Go Back  PPRuNe Forums > Misc. Forums > Computer/Internet Issues & Troubleshooting
Reload this Page >

Dodgy e-mail attachments from Microsoft.com


Notices
Computer/Internet Issues & Troubleshooting Anyone with questions about the terribly complex world of computers or the internet should try here. NOT FOR REPORTING ISSUES WITH PPRuNe FORUMS! Please use the subforum "PPRuNe Problems or Queries."

Dodgy e-mail attachments from Microsoft.com

Old 20th May 2003 | 05:33
  #1 (permalink)  
BRL
Thread Starter
 
Joined: Oct 2000
Posts: 5,068
Likes: 0
From: Brighton. UK. (Via Liverpool).
Dodgy e-mail attachments from Microsoft.com

Hi all. I have just received an e-mail from [email protected] . It contains an attachment called screen_doc and is a ZLO file. It is 51 kb. Norton anti-virus didn't get it but my zone-alarm has quarantined it saying...

" A shortcut to MS-DOS Programme is a program that could cause damage to your computer files, violate your privacy, or infect others with a dangerous virus. "

I assume its a virus and if it is then how can Microsoft send this kind of thing? Anyone else had anything like this?
BRL is offline  
Old 20th May 2003 | 05:41
  #2 (permalink)  
20 Anniversary
 
Joined: Apr 2003
Aviation Qualifications: SLF
Posts: 739
Likes: 258
From: Midlands
It's not actually from Microsoft, and it is a virus. More details here:

http://news.bbc.co.uk/1/hi/technology/3040247.stm

jethro15

Last edited by PPRuNe Towers; 20th May 2003 at 18:01.
jethro15 is online now  
Old 20th May 2003 | 05:41
  #3 (permalink)  

'nough said
 
Joined: Sep 2002
Posts: 1,025
Likes: 0
From: Raynes Park
It wasn't sent by MS - just someone pretending to be them. See BBC news item . I don't know much more than that - Symantec (aka Norton) does not seem to have anything on it.
amanoffewwords is offline  
Old 20th May 2003 | 06:16
  #4 (permalink)  
BRL
Thread Starter
 
Joined: Oct 2000
Posts: 5,068
Likes: 0
From: Brighton. UK. (Via Liverpool).
Thanks chaps. Just what are these w****rs trying to prove....
BRL is offline  
Old 20th May 2003 | 14:48
  #5 (permalink)  
25 Anniversary
 
Joined: May 1999
Aviation Qualifications: ATP+Mil
Posts: 27,397
Likes: 857
From: Quite near 'An aerodrome somewhere in England'
I received one yesterday but without any attachment - just deleted it.

It really is time that ISPs were forced to do more about this sort of thing. Surely the offending source can be traced?
BEagle is online now  
Old 20th May 2003 | 15:36
  #6 (permalink)  
Per Ardua ad Astraeus
 
Joined: Mar 2000
Posts: 18,575
Likes: 4
From: UK
"Surely the offending source can be traced?"

I wish, Beags! I am getting quite a few now with incomplete return addresses whixh make bouncing with 'Mailwasher' impossible and tracing difficult. The 'Earthlink' ISP is coughing up a few right now. It becomes very time consuming sending to each ISP each time. We need robust legislation NOW!

'FL' where are you?
BOAC is offline  
Old 20th May 2003 | 17:15
  #7 (permalink)  
Evo
20 Anniversary
 
Joined: Sep 2002
Posts: 1,650
Likes: 0
From: Chichester, UK
The difficulty with legislation is that the spam/e-mail virus problem is global - the e-mail may be sent in China and come to you via a relay in Burkina Faso. You could say that it's the ISPs problem and they should block it, but should they really decide what e-mail you do or do not receive? What is their role? If they should scan it, should the post office censor your post? There's no quick-fix that I can see.
Evo is offline  
Old 20th May 2003 | 17:41
  #8 (permalink)  
Per Ardua ad Astraeus
 
Joined: Mar 2000
Posts: 18,575
Likes: 4
From: UK
Why cannot those emails that have 'incorrect' return addresses be hit? The 'earthlink' example I mentioned had a r/a 'xxx@earthlink' whereas the full address should be '[email protected]'.
BOAC is offline  
Old 20th May 2003 | 17:50
  #9 (permalink)  
Dop
Registered User
 
Joined: Oct 2002
Posts: 262
Likes: 0
From: Croydon (but really from Barnsley)
Big Red 'L' - I think they're trying to prove what L33T H4X0R5 they are and how many B0X3N they can 0WNZ to fuel their pathetic little egos as none of them will ever do anything good or worthwhile in their entire lives.

