[vox] New virus?

Bill Kendrick vox@lists.lugod.org
Tue, 19 Aug 2003 15:28:10 -0700


On Tue, Aug 19, 2003 at 03:12:54PM -0700, Mark K. Kim wrote:
> I'm sure I didn't send it for many many awfully many reasons (one being
> the X-Mailer).

Back when Klez first appeared, I created this page to send to people:

  "You Didn't Get a Virus from /ME!/"
  http://www.newbreedsoftware.com/bill/virus/

    "...What has most likely occured is that someone else's computer sent you
    a virus, and the virus was nice enough to randomly pick my e-mail address
    to show as the sender. ..."


> But all that aside, my biggest concern right now is that I
> got this e-mail on my e-mail account that's never been spammed before and
> the one I guard with my life.  Oh man...

Well, realize it goes something like this:

There are three people involved.  Mark, Mark's friend (we'll call him/her
"Pat") who is the original victim, and the intended new victim
(we'll call him/her "Vick").

  1. Pat's computer get's infected

  2. The virus on Pat's computer randomly picks [roll of the dice]
     Mark as the 'From' address and Vick as the 'To' address

  3. The virus sends the e-mail to Vick.

  4. Vick, or Vick's mail server decides it's a spam or virus, and
     contacts Mark (automatically or manually) to complain.
     "Hey Mark!  Stop sending Vick viruses!"


So at this point, even though you only gave Pat your e-mail address,
and you might not know Vick at all, now Vick or Vick's mail server
knows it, too, and thinks it's sending spam. :^)

D'oh!


-bill!
(_carefully_ typing this into PuTTY on a Windows2000 box... *whimper*)

-- 
bill@newbreedsoftware.com                    Was I useful?  Rate this message!
http://newbreedsoftware.com/bill  http://svcs.affero.net/rm.php?r=billkendrick