Full Disclosure mailing list archives

RE: Fwd: Internet Security Update


From: digitz <digitz () shaw ca>
Date: Tue, 08 Apr 2003 13:59:39 -0600

My a/v picked it up as being W32.Gibe.B@mm

-----Original Message-----
From: full-disclosure-admin () lists netsys com
[mailto:full-disclosure-admin () lists netsys com] On Behalf Of Ward
Vandewege
Sent: Tuesday, April 08, 2003 1:16 PM
To: Brad Knowles
Cc: Full Disclosure Mailing List
Subject: Re: [Full-disclosure] Fwd: Internet Security Update

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

I got the same message on March 19. Don't know what sends it.

Below are the headers of the message I received.

Bye for now,
Ward.

- ----

Return-Path: <PWGcoastal () aol com>
Delivered-To: pong-be-ward () pong be
Received: from pong.be [193.74.16.33]
        by localhost with POP3 (fetchmail-5.9.11)
        for ward@localhost (single-drop); Thu, 20 Mar 2003 09:53:50
+0000 (GMT)
Received: (qmail 9955 invoked by uid 101); 19 Mar 2003 21:26:40 -0000
Return-Path: <PWGcoastal () aol com>
Received: from unknown (HELO ms-smtp-03.tampabay.rr.com) (65.32.1.41)
  by mail.pong.be with SMTP; 19 Mar 2003 21:26:16 -0000
Received: from LLHosAe (60.34.35.65.cfl.rr.com [65.35.34.60])
        by ms-smtp-03.tampabay.rr.com (8.12.5/8.12.5) with SMTP id
h2JL6msx000092;
        Wed, 19 Mar 2003 16:06:49 -0500 (EST)
Date: Wed, 19 Mar 2003 16:06:48 -0500 (EST)
Message-Id: <200303192106.h2JL6msx000092 () ms-smtp-03 tampabay rr com>
FROM: "MS Public Support" <nbljlh266960 () technet msn net>
TO: "Microsoft Customer" <>
SUBJECT: Network Security Update.
X-Virus-Scanned: NOD32
Mime-Version: 1.0
Content-Type: multipart/mixed; boundary="ypBSfERRmmoWSbeU"

- ----

On Tue, Apr 08, 2003 at 07:32:26PM +0200, Brad Knowles wrote:
Folks,

      I don't think this is a real Microsoft security announcement 
(they wouldn't be likely to be sent via an unknown IP address over in 
the space owned by hiwaay.net), but it does appear to be the result 
of a hoax, a virus, or a Trojan Horse that I have not yet heard of.

      I've done various searches via Google and on the web sites of
the 
anti-virus vendors, and haven't turned up anything on this issue. 
Have I missed something?


- -- 
Pong.be         -(       Writing software is more fun than working.
)-
Virtual hosting -(
)-
http://pong.be  -(
)-
GnuPG public key: http://gpg.dtype.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)

iD8DBQE+kx/cqC3O5tzmh5wRAoAeAKCeq3xpB4E7wLw8/35p1XVnPxb6mgCcDzHY
sJxbzgb0t2K3trF31h1b8T0=
=ScJO
-----END PGP SIGNATURE-----
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: