niXforums Forum Index
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   PreferencesPreferences   Log in to check your private messagesLog in to check your private messages   Log inLog in 
·  nixdoc.net ·  man pages ·  Linux HOWTOs ·  FreeBSD Tips ·  Forums
navigation Forum index » Apps » Qmail
[FYI] Virus from qmail@list.cr.yp.to (faked)
Post new topic   Reply to topic Page 1 of 1 [3 Posts] View previous topic :: View next topic
Author Message
Erwin Hoffmann
*nix forums addict


Joined: 24 Jan 2005
Posts: 71

PostPosted: Thu Jan 27, 2005 8:50 pm    Post subject: [FYI] Virus from qmail@list.cr.yp.to (faked) Reply with quote

Hi,

seems, that some guys use the a faked SMTP Return-Path address
"qmail@list.cr.yp.to" to spread virii.

Here's the first piece of the message:


Received: (qmail 24802 invoked from network); 27 Jan 2005 11:41:16 -0000
Received: from rasbtnlchn074.184.145.203.touchtelindia.net (HELO
gateway.com) (203.145.184.74)
by hamburg134 with SMTP; 27 Jan 2005 11:41:16 -0000
Date: Thu, 27 Jan 2005 17:15:10 -0800
To: "Feh" <feh@fehcom.de>
From: "Qmail" <qmail@list.cr.yp.to>
Subject: Delivery by mail
Message-ID: <ukkbecsopsvkenswhxc@fehcom.de>
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="--------shhqdgmwmkxslifehsla"

----------shhqdgmwmkxslifehsla
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: 7bit

<html><body>
Before use read the help

<br>
</body></html>

----------shhqdgmwmkxslifehsla
Content-Type: application/octet-stream; name="upd02.com"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="upd02.com"

TVoAAAEAAAACAAAA//8AAEAAAAAAAAAAQAAAAAAAAAC0TM0hAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAQAAAAFBFAABMAQUAAAAAAAAAAAAAAAAA4AAPAQsBAAAAOgAAAEoAAAAAAAAAoAAA
ABAAAABQAAAAAEAAABAAAAACAAAEAAAAAAAAAAQAAAAAAAAAnPMAAAACAAAAAAAAAgAAAAAA

Clamscan (0.72) doesn't detect it !

SPAMCONTROL users should add:


badmimetpyes: TVoAAAEAA

badloadertypes: MyLkR


The badmimetypes should also work for Russel's patch.


Users of qmvc are safe (by design) if they use the badmimetype and/or
badloadertype mechanism.

regards.
--eh.



Dr. Erwin Hoffmann | FEHCom | http://www.fehcom.de/
Wiener Weg 8, 50858 Cologne | T: +49 221 484 4923 | F: ...24
Back to top
Jason Frisvold
*nix forums beginner


Joined: 27 Jan 2005
Posts: 44

PostPosted: Thu Jan 27, 2005 8:50 pm    Post subject: Re: [FYI] Virus from qmail@list.cr.yp.to (faked) Reply with quote

On Thu, 27 Jan 2005 21:50:04 +0000, Erwin Hoffmann <feh@fehcom.de> wrote:
Quote:
Clamscan (0.72) doesn't detect it !

0.72 is very old.. Have you tried 0.80?

Quote:
regards.
--eh.

Dr. Erwin Hoffmann | FEHCom | http://www.fehcom.de/
Wiener Weg 8, 50858 Cologne | T: +49 221 484 4923 | F: ...24



--
Jason 'XenoPhage' Frisvold
XenoPhage0@gmail.com
Back to top
Niek
*nix forums addict


Joined: 23 Jan 2005
Posts: 92

PostPosted: Thu Jan 27, 2005 8:50 pm    Post subject: Re: [FYI] Virus from qmail@list.cr.yp.to (faked) Reply with quote

On 1/27/2005 9:57 PM +0100, Jason Frisvold wrote:
Quote:
On Thu, 27 Jan 2005 21:50:04 +0000, Erwin Hoffmann <feh@fehcom.de> wrote:

Clamscan (0.72) doesn't detect it !


0.72 is very old.. Have you tried 0.80?
0.80 is very old, have you tried 0.81 (released 24h ago) Smile


@Erwin: Worms gather email addresses (which are used for the From: and
To: field) from the infected machine.

Niek
--
Use plain text: http://www.geoapps.com/nomime.shtml
Learn to quote: http://www.netmeister.org/news/learn2quote2.html
Avoid disclaimers: http://www.goldmark.org/jeff/stupid-disclaimers
Back to top
Google

Back to top
Display posts from previous:   
Post new topic   Reply to topic Page 1 of 1 [3 Posts] View previous topic :: View next topic
The time now is Sat Jan 10, 2009 4:53 am | All times are GMT
navigation Forum index » Apps » Qmail
Jump to:  

Similar Topics
Topic Author Forum Replies Last Post
No new posts Transfer qmail email account to postfix server tallman Postfix 0 Thu Jun 05, 2008 12:43 pm
No new posts List History Backup Gladiator IBM DB2 3 Fri Jul 21, 2006 8:21 am
No new posts Testing my Black List Marc Perkel Exim 6 Fri Jul 21, 2006 5:57 am
No new posts Your Opinion about how to set up a DNS list Marc Perkel Exim 0 Fri Jul 21, 2006 2:18 am
No new posts FAQ 4.41 How can I remove duplicate elements from a list ... PerlFAQ Server Perl 0 Fri Jul 21, 2006 1:03 am

Blair Coupons | Looking for Credit Cards? | Problem Mortgage | Credit Card Consolidation | Credit Cards
Copyright © 2004-2005 DeniX Solutions SRL
 
Other DeniX Solutions sites: Unix/Linux blog |  electronics forum |  medicine forum |  science forum | 
Privacy Policy


Powered by phpBB © 2001, 2005 phpBB Group
[ Time: 0.1309s ][ Queries: 16 (0.0491s) ][ GZIP on - Debug on ]