BEagle - The problem is that the virus sends out more copies of itself, so the odds are the person who sent it to you doesn't actually know they're doing it, because they ran the attachment when they got the mail from some other, possibly equally innocent, person. Tracing it back would be incredibly complicated. The person who started it off probably used an anonymiser to cover his tracks (and it almost certainly was a him - some pale spotty geek who needs to get out more).

BT Openworld now do virus checking on all mail passing through, and this has caught a lot of viruses before they've ever got to me. They also do spam checking too, although a lot still gets through. If all ISPs did virus checking, in close support from anti-virus companies, and blocked any viruses passing through them, it would do a lot to curb the spread of these email viruses.
Dop is offline  
Old 20th May 2003 | 23:19
  #10 (permalink)  
BRL
Thread Starter
 
Joined: Oct 2000
Posts: 5,068
Likes: 0
From: Brighton. UK. (Via Liverpool).
How did he get away with sending an e-mail with the address of [email protected] ? Is there a programme that does that kind of thing?

This new virus has been traced to Holland so says the report. If thats the case, why can't they trace the isp and find out who it is?

Dop I agree. As these people are annonymous then who gives them the glory they crave doing things like this? Its like graffitti artists. No-one knows who they are and they change thier tags a lot so who are they trying to impress Beats me to see what the point is at the end of the day really when no one can praise you for what you have done.

As for Btopenworld blocking them, mine came through the BTinternet address that I have.
BRL is offline  
Old 20th May 2003 | 23:28
  #11 (permalink)  
 
Joined: Jun 2000
Posts: 1,003
Likes: 0
From: Geriatrica, UK
And me too. Deleted before opening even though checking the Header confirmed that the sender's apparent address was [email protected]. Then I came here and found all you other folks in the same boat. So we are getting smarter about this - at least in this slice of the population.

But it came to my personal e-mail address that is not published here. But then I do get a lot of Spam there anyway. The spam coming to my fobotcso address is consistent; 6-10 a day of delete before reading stuff.

BTOpenworld's anti-spam only stops about ½ the stuff coming to my personal account. It lets through e-mails with the most bizarre titles and senders' names. Often composed of random characters that have no meaning. Still, at least its better than nothing.

{Edit} The e-mail system is in its infancy so we must hope for a fix one day but what? If we all had to pay one penny for every e-mail address we e-mailed to it wouldn't break the bank and it would turn off all the broadcast spammers who send 500-1000 at a time. I have no idea how you would implement this in China, however!
fobotcso is offline  
Old 21st May 2003 | 02:28
  #12 (permalink)  
25 Anniversary
 
Joined: Jul 2000
Posts: 1,535
Likes: 13
From: UK
Have to say I can't recommend Mailwasher enough. It checks the messages on your server and shows you the content without downloading to your computer. You can then delete from your mailbox or bounce it back as if you don't exist. Either way, I found this same message, toyed briefly with the idea of downloading it in OE but then used MW to delete it - looks like I chose wisely (for a change).

See http://www.mailwasher.net

You can make a message look like it's come from someone else by changing your own email address under the tools menu
Background Noise is offline  
Old 21st May 2003 | 04:12
  #13 (permalink)  

Plastic PPRuNer
25 Anniversary
 
Joined: Sep 2000
Posts: 1,902
Likes: 0
From: Rochechouart, France
Grr.... Been toying with the idea of MailWasher for a while. Been running at a rate of 40:1 Spam to Genuine for the last couple of months - someone must have finally got me on one of those "Buy a million e-mail addresses!" lists. Been drivin' me crazy.

Thanks BN, you just pushed me into downloading and registering MW. Seems to work a treat too. Hopefully if I keep bouncing the deluge will lessen somewhat eventually. F%^&$heads!
Mac the Knife is offline  
Old 21st May 2003 | 05:45
  #14 (permalink)  
25 Anniversary
 
Joined: Jul 2000
Posts: 1,535
Likes: 13
From: UK
Think symantec (norton) might know about this (?) a search of their site comes up with this (which refers to palyh in the alternative names):

http://[email protected]
Background Noise is offline  
Old 21st May 2003 | 06:23
  #15 (permalink)  
Dop
Registered User
 
Joined: Oct 2002
Posts: 262
Likes: 0
From: Croydon (but really from Barnsley)
Big Red 'L' - Do you have the virus/spam checking turned on? It's not enabled by default, and really the virus checking at least should be. The spam checking end could be a lot better, and while you can check your spam folders through webmail, there isn't a 'whitelist' option to always allow through certain mails, like mailing lists you're on. But the virus checker does seem to work with known viruses - although any virus checker is only as good as the virus database it runs off, so new viruses would spread until a check is found.

The 'From' address on an email is largely immaterial. You can set it to anything, so I could easily send out mails that would appear to be from '[email protected]' - unless you looked at the header and traced the origin of the message, you wouldn't know.

