(keitai-l) Re: w32.sobig

From: Jonas Petersson <zap_at_xms.se>
Date: 08/26/03
Message-ID: <3F4AF083.215DF25B@xms.se>
Greg Conquest wrote:
> [...] I found that the source of much of the extra 5
> MB were various messages all having a 100KB attachment. I was tempted t=
o
> look inside to see if it was SoBig, but I decided to leave it alone.

It sure sounds like it. For the record: I got about 10 more from the
very same IP (MANEESH client4.shecom.co.jp [218.44.132.46]) tonight.
With a decent mail reader you should be able to view the headers to find
the origin - the first "Received:" like is usually the givaway. =


And it should be perfectly safe to read the actual mail as long as you
don't click on the attachement (assuming your mail reader isn't brain
deadly "helpful").

> I'm glad I stopped Outlook
> Express from checking yahoo months ago (due to SPAM).

Even better, stop using Outlook Express: The "Express" part stands for
"get and spread virus quickly" and Outlook should be spelled "Look
Out!". It is broken by design and even Microsoft has admitted it now by
giving up support on it (sorry, I didn't save the link). Guess what one
of the headers in the SoBig mails I receive says? Yup:

X-Mailer: Microsoft Outlook Express 6.00.2600.0000

There is also this line: =


X-MailScanner: Found to be clean

		Right... / Jonas
-- =

Jonas Petersson  |  XMS Penvision  |  mailto:Jonas.Petersson@xms.se
Box 3294, V=E4stg=F6tegatan 13, S-600 03 Norrk=F6ping | http://www.xms.se=
/
Tel: +46 11 400 13 00 | Dir: +46 11 400 13 05 | Fax: +46 11 10 30 50
Received on Tue Aug 26 08:37:50 2003