of them now.
 

&&Still no linked images allowed around here Paz! Naughty...&&
IP Logged
 
Reply #3 - Aug 20th, 2003 at 6:10am

ozzy72   Offline
Global Moderator
Pretty scary huh?
Madsville

Gender: male
Posts: 37122
*****
 
I've got none! Nobody loves me Cry
 

...
There are two types of aeroplane, Spitfires and everything else that wishes it was a Spitfire!
IP Logged
 
Reply #4 - Aug 20th, 2003 at 6:19am

Professor Brensec   Offline
Colonel
Can't you give me a couple
more inches, Adam?
SYDNEY - AUSTRALIA

Gender: male
Posts: 2955
*****
 
I've been getting a number of emails with 'attachments'. I have no idea what any of them are or were, but I'm sure some must have been 'virus's.

Not on a webpage but just in my personal email.

It'll do them no good with me. I never, ever open an email that has an attachment, unless I have specifically asked for it from someone I know to be ok, and even then, I'm very careful.

I have had alot of the 'You've just been approved' ones.

Just as a point of interest, I'll be posting a business webpage shortly, where people will be emailing an order form to me. It will be through my Web host who has a SSL facility for me to use. Can someone attach or somehow 'infect' my order form with something and then send it to me so that it will look like any other form that is returned to me? If so what can I do to guard against this?

P.S. Is there any penalty if one of the morons happens to be caught. Does anyone know of a case where a 'Virus spreader' has been caught?.....What happened?
Does he still have balls...........or in the case of a woman......does she still have a ****.   Grin Wink
 

...&&...&&http://www.ra.online-plus.biz&&&&&&I cried because I had no shoes - until I saw a man who had no feet.&&&&Dell Dimension 8100 - Intel P4 1.7 Gb - 512 RD Ram - nVidia GeForce 128 mb FX5200.
IP Logged
 
Reply #5 - Aug 20th, 2003 at 7:16am
RollerBall   Ex Member

 
Quote:
I have had alot of the 'You've just been approved' ones.


Chance is these were virus-containing. There would be no need to attach anything to a genuine email confirming approval for something you had genuinely applied for

Quote:
Can someone attach or somehow 'infect' my order form with something and then send it to me so that it will look like any other form that is returned to me? If so what can I do to guard against this?


They can't infect your form because the contents of that will be generated by your software using something like Sendmail or Blat. Also, as they don't know what the output of your form looks like, they can't easily create a copy. But in any case, you know that your form doesn't have an attachment, so you'd be alerted anyway. So don't worry too much!

Quote:
Is there any penalty if one of the morons happens to be caught. Does anyone know of a case where a 'Virus spreader' has been caught?.....What happened?


The so-called Love Bug perpetrator was located at enormous effort in the Phillipines I think. He was a computer student and did receive a prison term I'm glad to say.

In view of the cost of his little effort to the World commercial and IT system I think he should have got 30 years as a deterrent to others, frankly, but it was a lot less than that.

PS

Just noticed the pic. If you need further info, send Teryl over for an in-depth one-2-one discussion about viruses, the Internet and the World Wide Web Wink

 
IP Logged
 
Reply #6 - Aug 20th, 2003 at 7:24am

deadnight   Offline
Colonel
Georgia, USA

Gender: male
Posts: 166
*****
 
I had a virus yesterday, it first succeded in disableing my norton, then it somehow took over my hotmail email. Probably through msn messenger. It was automatically sending out virused emails at random to people. I kept on getting returned emails about every 3 minutes saying the email couldn't be sent because hotmail virus scanner detected a virus on it. Hopefully none of them got through their virus scanner. It took me about 7 hours to clean the virus. Everytime I got Norton up and running it was disabled again. Then it said I had to re-install it. Gave me quite a headache.
 

ASUS P4C800 Deluxe &&Geforce FX5900 Ultra(256 MB)&&1 gig DDR PC3200 RAM&&Pentium 4, 3.0 GHZ, 800 mhz FSB&&Coolermaster 550 watt power supply&&----------------------------&&<-3dmark03 =
6535
->
IP Logged
 
Reply #7 - Aug 20th, 2003 at 7:34am

Romulus111VADT   Offline
Colonel

Gender: male
Posts: 5521
*****
 
I got hit with 23 to date. They should take these A$$holes out and shoot them live via the internet. Start off with the legs and work your way around...make them suffer for all the misery they've caused and the fact you need a full 2 gigs of darn hard drive just to hold the programs to protect your system from their warped sense of reality. Angry
 

"I have a place where dreams are born, And time is never planned. It’s not on any chart, You must find it with your heart."

