Re: Hijacked Zombie boxes

From: Ray McCormick ("Ray)
Date: 05/31/04


Date: Mon, 31 May 2004 14:53:59 +0100

Hi

I have received very many copies of Swen_A and have now taken the
steps recently advised by this group.
Henry's attitude is interesting, though does it take account of
bogus 'From' details?
Is it correct that the first-mentioned ISP in the File >
Properties > Details box is the correct ISP?
If this is so to whom at that ISP should reports be directed?

Ray

"Derek" <FredFlintstone@bedrock.com> wrote in message
news:#VLilvuREHA.3988@tk2msftngp13.phx.gbl...
> Henry,
> I tracked one of these persistent pests and tracked the ISP in
the message
> header (located in Singapore). When I complained, I was
informed that the
> message was not from one of their clients. I haven't received
further
> messages from this particular spammer but probably he/she just
opened a new
> account elsewhere.
> Derek Nicholson
>
> "henry baker" <holmes@sherlock.buz> wrote in message
> news:pan.2004.05.31.04.32.26.14000@sherlock.buz...
> > Many people here who have been infected by virms that take
control of
> > their boxes may not realize that they are the ones sending me
spam and
> > viruses because they have been electronically raped and their
computers
> > are being used by people in other countries to send
pornographic and other
> > spam, selling illegal drugs and other products and also
sending out
> > viruses and worms to other computers.
> > If your computer has been raped, your immediate concern is to
get it
> > offline and then fix it.
> > I deal in spam elimination and report the IP address of each
and every
> > computer that sends me spam and virii to their host IP
demanding that that
> > computer be taken off line immediately.
> > There is absolutely no excuse for gettting infected except
for stupidity
> > or worse, by buying a "million address" CD and hoping to get
rich by
> > spamming, or by illegally downloading copyrighted files from
a service
> > such as kaaza and others and getting zombified.
> > I will start publishing the IP addresses of infected
computers that are
> > currently spamming and attempting to contaminate other
computers.
> > If you see yours (assuming you even know what an IP address
is) you better
> > turn that box off.
> > Well over 60% of the spam and virus attacks are made by
"innocent" owners
> > of hijacked (raped ) boxes, most running XP.
> > Time for action is now. Update your security patches and be
sure you are
> > running a up-to-date AV program or expect to be reported to
your ISP
> > immediately. Many ISPs are already taking action about these
zombies and
> > it's about time.
> >
> >
>
>
>
>
>
>



Relevant Pages

  • Re: Why cant ISPs stop spam/virus ?!
    ... I don't doubt that a small load of well designed spam can pass through. ... You need to get a decent ISP. ... The method of distribution is now thousands of Windows computers, ... You cannot filter by place of origin. ...
    (comp.os.linux.misc)
  • Re: Hijacked Zombie boxes
    ... Henry Baker's tirade does not take into account address spoofing nor does he ... to contaminate other computers. ... when all he has is a dynamically assigned IP address; only the ISP has the ... spam, ...
    (microsoft.public.security.virus)
  • Re: Spam
    ... Accepting mail sent to "mail@" is bound to attract lots of spam, ... Some people hand out addresseds like: ... I don't by any means trust all my friends to make sure their computers are ... the ISP who host that (ie the company whose computer ...
    (comp.sys.acorn.misc)
  • RE: 192.168.x.x oddities
    ... Excluding my computers, broadcast addresses, and network addresses, the ... registered to my ISP, then is blocked thereafter. ... has no open ports to help identify it. ... I was also thinking of leaving the common 192.168.*.* range for other RFC ...
    (Security-Basics)
  • Hijacked Zombie boxes
    ... spam, selling illegal drugs and other products and also sending out ... viruses and worms to other computers. ... If your computer has been raped, your immediate concern is to get it ... of hijacked boxes, most running XP. ...
    (microsoft.public.security.virus)