RE: Win32.Sircam.Worm Alert.....

From: Aidan O'Kelly (okelly@xnet.ie)
Date: 07/25/01


Message-ID: <471ADE9820DCD411A46E00B0D079F2830AB34D@Xnetexch>
From: Aidan O'Kelly <okelly@xnet.ie>
To: vuln-dev@securityfocus.com, SECURITY-BASICS@securityfocus.com
Subject: RE: Win32.Sircam.Worm Alert.....
Date: Wed, 25 Jul 2001 11:11:34 +0100

This worm collects e-mail address's from the temporary internet files, thats
how it got all the postmaster@ and info@ address's. I got this virus the
other day from a reputable security company. :]

> Some of our corporate accounts have been pounded on by a
> particular user
> on verizon.net. None of those e-mail addresses are from someone's
> address book. They are all things like info@, webmaster@, postmaster@
> etc. so in our case, someone seems to be trying to propogate it
> deliberately.
>
> Tom
>
>

_________________________________________
Aidan O'Kelly
Systems Administrator okelly@xnet.ie

Xnet - The Data Storage People
Dublin: +353 (1) 2740 100
Belfast: +44(28) 9073 5872
www.xnet.ie | storage@xnet.ie

*******************************************************************
 Privileged/Confidential Information may be contained in this
 message. If you are not the addressee indicated in this message
 (or responsible for delivery of the message to such person), you
 may not copy or deliver this message to anyone. In such case,
 you should destroy this message and kindly notify the sender by
 reply email. Please advise immediately if you or your employer do
 not consent to Internet email for messages of this kind. Opinions,
 conclusions and other information in this message that do not relate
 to the official business of Xnet and shall be understood as
 neither given nor endorsed by it.
 ********************************************************************