Tilted Forum Project Discussion Community  

Go Back   Tilted Forum Project Discussion Community > Interests > Tilted Technology


 
 
LinkBack Thread Tools
Old 08-20-2003, 12:10 AM   #1 (permalink)
Psycho
 
steveincolumbus's Avatar
 
Location: BFE, Kentucky
Sobig.F worm

So anyone else's inbox being overrun by mails that have the subject of the folowing:

Re: Details
Re: Approved
Re: Re: My details
Re: Thank you!
Re: That movie
Re: Wicked screensaver
Re: Your application
Thank you!
Your details

Looks like a new work out as of tuesday the 19th that is basicly spaming its way out.......
This one is pissing me off, b/c i get on average one email a minute from this, the corp. a/v stops the viris but i get notifications of it...... I guess time to go hit the rules for hte spam filter and see if I cam block this crap........

If you want more details on it here is a link to Symantecs site.....

http://securityresponse.symantec.com...obig.f@mm.html
steveincolumbus is offline  
Old 08-20-2003, 08:28 AM   #2 (permalink)
Stereophonic
 
brandon11983's Avatar
 
Location: Chitown!!
yeah. I've been getting tons of shit in my box from that too. Someone has way too much time on their hands.
__________________
Well behaved women rarely make history.
brandon11983 is offline  
Old 08-20-2003, 09:47 AM   #3 (permalink)
Psycho
 
Location: Anywhere but here
Yup...I get close to 30 a day in my work inbox. Luck for me we have good anit viri software to kill it as it comes in.
__________________
What the fuck is "wtf"?
mute76 is offline  
Old 08-20-2003, 11:30 AM   #4 (permalink)
Dopefish
 
wraithhibn's Avatar
 
Location: the 'Ville
I dont know if I have it or not, cause I'm not getting any of those emails, but my inbox is filling up with return to sender emails of Sobig.F coming from my hotmail account. I guess someone that has me in their address book has it, cause I ran 3 different AV's and symantec's sobig.F fix.
__________________
If you won't dress like the Victoria Secret girls, don't expect us to act like soap opera guys.
wraithhibn is offline  
Old 08-20-2003, 11:41 AM   #5 (permalink)
Crazy
 
Location: Upstate NY
what it will do is get all the email addresses it can find, ones on websites, in your address book what not. It will then spam those account and also use those accounts as spoofed email accounts so it looks like they came from you when they didn't. Look at the headers and look for the orginiating IP and contact that user to let them know, if you know that person.
__________________
I am jack's broken heart
silenced is offline  
Old 08-20-2003, 11:41 AM   #6 (permalink)
Pro Libertate
 
Location: City Gecko
This one is annoying but a breeze if your AV is utd.

However the amount of helldesk calls I've seen today is laffable, "I didn't send these mails, I want you to track where they came from, and I will inform HR" is a notable quote from today.

Needless to say (but I will) we politely ignored them, and eventually got the helldesk to not process those calls.

PS: I think it spoofs email addresses, but no expert, cause loads of my clients are getting the same symptoms(SP) as wraith
__________________
[color=bright blue]W[/color]e Stick To Glass

"If three of us travel together, I shall find two teachers."
Confucious

Mad_Gecko is offline  
Old 08-20-2003, 08:17 PM   #7 (permalink)
Crazy
 
Location: Salt Lake City
SoDamnAnnoying!
I got some 250 copies of the virus yesterday alone in my tech support inbox. Somebody must have our tech support email on their address list, and that somebody must not have a clue what virus protection is.
__________________
---<>---^^---<>---^^---<>---
---^^---<>---^^---<>---^^---
---<>---^^---<>---^^---><---
GreasyP is offline  
Old 08-20-2003, 10:00 PM   #8 (permalink)
Riiiiight........
 
help!!
my mailbox has been FLOODED with this today. came on to see if anyone has a solution to this....
and for some reason, it all seems to be coming from one IP address.

Received: from ACNT-SPARE (168-215-59-34.gen.twtelecom.net [168.215.59.34])

how do i reach this guy and tell him to turn off his comp??!!
dimbulb is offline  
Old 08-21-2003, 04:26 AM   #9 (permalink)
Crazy
 
Location: Right where I want to be.
Sobig has it's own SMTP engine so you can shut down the mailserver, you can only watch it email itself till you remove it.

Take the machine off the network now!
irieemon is offline  
Old 08-21-2003, 07:03 AM   #10 (permalink)
Fear the bunny
 
Location: Hanging off the tip of the Right Wing
My ISP has filtered out all of this, and I haven't received anything at all. Mediacom rules!
__________________
Activism is a way for useless people to feel important.
BoCo is offline  
Old 08-21-2003, 08:48 AM   #11 (permalink)
The GrandDaddy of them all!
 
The_Dude's Avatar
 
Location: Austin, TX
same here. havent received any of those.
__________________
"Luck is what happens when preparation meets opportunity." - Darrel K Royal
The_Dude is offline  
Old 08-21-2003, 06:17 PM   #12 (permalink)
fik
Crazy
 
Location: Tacoma, WA
600 new viruses in the past 20 hours for me.
It seems to have slowed down actually.

But that is nothin compared to someone I know that is getting 1000 per hour.
fik is offline  
Old 08-21-2003, 06:22 PM   #13 (permalink)
I demand a better future
 
HeAtHeN's Avatar
 
Location: Great White North
Its a virus fest the last coupla days. I just got the new AVG 7... its kicking virus butt for me.
__________________
Quote:
Isn't it enough to see that a garden is beautiful without having to believe that there are fairies at the bottom of it too?
Douglas Adams
HeAtHeN is offline  
 

Tags
sobigf, worm


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -8. The time now is 08:18 AM.

Tilted Forum Project

Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0 PL2
© 2002-2012 Tilted Forum Project

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360