OT: Is eveyone absolutley sick of the Sobig-f worm

Christ today alone, I've had copies sent to me, and 8 bounces or quarentine messages where I'm supposed to have sent it (faked mail address).

My system at home at home and work is completley safe, and my mailserver scans and cleans attachments before delivery, but it is getting really annoying.

Reply to
MeatballTurbo
Loading thread data ...

I'm getting a few people reporting it supposedly coming from me only a has bothered to include a copy of the header and it shows it's not coming from me. (Actually the account it's reported as coming from is incoming only and can't send)

Reply to
Depresion

oops make that 12 copies sent to me.

Although now since I posted that it is at 15 and rising.

Reply to
MeatballTurbo

Yeah, I'm getting bugger all in the way of headers too, but the mails are now upto 18, and 10 more as bounces.

Reply to
MeatballTurbo

However it can look at the e-mail address you put in the account properties and use that. It contains its own SMTP server so sends itself.

Reply to
Conor

Finally got some headers on a bounce. MARGI ain't my mail server.

Looks like AT&T have that entire netblock too.

Return-path: Received: from [12.207.156.209] (helo=MARGI) by gaia.hmdns.net with esmtp (Exim 4.20) id 19pqhU-0003iR-IG for snipped-for-privacy@theFUNplace.com; Thu, 21 Aug 2003 10:46:09 -0400 From: To: Subject: Your details Date: Thu, 21 Aug 2003 9:48:41 --0500 X-MailScanner: Found to be clean Importance: Normal X-Mailer: Microsoft Outlook Express 6.00.2600.0000 X-MSMail-Priority: Normal X-Priority: 3 (Normal) MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="_NextPart_000_0052D447" Message-Id:

Phew, looks like I'm still clean then, and it has just picked up my email address from somewhere. Maybe even here.

Reply to
MeatballTurbo

carl the worst thing you can do is post your email address in newsgroups, bots are scanning all day long and your inbox will soon be swamped with s**te from tailand and japan,

Ronny

Reply to
Ron

That must cost a fortune... ;)

Reply to
Dan405

There's also RebootR unlike Blaster it's designed to shut down your PC Blaster is just badly written and causes the RPC server to go belly up, windows then thinks it had better restart to be safe.

Reply to
Depresion

In article , snipped-for-privacy@bouncing-czechs.com spouted forth into uk.rec.cars.modifications...

It seems, all the bounces that have headers, indicate an IP address in the IP block owned by AT&T, and the mail engine identifies itself as MARGI. The address is 12.207.156.209

It looks like that AT&T have certain IP rules in place regarding that part of the block, as a traceroute to it dies a few hops before it gets there. Looks like it is part of a dynamic range used for dialup customers.

Reply to
MeatballTurbo

In article , snipped-for-privacy@blank.com spouted forth into uk.rec.cars.modifications...

Yep. I can go with that. BP6 with Dual Celeries 466x 475 and 525, 256meg ram, and a 32meg GF2. Will run XP with out any bother. Sometimes progs are a little slow starting, but once running, no ill effects.

Single Duron 750, with 256 meg ram, and a 32 meg TNT2, no bother.

My BP6 is soon going to be retired from daily active service to be replaced by the KT133 Ultra and a Duron 1.3 with 512meg DDR that is currentely in the CarPC.

The BP6 will be going into the Old Cube case I made to run Mandrake, and The CarPC is getting an Epia M10000 Nehmiah, to bring it's size down.

Reply to
MeatballTurbo

So far I've had over 200 copies or bounces of sobig, all seem to originate from the same IP (208.148.124.254). This is according to NeoTrace terminates somewhere in Seattle, USA. It's getting rather boring now, particularly as the work pc has no facility to preview before downloading emails so I've got to sort and delete them by hand. I use Mailwasher on my own pc and it's brilliant for anti-spam and cutting out viruses. Any that is misses then have to go through Norton AV 2003.

DavidCN

Reply to
DavidCN

Amazing the people who press their tongues firmly into Bill Gates' bum cleft really will let Microsoft get away with anything rather than have a word said against the company.

Reply to
Steve Firth

Server not MS, desktop systems not MS.

What's a virus?

Reply to
Steve Firth

In article , %steve% @malloc.co.uk spouted forth into uk.rec.cars.modifications...

There are Unix Virii, but they run on the honour system. After recieving the email, you have to promise to follow the instructions within, delete important system files, and then forward the mail to the 10 most important people in you pine address book.

Reply to
MeatballTurbo

Agreed.

Microsoft Windows suits my needs just fine, and I couldn't give a flying f*ck what Microsoft get upto. If I didn't like Windows, then I'd change - it's not like there is a shortage of operating systems !

Reply to
Nom

Servers MS, desktop systems MS.

What's a virus?

They're a complete non issue as long as you keep everything upto date.

Reply to
Nom

MotorsForum website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.