Security Incidents mailing list archives

Re: lifestages on IRC


From: rune () TRANS4MEDIA COM (Rune Kristian Viken)
Date: Mon, 10 Jul 2000 09:36:31 +0200


On Sun, 09 Jul 2000, you wrote:

      Is it possible to spoof the ip address given by the irc client to
the IRC server ? Actually, i'm new to IRC and don't know anything about
this.  This "offer" of file happened twice , so i've started using irc on
linux only. Also What can i do to track the guy who was doing me this
"favor" ?

The guy was infected.  It happened when you joined a channel.  If you're new to
IRC - which you obviously are - you'll probably be quite confused by all the
exe's, shs's, ini's, com's, bat's, and so forth that is floating around.  The
people that send them are INFECTED.

Also, life-stages is a *Very* nasty worm.  It has *specifically* targetted us
that run certain anti-virus/worm channels on IRC - it makes the client
autoignore us if he joins certain channels.  Also, the virus autoignored people
that write to the client about "infected" , "life-stages" , "remove", "virus" -
and lots of other trigger-words.

What you should do, is to write the guy that sent you the file a message -
worded VERY carefully so that you trigger the ignorefunction - and explain to
him that he is infected.

--
"Rune Kristian Viken" <rune () trans4media com> <http://arcade.kvinesdal.com>
System, Network & Security Administrator.  Phone: (+47) 92 85 34 38



Current thread: