Possible Intrusion Attempt?

From: Matt LaFelero (ramstryke_at_yahoo.com)
Date: 05/22/03

  • Next message: Muhammad Naseer Bhatti: "ICMP/SYN Flood"
    Date: 21 May 2003 23:48:00 -0000
    To: incidents@securityfocus.com
    
    
    ('binary' encoding is not supported, stored as-is)

    I'm hoping someone here might be able to shed some light on this
    situation..

    Some of my users have been getting some interesting spam mail. This is
    the first time I've ever seen a spam mail do this. When the user opens
    the spam mail, all of a sudden, an Internet Explorer authentication
    boxes pops up. You know those that ask for username, password, and
    domain.

    Well, I run MS Proxy 2.0 here and the logon with a 2KPro machine is
    integrated so the user never sees this box or has to enter his/her
    password to get on the Web.

    It's strange that this email triggers the authentication box. What's
    even weirder is that it populates the username for them, with weird
    names. The names always seem to change from spam mail to spam mail. I've
    seen iterations like fluff, skank, morton, taxiway.. you name it.

    It seems most of the emails are HTML, which can explain a lot. None of
    them had attachments. From what I could gather it seems to attempting to
    load a site. We run Outlook 2000 with SP3 and all hotfixes.

    My question is, how is this happening and is it a threat?

    ----------------------------------------------------------------------------
    *** Wireless LAN Policies for Security & Management - NEW White Paper ***
    Just like wired networks, wireless LANs require network security policies
    that are enforced to protect WLANs from known vulnerabilities and threats.
    Learn to design, implement and enforce WLAN security policies to lockdown enterprise WLANs.

    To get your FREE white paper visit us at:
    http://www.securityfocus.com/AirDefense-incidents
    ----------------------------------------------------------------------------


  • Next message: Muhammad Naseer Bhatti: "ICMP/SYN Flood"

    Relevant Pages

    • RE: Possible Intrusion Attempt?
      ... This is the first time I've ever seen a spam mail do this. ... triggers the authentication box. ... that are enforced to protect WLANs from known vulnerabilities and threats. ... implement and enforce WLAN security policies to lockdown enterprise WLANs. ...
      (Incidents)
    • Re: Possible Intrusion Attempt?
      ... > Some of my users have been getting some interesting spam mail. ... Internet Explorer will offer its local authentication credentials ... implement and enforce WLAN security policies to lockdown enterprise WLANs. ...
      (Incidents)
    • Re: Possible Intrusion Attempt?
      ... authentication requests to remote sites, ... >Some of my users have been getting some interesting spam mail. ... wireless LANs require network security policies ... implement and enforce WLAN security policies to lockdown enterprise WLANs. ...
      (Incidents)
    • RE: A question for the list...
      ... >> evolution of the network ... implement and enforce WLAN security policies ... >> enterprise WLANs. ... implement and enforce WLAN security policies to ...
      (Incidents)
    • Re: [ANNOUNCE] protocol watcher
      ... attack, which is known to be a SYN attack! ... wireless LANs require network security policies ... > that are enforced to protect WLANs from known vulnerabilities and threats. ... implement and enforce WLAN security policies to lockdown enterprise WLANs. ...
      (Incidents)