This is topic Bounced Mail I Never Sent in forum Film-Yak at Film-Tech Forum ARCHIVE.
To visit this topic, use this URL:
https://ft-forum.com/ft/cgi-bin/ubb/ultimatebb.cgi?ubb=get_topic;f=8;t=002448
Posted by Steve Kraus (Member # 476) on 09-07-2003, 09:14 PM:
I've been getting occasional bounce messages from messages I never sent, either for bad addresses but also ones that were rejected for nefarious attachments. This is on an address I closely guard and almost never gets spam (if I get 2 in a month it's a lot). Anyone else having this problem? I don't think I have a virus sending out mail I don't know about (and there is no sign it actually originated with me). FWIW I do not use Outlook and the messages either came from it or are made to look like they did. Recipients are not anyone I know.
Posted by Sam Hunter (Member # 1119) on 09-07-2003, 09:18 PM:
Its the sobig virus on other folks computers. Your computer did not send them. Sobig obtained your address from someone elses address book and used it as the sending address in its attempt to infect more PC's.
Posted by Kenneth Wuepper (Member # 1174) on 09-07-2003, 09:25 PM:
I have experienced this same problem. There are letters which are proported to come from my computer. They are to people who are not on my mail list. The common thread is an attachment "To Class" which I have never opened.
My sister in law is at a university and they had a virus in their system. I believe that this may have been the source of my funny e-mails.
Posted by Joe Redifer (Member # 3) on 09-07-2003, 09:54 PM:
I have also been seeing this. Sometimes they have a PIF attachment. The addresses they were attempted to be sent to always seem to be foriegn, with ".dk" in the address somewhere.
I may get a few bad looks from people who consider themselves pro-life (not my intention to offend), but people who write viruses, worms, perform identity theft, etc sure make a strong argument for abortion, as I wish they would have been. If only we could've known in advance.
Posted by Steve Kraus (Member # 476) on 09-07-2003, 10:19 PM:
That which you didn't abort you can always execute.
Posted by Joe Redifer (Member # 3) on 09-07-2003, 10:58 PM:
Fair enough.
Posted by Richard C. Wolfe (Member # 431) on 09-07-2003, 11:54 PM:
I have received quite a few of these recently. I did read a few of them and found the same as the rest of you that they had not been sent by me. I refused to open any attachments or downloads, and now won't even bother to read them. I just delete them.
Posted by Ken Layton (Member # 133) on 09-08-2003, 12:48 AM:
I've been getting them too. Every one of them gets the "delete" treatment!
Posted by Leo Enticknap (Member # 534) on 09-08-2003, 01:23 AM:
Steve: I think the source of your bounced messages is as follows: Computer A is infected with SoBig, which disguises its origin by taking e-mail addresses at random from its Outlook address book and putting them in the 'from' field. Your name is in that address book, ergo a SoBig message is sent by Computer A to Computer B looking like it came from you. Either Computer B's ISP has a built-in virus filter which recognises the virus and bounces the message back to the address in the 'from' field (i.e. yours), or Computer B's owner uses a utility such as Mailwasher to manually bounce it themself.
The bottom line here is that if you do use a mail previewing and bouncing program, bounce spams only, not viruses. If you bounce a virus which has forged the 'from' field to disguise its origin, you'll only confuse the situation and suggest to an innocent third party that his/her computer is infected.
Posted by Jack Ondracek (Member # 1466) on 09-08-2003, 02:08 AM:
It's been a couple of days since I've received any of these... but I got a lot of them before that. All said that I had sent messages that were found to be "clean". The originating IPs were all screwy and there were no attachments.
Sure is getting to be interesting, being on this party line!
Posted by Sam Hunter (Member # 1119) on 09-08-2003, 09:08 AM:
As I said, it's the SOBIG virus causing that and you shouldn't open such emails. The virus is on the other folks computers and you would be well advised to install/run a decent virus scan to check yours for it as well.
Posted by Jack Ondracek (Member # 1466) on 09-08-2003, 01:50 PM:
quote:
...it's the SOBIG virus causing that and you shouldn't open such emails.
Nahhhhh.... I just send them on to Ken!
Posted by Sam Hunter (Member # 1119) on 09-08-2003, 02:24 PM:
I remember getting that on my company email system and I use Eudora as my home email client. I freaked out because I was thinking why didn't my Virus scan catch that? I couldn't find where I had sent any emails in my sent items box and all that. I did however find that even though my Virus scanner said it was updated I did a manual update check and found a new version upon once downloaded and ran found many instances of the bug in my PC. This was in the late evening when I had found this and my Virus scan had just updated that morning. What a pisser.
Anyway, can't wait for the next round of bugs
Posted by Don Bruechert (Member # 1538) on 09-08-2003, 04:26 PM:
Nice thing about running your own mailserver is that I have a set of scripts that deletes this crap before it ever gets into my mailbox. So far I had only been using it for me, but today I installed it for someone else who has a mail account on my server that had 600 of these little bastages in her mailbox this morning (that's 50MB of viruses!). She bitched after spending 2 hours trying to delete them all, and I mass deleted about 400 of them off the server which took me about 2 hours. Then they were coming in so fast this afternoon that I couldn't keep up with them, so I installed the toy and they are no more...
us boys and our toys... anyone running unix/linux with procmail and postfix or sendmail can check out www.spambouncer.org (this does not work for end users).
Posted by Bobby Henderson (Member # 840) on 09-08-2003, 05:05 PM:
E-mail address spoofing is nothing new. Lots of viruses have done it in the past. Also, beware of incoming messages disguised to look like they have bounced back or other messages made to look like they're from your ISP or Microsoft. I always laugh at the one titled "Microsoft Security Patch".
There should be a death camp for virus writers.
Powered by Infopop Corporation
UBB.classicTM
6.3.1.2