Albert Einstein - "Two things are infinite: the universe and human stupidity; and I'm not sure about the universe."

Martin Luther King Jr. - “Nothing in the world is more dangerous than a sincere ignorance and conscientious stupidity.”

Johann Wolfgang von Goethe - “There is nothing worse than aggressive stupidity.”

Mark Twain - “Never argue with stupid people, they will drag you down to their level and then beat you with experience.”
IP Logged
 
Reply #8 - Aug 20th, 2003 at 7:37am

Craig.   Offline
Colonel
Birmingham

Gender: male
Posts: 18590
*****
 
well the only good news on this is it expires in two weeks or sept 10th
 
IP Logged
 
Reply #9 - Aug 20th, 2003 at 8:12am

Scottler   Offline
Colonel
Albany, New York USA

Gender: male
Posts: 5989
*****
 
I logged in this morning to find 115 emails, all seeming to be from FS related sites.  Some of the bigger ones were:

FSInflight.com
FSNavigator
Simflight

There may or may not have been a Simviation, I didn't keep them long enough to make a mental list.  lol

Many said "You're Approved", some others said "Your details" or "My Details".

Seems odd that they'd all be FS related...
 

Great edit, Bob.&&&&&&Google it. &&&&www.google.com
IP Logged
 
Reply #10 - Aug 20th, 2003 at 8:46am

Biggles   Offline
Colonel

Gender: male
Posts: 404
*****
 
Today I was hit with about 150 of them for the first time. It took me ages just to get through all the virus reports from Norton.
Just wondering, does viewing the message actually do any harm or do you have to open the attachments???

One last question, can Firewalls protect your computer from this type of bombardment???  ???
Biggles
 
IP Logged
 
Reply #11 - Aug 20th, 2003 at 8:48am

Mr. Bones   Offline
Colonel

Posts: 4304
*****
 
thanks for letting us know...but i haven't had any of them...lucky me!  Wink
 

Raw power...the J-58.&&...&&&&My Anet collection.&&
IP Logged
 
Reply #12 - Aug 20th, 2003 at 9:10am

Professor Brensec   Offline
Colonel
Can't you give me a couple
more inches, Adam?
SYDNEY - AUSTRALIA

Gender: male
Posts: 2955
*****
 
I don't know anything about these things or the protection methods, but they have a firewall at the office I work at occasionally. They had the Internet 'offline' last week, because they said the firewall was down for some reason.

So the firewall apparently does give a degree of protection otherwise they wouldn't have taken the Internet offline.

Personally, I thought that if you had the most up to date Norton, you would be safe (the program would catch it and warn you) except for the most recent virus's that weren't included in the latest updates.
Is this a fair assumption?  Grin Grin Wink
 

...&&...&&http://www.ra.online-plus.biz&&&&&&I cried because I had no shoes - until I saw a man who had no feet.&&&&Dell Dimension 8100 - Intel P4 1.7 Gb - 512 RD Ram - nVidia GeForce 128 mb FX5200.
IP Logged
 
Reply #13 - Aug 20th, 2003 at 9:10am

Craig.   Offline
Colonel
Birmingham

Gender: male
Posts: 18590
*****
 
opening the email shouldnt do any harm but its best just to delete them to avoid any slight possibility of infection. the firewall cant stop this kind of thing if you open the attachment i believe.
whats really starting to annoy me is the fact i could be missing important emails because these things are filling up my inbox and bouncing back any legit emails to the sender due to a full inbox.
i seriously hope they catch the person who did this and hang him from a high beam by his testicles using fishing wire
 
IP Logged
 
Reply #14 - Aug 20th, 2003 at 9:11am

Scottler   Offline
Colonel
Albany, New York USA

Gender: male
Posts: 5989
*****
 
Apparently the problem goes beyond the FS world...

http://news.yahoo.com/fc?tmpl=fc&cid=34&in=tech&cat=computer_viruses_and_worms
 

Great edit, Bob.&&&&&&Google it. &&&&www.google.com
IP Logged
 
Pages: 1 2 3 4
Send Topic Print