What I think one of the major problems with the internet as a whole is that when most of the fundamental protocols (TCP/IP, mail, news, etc) were originally developed, nobody gave any thought to security. It was just one big happy family and nobody would ever think to send fraudlent emails or viruses, ever... So very basic protocols have been fraught with security problems for years.

If Email had been designed from day one so that you could not send emails with forged addresses, a lot of this stuff would never happen.
Dop is offline  
Old 21st May 2003 | 08:51
  #16 (permalink)  
 
Joined: Dec 2000
Posts: 28
Likes: 0
From: Enzed
CAA New Zealand received a mass post of the virus today from [email protected] - caught at the door by the MIS boys - well done.
Kotare is offline  
Old 21st May 2003 | 09:43
  #17 (permalink)  
 
Joined: Feb 2003
Posts: 180
Likes: 0
From: somewhere
I also have BTOpenworld - and got this virus delivered to me twice

One icon for those people who write these things ---> , well actually 2

I wrote a very nasty email as a reply - but it was returned to sender.... hmm
Andrew M is offline  
Old 21st May 2003 | 14:03
  #18 (permalink)  
Per Ardua ad Astraeus
 
Joined: Mar 2000
Posts: 18,575
Likes: 4
From: UK
DOP - the point I was making about the incomplete return address was taken FROM the email header! It missed the '.net' from the end of the address, thereby stopping Mailwasher from bouncing it.

Full agreement on the comments above for MW - there you CAN set up approved and blocked senders.
BOAC is offline  
Old 21st May 2003 | 15:27
  #19 (permalink)  
Evo
20 Anniversary
 
Joined: Sep 2002
Posts: 1,650
Likes: 0
From: Chichester, UK
If Email had been designed from day one so that you could not send emails with forged addresses, a lot of this stuff would never happen.
A little bit of history

E-mail as we know it (name @ destination) and the network-of-networks idea that became the internet date back to the early seventies. Simple Mail Transfer Protocol (SMTP) and the sendmail program (still very widely used) date back to 1981. ARPANET switched to TCP/IP, the protocol that the internet still uses, in 1982. Back then the idea of spam, e-mail nasties, DoS attacks and forged addresses were inconceiveable - the infant internet was a tightly-knit collection of (mainly American) official networks. Why should they have thought of designing a secure forgery-resistant e-mail protocol? Or SYN-attack resistant IP? Every extra byte cost a lot of computing and network power. E-mail and the internet itself was designed to be as simple as they could get away with.

The problem is that there is a huge amount of inertia in the system - so much so that 20 years later we're still using essentially the same software and protocols, and they're no longer good enough. However, fundamental changes are very hard to make - suddenly networks become isolated from each other due to different protocols and we are temporarily back in the 70s. People have been trying to get IPv6 adopted for years,
and that's a fairly trivial change designed mainly to open up a larger number of IP addresses - the current IPv4 system doesn't really have enough to go around. Developing and rolling out a globally-secure digitally-signed e-mail protocol is a much harder problem to solve.

Solutions? There isn't an easy one. Best bet may be to build a whole new system from the ground up and roll it out in some way. Backwards compatibility is probably the wrong idea, but it makes the migration of millions of non-technical users to "Internet v2.0" a huge problem. Make it backwards compatible and you leave the prospect of all the old holes. It's a problem for someone smarter than me
Evo is offline  
Old 22nd May 2003 | 04:15
  #20 (permalink)  
20 Anniversary
 
Joined: Mar 2002
Posts: 448
Likes: 0
From: London, UK
20/20 hindsight is a wonderful thing. Evo explained the background very succinctly, but to expand a little... it's just a tad disingenuous to suggest that "they" should of thought of security at the time. It was difficult enough just getting all those different brands of computers and operating systems to talk to each other in the first place, let alone devising ways to stop them... This is a little difficult to imagine if you've been brought up in a world that only knows of Pee Cees running Micro$oft...

Solutions? There isn't an easy one. Best bet may be to build a whole new system from the ground up and roll it out in some way. Backwards compatibility is probably the wrong idea, but it makes the migration of millions of non-technical users to "Internet v2.0" a huge problem. Make it backwards compatible and you leave the prospect of all the old holes. It's a problem for someone smarter than me
Call me cynical, but I wouldn't be at all suprised to discover that Bill hasn't secretly embedding the "Micro$oft Secure Mail Application" inside Windoze products for years. One day, he'll announce that he has the "answer" to spam, switches it on, and everybody (who uses Micro$oft) is "protected." Oh, forgot to mention that if you don't use Micro$oft, you won't be able to read any email from the MSMA using any non-M$ mail client. And you have to trust M$ to be the final arbiter of what constitutes spam then... Of coure, I'm probably being excessivley cynical...
RomeoTangoFoxtrotMike is offline  

Thread Tools
Search this Thread

Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service

Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Use of this site indicates your consent to the Terms of Use.