[thelist] Spoofing and My Doom..... example

Seth Bienek houcfug.list at sethbienek.com
Fri Jan 30 15:07:18 CST 2004


Some email clients (outlook express... Cough) automatically add people whom
you email to your contacts.

The way the virus works is that it picks someone from your contacts as a
"from" address to spoof, and someone else from your contacts as a recipient.

I'm not sure if it picks a different "from" address to spoof for each email
it sends or if it uses the same address for all recipients.

This would explain how someone could receive the virus from an email address
that is never used for sending mail.

Take Care,

Seth

-----Original Message-----
From: thelist-bounces at lists.evolt.org
[mailto:thelist-bounces at lists.evolt.org] On Behalf Of John C Bullas
Sent: Friday, January 30, 2004 1:52 PM
To: thelist at lists.evolt.org
Subject: Re: [thelist] Spoofing and My Doom..... example

At 19:42 30/01/2004, you wrote
>Are you saying then that the worm possibly harvests emails from either 
>the internet or from cached web pages?

I think since NO emails are ever sent out using this subdomain address and
it is in uncloaked form on the 3rd party page in question....

A RESOUNDING YES

FB


>--- John C Bullas <jcbullas at nildram.co.uk> wrote:
> > just as we were talking about spoofed outgoing addresses.......
> >
> > The email address below is one used for a car sale here:
> >
> > http://www.minimania.com/web/id/4389/ClassDetail.cfm
> >
> > on a well visited and spidered site :(
> >
> > this email address is NEVER used as an outgoing one AND the network 
> > and PC were turned off at the wall......
> >
> > FB



More information about the thelist mailing list