Re: Tracking SirCam

From: Gary Flynn (flynngn@jmu.edu)
Date: 07/25/01


Message-ID: <3B5F2C9D.2D0B0C9F@jmu.edu>
Date: Wed, 25 Jul 2001 16:31:25 -0400
From: Gary Flynn <flynngn@jmu.edu>
To: Peter Krawczyk <petek@mc.net>
Subject: Re: Tracking SirCam

Peter Krawczyk wrote:
>
> In the header of the message, everything looks dynamic, and so tracking it
> seems to be hard. However, there is a slip -- the Date: header actaully
> appears as 'date:'.

Sorry I haven't kept up with this one. This message seems to be saying
the virus engineers its own SMTP header.

Is the FROM: information correct?

-------------------------
Gary Flynn
Security Engineer - Technical Services
James Madison University

Please R.U.N.S.A.F.E.
http://www.jmu.edu/computing/info-security/engineering/runsafe.shtml

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • Re: Tracking SirCam
    ... Subject: Tracking SirCam ... there is a slip -- the Date: header actaully ... | case 'date:' for the header are sent by the SirCam virus. ... but one of these I've seen came through mail lists, ...
    (Incidents)
  • Re: track changes and header problem
    ... Don't turn on change tracking after updating the document - As soon as ... anything causes the header/footer to update, they'll register a change. ... > but the header still shows deleted text and the revised text (the header ...
    (microsoft.public.word.pagelayout)
  • Tracking SirCam
    ... Subject: Tracking SirCam ... Trying to track the SirCam virus without looking at the body of the ... In the header of the message, everything looks dynamic, and so tracking it ... Senior System Administrator ...
    (Incidents)
  • track changes and header problem
    ... a couple of suggestions on how to fix this, there were no clear answers and ... Running 2000 with tracking changes enabled. ... but the header still shows deleted text and the revised text (the header is ... send this out to a customer and am just trying to remove the last remnants ...
    (microsoft.public.word.pagelayout)