OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: .exe, and other attachments

From: Matthias Andree (madt.e-technik.uni-dortmund.de)
Date: Mon Sep 22 2003 - 04:56:37 CDT


Tony Earnshaw <tonnibilly.demon.nl> writes:

> Matthias Andree wrote:
>
>>>1: In the ongoing so-called "Swen/W32/gibe.f" (rubbish, there are at
>>>least 4 differently sized .exe executables involved) at least in the
>>>beginning a good deal of the drekk was coming from "innocent" home- and
>>>broadband users. Scaring them out of their wits with rejections is the
>>>only way to let each one know that something is wrong.
>> Is there any evidence that this worm (or set of worms) will actually
>> display delivery failures
>
> Yes. 'Received' trail, reject_non_fqdn_hostname,
> reject_unknown_sender_domain.

I thought the days of using real sender addresses were past... seems
you're lucky this time.

--
Matthias Andree

Encrypt your mail: my GnuPG key ID is 0x052E7D95