comp.lang.ada
 help / color / mirror / Atom feed
From: Preben Randhol <randhol+abuse@pvv.org>
Subject: Re: Current "Swen" worm attack - the best address
Date: Fri, 26 Sep 2003 09:00:21 +0000 (UTC)
Date: 2003-09-26T09:00:21+00:00	[thread overview]
Message-ID: <slrnbn8014.m8.randhol+abuse@kiuk0152.chembio.ntnu.no> (raw)
In-Reply-To: e2e5731a.0309251916.181d1016@posting.google.com

On 2003-09-26, Alexander Kopilovitch <aek@vib.usr.pu.ru> wrote:
>
> Well, perhaps "highly" was overstatement -;) . But I still think that
> it is unlikely. My reason is that, although such a forgery is possible
> it requires extra effort (for which I don't see valid purpose), and
> adds unnecessary danger for the worm's creator(s). And even stronger
> reason (for me) is that it seems that in all messages I received
> within that stream (except 1), addresses at that place were quite
> good-looking, and single exception was simply
> rmailroutine@microsoft.com .

Huh? It is common that viruses take the e-mail addresses and forge mails
in these names as they get sent. The source is the machine the virus was
installed on so there isn't much danger for the worm creators from that.

> So what? I saw similar names at this place in perfectly valid
> messages.

Valid as in from cesa.air.defense.gouv.fr ? There is no site with that
name. The point is that 81.80.25.150 is probably the source, but I'm not
an expert on how the mails routes.

nslookup cesa.air.defense.gouv.fr

Non-authoritative answer:
*** Can't find cesa.air.defense.gouv.fr: No answer

> Anyway, this is not private person's address, and even not a company's
> address, so there will not be much damage (I hope that French Air
> Defense will be able to fight viruses more successfully than me -;) .

See above

Preben



  reply	other threads:[~2003-09-26  9:00 UTC|newest]

Thread overview: 16+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2003-09-24 22:31 Current "Swen" worm attack - the best address Alexander Kopilovitch
2003-09-25  8:19 ` Preben Randhol
2003-09-25 15:48   ` Wes Groleau
2003-09-25 20:52     ` [OT] Bad addresses (was: Current "Swen" worm attack - the best address) Henrik Motakef
2003-09-26  0:49       ` [OT] Bad addresses Wes Groleau
2003-09-25 16:43   ` Current "Swen" worm attack - the best address Alexander Kopilovitch
2003-09-25 19:38     ` Preben Randhol
2003-09-26  3:16       ` Alexander Kopilovitch
2003-09-26  9:00         ` Preben Randhol [this message]
2003-09-26 17:20           ` Alexander Kopilovitch
2003-09-26 23:21             ` Wes Groleau
2003-09-27 13:45               ` Alexander Kopilovitch
2003-09-28  2:30                 ` Wes Groleau
2003-09-28 17:52                   ` Alexander Kopilovitch
2003-09-28  2:32                 ` [off-topic] open letter to ISP admins--and virus program vendors Wes Groleau
2003-09-28  3:18                   ` Wes Groleau
replies disabled

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox