Author Topic: Be Careful Of Mail From Ripsnort  (Read 557 times)

Offline Gremlin

  • Silver Member
  • ****
  • Posts: 1909
      • http://www.webtreatz.com/tod/lognew.html
Be Careful Of Mail From Ripsnort
« on: August 24, 2002, 01:19:20 PM »
Guys,

Got a mail from Ripsnort with title 'gremlin, congratulations!'  It contains I-Worm-Elkern virus, which proceeded to run riot through my system, totally screwing up my BoB frame 1. If you get this mail DO NOT EVEN PREVIEW IT.

I had turned off my virus scanner because I didnt want any other proggies runnin during BoB.  That'll teach me.  This virus infecteds .exe (executable) programs rapidly.  You have been Warned.

Just want to be very clear, this infection WAS NOT Ripsnorts fault, rip is a victim of this virus, just as I am.


« Last Edit: August 26, 2002, 11:22:32 AM by Gremlin »

Offline Innominate

  • Gold Member
  • *****
  • Posts: 2702
Be Careful Of Mail From Ripsnort
« Reply #1 on: August 24, 2002, 01:26:54 PM »
Eudora is a nice email client.

Outlook is a security hole.

Offline Swoop

  • Plutonium Member
  • *******
  • Posts: 9180
Be Careful Of Mail From Ripsnort
« Reply #2 on: August 24, 2002, 01:34:33 PM »
Grem,

when you say "from Ripsnort", what email addy was it from exactly?  I know Rip uses about 4.


Offline -ammo-

  • Platinum Member
  • ******
  • Posts: 5124
Be Careful Of Mail From Ripsnort
« Reply #3 on: August 24, 2002, 02:33:34 PM »
Rip--

Pls take my email addy out of your address book:D
Commanding Officer, 56 Fighter Group
Retired USAF - 1988 - 2011

Offline Chairboy

  • Probation
  • Plutonium Member
  • *******
  • Posts: 8221
      • hallert.net
Get Norton
« Reply #4 on: August 24, 2002, 02:47:41 PM »
Norton Antivirus is good to have.  If you insist on using Outlook and exposing yourself unnecessarily to all these security vulnerabilities, the least you can do is get good AV (like Norton).
"When fascism comes to America it will be wrapped in the flag and carrying a cross." - Sinclair Lewis

Offline Saintaw

  • Platinum Member
  • ******
  • Posts: 6692
      • My blog
Be Careful Of Mail From Ripsnort
« Reply #5 on: August 24, 2002, 02:58:57 PM »
pft, I always knew that "Ripsnort" guy was dodgy, sheesh!
Saw
Dirty, nasty furriner.

Offline 10Bears

  • Silver Member
  • ****
  • Posts: 1509
Be Careful Of Mail From Ripsnort
« Reply #6 on: August 24, 2002, 04:23:18 PM »
It's that damn klem virus again..

If you can put anything you want to attach on your own server space then send a link that's the better way.

I won't open attachments from anyone. This virus goes through your addr book and sends it from somebody you know. I'm sure Rip didn't do it intentionaly.

TOD and BOB CO's take note. Put all the maps and stuff on your own server space.

Offline Chairboy

  • Probation
  • Plutonium Member
  • *******
  • Posts: 8221
      • hallert.net
Be Careful Of Mail From Ripsnort
« Reply #7 on: August 24, 2002, 05:32:40 PM »
It is most definately his fault for not using AntiVirus software in this day and age.  That he uses Outlook makes it that much more egregious.
"When fascism comes to America it will be wrapped in the flag and carrying a cross." - Sinclair Lewis

Offline Gremlin

  • Silver Member
  • ****
  • Posts: 1909
      • http://www.webtreatz.com/tod/lognew.html
Be Careful Of Mail From Ripsnort
« Reply #8 on: August 26, 2002, 04:26:26 AM »
I do have a really good virus scanner, AVG from grisoft it really is good and its free, BUT.  Because I didnt want any other software running during the BoB frames I disabled it as I was not expecting to make any other internet connection other than to HTC server. Then I am told that there are some additional orders in the email!  Ok I'll just have a quick shifty at those, big mistake.  The rest is history.  I spoke to rip last night and he seems to feel that its possible that this virus came from someone else who has rip in their address book.  However I wonder if a virus could send mail from a users account without the password for that account.

Just to be clear, I was never ever suggesting that rip did anything un-to-ward, just want to be clear on that.

Chairboy, yes it was stupid of me to lower my guard like that.  However, who can stand up honestly and say they have never done something like that too??  You were just lucky you got away with it.

Swoop:  I daren't preview that mail again to find out.  However I will be rebuilding that image sometime this week (the virus completely thrashed it).  When I am building it I will check out which mail addy it was.  (In case your wondering swoop, our little piece of co-op work;) is ok.)  This thing seems to only infect .exes .dlls .scr etc.

Offline Gremlin

  • Silver Member
  • ****
  • Posts: 1909
      • http://www.webtreatz.com/tod/lognew.html
Be Careful Of Mail From Ripsnort
« Reply #9 on: August 26, 2002, 04:27:37 AM »
Quote
Originally posted by Chairboy
It is most definately his fault for not using AntiVirus software in this day and age.  That he uses Outlook makes it that much more egregious.


How do you know I use outlook????

Offline Innominate

  • Gold Member
  • *****
  • Posts: 2702
Be Careful Of Mail From Ripsnort
« Reply #10 on: August 26, 2002, 04:36:49 AM »
Quote
Originally posted by Gremlin


How do you know I use outlook????

 I spoke to rip last night and he seems to feel that its possible that this virus came from someone else who has rip in their address book. However I wonder if a virus could send mail from a users account without the password for that account.


These worms are usually outlook specific.  Running executables attached to an email is stupid.  Outlook lets some files do things to disguise thier true nature.  Try eudora.

You don't need an account to SEND mail, only to receive.  Trusting a from address is not a good idea.  The only way to verify it came from the person who it claims to be from is to reply to them and ask, and have them reply to you again with your message.  Because of the way email works, an SMTP(mail sending) server simply believes what it's told.

Checking email headers is a good idea for such emails.  You can tell where the message originated, and if it came from an isp other than the one the message claims to be from, you know something is fishy.  Also, any email sent from AOL will get an "X-Apparently-From:" header showing the senders REAL aol email.

Offline sveno

  • Nickel Member
  • ***
  • Posts: 512
lucky me...
« Reply #11 on: August 26, 2002, 07:20:48 AM »
... running "The Bat!" here - handsdown the best ever emailclient :) wonder if someone knows that one here...

outlook / office with broadband without firewall / antivirus on win98 / XP = big ouch

Orgasmic Interception.
Current status of M.I.L.F: On standby - awaiting aircraft.

Offline Turbot

  • Silver Member
  • ****
  • Posts: 1122
Be Careful Of Mail From Ripsnort
« Reply #12 on: August 26, 2002, 10:50:17 AM »
Run your Windows Updates.  I also recommend ZoneAlarm (the Pro version - not the free one.)

Offline Gremlin

  • Silver Member
  • ****
  • Posts: 1909
      • http://www.webtreatz.com/tod/lognew.html
Be Careful Of Mail From Ripsnort
« Reply #13 on: August 26, 2002, 10:53:08 AM »
Turbot,  I got the free one, what does the pro one do the free one doesnt??

Thx

Offline Turbot

  • Silver Member
  • ****
  • Posts: 1122
Be Careful Of Mail From Ripsnort
« Reply #14 on: August 26, 2002, 11:05:42 AM »
Quote
Originally posted by Gremlin
Turbot,  I got the free one, what does the pro one do the free one doesnt??

Thx


http://www.zonealarm.com/store/content/company/products/znalm/comparison.jsp