Homeland Security infected with SoBig.F email virus
LeftHander
(1000+ posts)
Send PM |
Profile |
Ignore
|
Thu Aug-21-03 08:32 AM
Original message |
Homeland Security infected with SoBig.F email virus |
|
Edited on Thu Aug-21-03 08:46 AM by LeftHander
I got a bounced email from someone in US Customs. This was a result of the recent SO BIG.f Microsoft e-mail virus. Apparently the virus executed from someones machine internal network ip (65.246.158.29) and the e-mail was sent by the Homeland Security email server mx2.mail.dhs.gov to a person in US Customs
What happens is when the e-mail virus executes it gathers all the e-mail addresses it can find on the infected machine and then e-mails it self to all the addresses spoofing the FROM: line with an address it finds. (Spoofing is the use of a e-mail address in the From line other than the actual sendee's) Well MY work address was picked up off of someones machine at dhs.gov.
So what is homeland security doing with my email address?
If homeland security is supposed to keep us safe how secure can they be if a stupid Microsoft e-mail virus can easily infect them?
What about other viruses that randomly send files from the infected harddrive?
Wouldn't this put national security at risk??
|
JackSwift
(1000+ posts)
Send PM |
Profile |
Ignore
|
Thu Aug-21-03 08:52 AM
Response to Original message |
1. Homeland Security has your email |
|
and street address as preparation for picking you up and sending you to a death camp because you are a liberal.
|
LeftHander
(1000+ posts)
Send PM |
Profile |
Ignore
|
Thu Aug-21-03 10:35 AM
Response to Reply #1 |
12. I was wondering about that black helicopter |
|
....over my house the other day....
and the white van in the street from time to time....and the sedan with blackwall tires with two dudes in suits and sunglasses following me to work...
hehehe
|
sybylla
(1000+ posts)
Send PM |
Profile |
Ignore
|
Thu Aug-21-03 09:07 AM
Response to Original message |
|
If the sender is spoofed, how do you find out who sent it?
|
Kellanved
(1000+ posts)
Send PM |
Profile |
Ignore
|
Thu Aug-21-03 09:10 AM
Response to Reply #2 |
3. The IP (your computer's address in the net) isn't so easily spoofed |
|
Edited on Thu Aug-21-03 09:10 AM by Kellanved
It's still possible (Spammers do it using Proxies), but it is complicated to do so automatically.
|
sybylla
(1000+ posts)
Send PM |
Profile |
Ignore
|
Thu Aug-21-03 09:21 AM
Response to Reply #3 |
4. Yea, but how do I look at the 50 or so I received and know |
|
what the ip address of the sender was?
|
TahitiNut
(1000+ posts)
Send PM |
Profile |
Ignore
|
Thu Aug-21-03 09:23 AM
Response to Reply #4 |
5. http://www.spamcop.net/ |
Kellanved
(1000+ posts)
Send PM |
Profile |
Ignore
|
Thu Aug-21-03 09:26 AM
Response to Reply #4 |
7. a decent mail client will tell you |
|
It's all in the header (hidden by Outlook).
|
sybylla
(1000+ posts)
Send PM |
Profile |
Ignore
|
Thu Aug-21-03 09:46 AM
Response to Reply #7 |
8. Ah, your clue helped me out. |
|
Edited on Thu Aug-21-03 09:51 AM by sybylla
I use Netscape and just had to change the header view to All.
Thanks :toast:
The first 10 or so seem to come from the same two servers. Interesting.
edited for spelling and to say that I find it interesting that every one of the viral e-mails I got came from Users of Outlook Express.
|
htuttle
(1000+ posts)
Send PM |
Profile |
Ignore
|
Thu Aug-21-03 10:07 AM
Response to Reply #8 |
9. I don't think the virus would affect any other email programs |
|
Edited on Thu Aug-21-03 10:08 AM by htuttle
Just Outlook and Exchange on Windows.
Maybe the people of the world should sue Microsoft in a massive class action suit for phucking up our internet... Their laxity and sloth have cost the rest of us a whole lot of money over the last few years with this crap.
|
havocmom
(1000+ posts)
Send PM |
Profile |
Ignore
|
Thu Aug-21-03 10:33 AM
Response to Reply #9 |
11. have had a couple on infected emails on the Eurdora program |
|
but Norton has killed them thus far.
|
HootieMcBoob
(1000+ posts)
Send PM |
Profile |
Ignore
|
Thu Aug-21-03 09:24 AM
Response to Original message |
6. I've been getting tons of those things |
|
I have a mac so I don't think I'm vulnerable but tons of bounced mail from all over and weird re:that movie and other kinds of things with bizarre attachments. My partner's whole workplace was basically shut down because an intern opened an attachment that they got.
|
havocmom
(1000+ posts)
Send PM |
Profile |
Ignore
|
Thu Aug-21-03 10:31 AM
Response to Original message |
10. Havocdad's office computer (works for US government) got the worm |
|
and it sent out all sorts of emails to addresses he didn't have in his address book. The state office for his dept has had virus problems and they figure it came from them.
The previous worm got the main server at the state office level. They sent faxes to all the field offices advising everyone to stay off the web and not use their email programs. When the state office got their system cleaned up, they sent emails advising everyone they could go ahead and use the web and email again. Then they called to find out why the field offices weren't responding to the email.
It is that level of competance which makes Havocdad not worry about government programs to monitor everything everybody does. He figures their communication is so abominable that it really is not much of a threat. Wish I could share his view.
So far, Norton has managed to fend it off on the home PC.
|
DU
AdBot (1000+ posts) |
Fri Dec 27th 2024, 06:12 AM
Response to Original message |
Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators
Important Notices: By participating on this discussion
board, visitors agree to abide by the rules outlined on our Rules
page. Messages posted on the Democratic Underground Discussion Forums are the
opinions of the individuals who post them, and do not necessarily represent
the opinions of Democratic Underground, LLC.