OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: [Security-Discuss] Worrying message

From: Vincent Danen (vdanenmandriva.com)
Date: Wed Jan 09 2008 - 15:56:51 CST


* Anne Wilson <cannewilsongooglemail.com> [2008-01-09 20:58:53 +0000]:

>> Well, the "undisclosed-recipients" is a bit of a giveaway that it's not
>> a legite message. I only ever see that with spam. Was there actually
>> anything in the message contents? If I got this, it ended up in
>> /dev/null due to spam filtering.
>>
>It had an empty body. It ended in my Unsure folder, probably because some of
>the headers mention mandriva.

Hmmm.. ok

>> >... that or Vincent did a boo boo (*gasp*)
>>
>> Me? Hardly! =)
>>
>> I have root on a few machines, but I doubt that would come from any of
>> the ones I deal with (although without seeing the full headers it's
>> tough to determine). I can't imagine ever sending a message as root to
>> anything other than specific maintenance-related email addresses via
>> cronjobs.
>>
>Cronjobs are what I was reminded of, and it made it seem unlikely.

Yeah, but a cronjob has never been sent to "undisclosed-recipients".

Sounds like nothing to worry about to me.

--
Vincent Danen http://linsec.ca/

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.8 (Darwin)

iEYEARECAAYFAkeFQyMACgkQLrxeMv7jCtSCowCdFScdYLLfNRJqlJHJ8+gVypL8
r7wAni3endwydw9zB96RHOcmze0ycwEB
=lMrB
-----END PGP SIGNATURE-----