[Gllug] New worm doing the rounds?

Richard Jones rich at annexia.org
Mon Feb 9 14:24:11 UTC 2004

Attachments containing:

Content-id: <000000000000000>
Content-type: audio/x-wav; name=__warn.txt
Content-transfer-encoding: base64
Content-disposition: attachment; filename=__warn.txt

(followed by a few lines of base64 encoded data and about 17,000
blank lines).

Is this a new worm?  It seems different in size from previous Windoze

<rant mode="angry">

Don't you think these "anti-virus" vendors could stop sending me emails
like this:

 "We have detected [Windoze worm which is well-known to fake the From:
  header] in an email you sent to [email address I have never heard of]"

It really is just plain stupid.  If you know what the worm is, then
you know it fakes the From header, so don't send a bounce.



Richard Jones. http://www.annexia.org/ http://www.j-london.com/
Merjis Ltd. http://www.merjis.com/ - improving website return on investment
Learning Objective CAML for C, C++, Perl and Java programmers:
Gllug mailing list  -  Gllug at gllug.org.uk

