Originally posted by DJ Jackalope
Announcement
Collapse
No announcement yet.
Sobig question
Collapse
X
-
-
If it was not for the "Dear Occupant" mail I'd feel totally unloved. :>
Leave a comment:
-
.sobig celebration
Hm.
Today is the first day I did not receive a single .sobig attachment.
*throws party*
Leave a comment:
-
Originally posted by guanoLooking over google, the only place where your (Blackwave) email address and mine appear on the same web page is the Defcon 11 slogan contest.
Although Mr. Florida has stopped, I'm betting the web logs for the slogan contest will show his IP address... :-)
Leave a comment:
-
Looking over google, the only place where your (Blackwave) email address and mine appear on the same web page is the Defcon 11 slogan contest.
Although Mr. Florida has stopped, I'm betting the web logs for the slogan contest will show his IP address... :-)
Leave a comment:
-
semantics on Symantec ;)
Originally posted by guano
Sorry Blackwave -- not exactly true. Sobig-F also scans files on the computer looking for anything that might be an email address. This includes web cache. Thus, if someone visited defcon.org and then got infected, all those email addresses at defcon.org would be sent the virus. (I'm 90% certain that's how Mr. Florida got both you and me.) You don't need to be in their address book or inbox.
Leave a comment:
-
Originally posted by blackwave
regarding SoBig.F as long as someone doesn't have your email addy during their infected state you should be in fine shape, especially if you don't windows yourself. I have yet to get an infection myself, just more these annoyances that are beyond my control with a few of my public email addresses... alas.
Leave a comment:
-
Originally posted by Siviak
ya know.. something just occered to me.. with all my years of using Windows (for wich I have suffered more than my fair share of shit) and AOL (don't even get me started with all of THAT) I have yet to contract a virus..... way to go Uber Hackers.. no leave me alone ;)
btw for the ppl that pm'd me about the countdown...
here are a couple of links...
http://www.wininformant.com/Articles...rticleID=39943
http://searchsecurity.techtarget.com...920957,00.html
Leave a comment:
-
Originally posted by Siviak
ya know.. something just occered to me.. with all my years of using Windows (for wich I have suffered more than my fair share of shit) and AOL (don't even get me started with all of THAT) I have yet to contract a virus..... way to go Uber Hackers.. no leave me alone ;)
Leave a comment:
-
ya know.. something just occered to me.. with all my years of using Windows (for wich I have suffered more than my fair share of shit) and AOL (don't even get me started with all of THAT) I have yet to contract a virus..... way to go Uber Hackers.. no leave me alone ;)
Leave a comment:
-
Option #3 None of the above.
It appears to be a Lovelorn variant. Now why my scanners still aren't picking it up, I have no idea.
Leave a comment:
-
Originally posted by octalpussy
No, I'm not sure. I don't know what it is, because none of my virus scanners are picking it up. The e-mails it is sending out have subjects of "help" and something about "baby $2000 USD play this game".
You should:
1. nmap against your system. Look for all ports below 10000.
2. Look for "new" services. In particular, open proxies, web servers, IRC servers, and remote control software (current fad: DameWare).
Option #1: The port scan will find a set of open ports. Either 1180-1185, 2280-2285, or 3380-3385. That's SoBig-A, B-D, and D-E (D changed ports near the end).
Option #2: You've probably had your system compromised. There are a couple of spam groups that are compromising systems, installing rootkits, and then sending spam. (I cleaned three such systems in the last two weeks, and I've identified a few dozen more.) The rough topics you've listed match one of these groups.
If this is the case, drop me a PM with your email and we'll take this conversation off-line. (If this is the case, then I really want a copy of some of the emails, as well as the IRC connections logs, DameWare logs, etc... Yes, they leave logging enabled!)
Having said that... If this is the case, you should:
1. Copy off all of your personal data.
2. Reinstall from scratch.
Leave a comment:
-
Originally posted by blackwave
of course it can send to all the recipients of your palm's address book. Surely you aren't the only one with the emails of your palm's address book recipients...
stop it. you know what i mean!
Leave a comment:
-
Originally posted by KeLviN
i am well aware.... but you should all feel happyh knowing that the thing has no way of sending to all the recipiants of my palms address book.
Leave a comment:
-
Originally posted by blackwave
d00d.. it isn't about what os or client you are running... it is about being on a list... once you are on that list the all the shit starts to come to you... regardless of what you are running...
Leave a comment:
Leave a comment: