|
 |
|
08-21-2003, 05:47 PM
|
#1
|
|
Registered User
Join Date: May 2002
Location: Warrington UK
Posts: 1,484
|
SoBig.F. Please read.
Who's been hammered by this today?
In the last 24hrs I've recieved over 130 mails infected by it, plus 26 bounces containing faked address's supposedly from me (my system and the server, and every other PC on my homenetwork is clean, Natted, and firewalled.
Most the messages have incomplete headers.
but a 5 of the bounces that included the full headers included the server name MARGI, and an AT&T owned IP address.
Address is 12.207.156.209
Looks to be part of a Dialup/Dynamic connection pool.
Any one recognise that IP, if you do, check your system very carefully.
I'm not pointing and blaming, just trying to help you sort things out, if it is you.
__________________
4x4 in a turbo stylee.
|
|
|
|
|
|
Advertisement
|
Sponsored links
|
08-21-2003, 06:40 PM
|
#2
|
|
Maximum Bitrate
Join Date: Dec 2000
Location: Smyrna, Ga, USA
Posts: 778
|
Well you know its the fastest spreading computer virus to date.
You just might get a couple of copies of it. Are you saying someone that reads this board has it - I wouldnt doubt it; Whats your point ?
Yes its a huge pain in the *** to hit delete. Sys admins across the nation have people screaming down there throats - and they have hundreds of client machienes to clean, in addition to a way over worked server trying to cope with all the traffic.
Just be glad the worm doesnt attack your file system and delete data.
|
|
|
08-21-2003, 07:16 PM
|
#3
|
|
Variable Bitrate
Join Date: Jul 2003
Location: Earth
Posts: 359
|
Quote: Originally Posted by gizmomkr
Well you know its the fastest spreading computer virus to date.
You just might get a couple of copies of it. Are you saying someone that reads this board has it - I wouldnt doubt it; Whats your point ?
Yes its a huge pain in the *** to hit delete. Sys admins across the nation have people screaming down there throats - and they have hundreds of client machienes to clean, in addition to a way over worked server trying to cope with all the traffic.
Just be glad the worm doesnt attack your file system and delete data.
Compare this to a network of 5000 machines being off line for 3 hours today and then consider yourself lucky......
Sobig.F and something else....Nachi bought are network to its knees
|
|
|
08-22-2003, 02:24 AM
|
#4
|
|
Registered User
Join Date: May 2002
Location: Warrington UK
Posts: 1,484
|
I know it isn't a problem to hit delete. But if someone has it, and doesn't know, (and it uses it's own SMTP engine so why would you other than the internet gets a bit slow if you are using it while it bulk mails silentley) wouldn't they want someone to tell them and fix it?
__________________
4x4 in a turbo stylee.
|
|
|
08-22-2003, 04:18 AM
|
#5
|
|
Variable Bitrate
Join Date: Jul 2003
Location: Earth
Posts: 359
|
The University network is sooooo pooooo if you sneeze it will fall.
|
|
|
08-22-2003, 06:38 AM
|
#6
|
|
Registered User
Join Date: May 2002
Location: Warrington UK
Posts: 1,484
|
Quote: Originally Posted by gizmomkr
Well you know its the fastest spreading computer virus to date.
You just might get a couple of copies of it. Are you saying someone that reads this board has it - I wouldnt doubt it; Whats your point ?
Yes its a huge pain in the *** to hit delete. Sys admins across the nation have people screaming down there throats - and they have hundreds of client machienes to clean, in addition to a way over worked server trying to cope with all the traffic.
Just be glad the worm doesnt attack your file system and delete data.
Thing is, I'm not infected.
But for my poor old Pentium pro mail and web server and NAT router, even the few hundred it has handled in the last couple of hours is tough for it.
It's all incoming, and bounce messages.
I must have had 10 from each address now, and just like mine in the bounces, they are probably fake (the real sender that is).
__________________
4x4 in a turbo stylee.
|
|
|
08-22-2003, 06:45 AM
|
#7
|
|
Super Moderator
Join Date: May 2002
Location: Albany, NY
Posts: 1,802
|
i keep graphs of cpu performance of our mailserver and when sobig hit there was a 700% jump in CPU usage. this is for a small company of 10 people mind you. I'd hate to be an admin of a big network.
__________________
'98 Explorer Sport
http://mp3car.zcentric.com (down atm)
AMD 800mhz 192megs RAM 60gig hard drive 9 inch widescreen VGA
80% done
|
|
|
08-22-2003, 09:04 AM
|
#8
|
|
Registered User
Join Date: Apr 2001
Location: Chicago Suburbs
Posts: 1,282
|
perhaps this is the reason i cant get onto hotmail today....
keeps claiming "Server too busy"
~mike
__________________
Single Member of the "1000 Post and No MP3 Car" Club
PROJECT ON INDEFINATE HOLD... BOUGHT A HOUSE
2000 Cavalier Z24 [###-------] Only 30% Done ... Still
|
|
|
|
Sponsored links
|
|
Advertisement
|
|
08-22-2003, 09:31 AM
|
#9
|
|
FLAC
Join Date: Jul 2003
Location: San Antonio, TX. USA
Posts: 1,375
|
We got pummeled by the spam that contains the "sobig" virus. It slowed down our mail server somewhat. I'm glad to say that out of 250 clients we only got three infected. I yell at our end users alot and sometimes they listen. This time they did. Interesting enough, the three that got infected were our gen mgr, a department supe and my desktop machine. I know I didn't click on the attachment so they must have infected by just opening the email.
Take Care
|
|
|
08-22-2003, 10:54 AM
|
#10
|
|
Super Moderator
Join Date: May 2002
Location: Albany, NY
Posts: 1,802
|
chut yes.. thats why you never use Outlook
__________________
'98 Explorer Sport
http://mp3car.zcentric.com (down atm)
AMD 800mhz 192megs RAM 60gig hard drive 9 inch widescreen VGA
80% done
|
|
|
08-22-2003, 11:59 AM
|
#11
|
|
FLAC
Join Date: Jul 2003
Location: San Antonio, TX. USA
Posts: 1,375
|
Actually, that's all we use. And getting people off of Express was a real pain in the ***.
Quote: Originally Posted by hijinks21
chut yes.. thats why you never use Outlook
|
|
|
08-22-2003, 12:07 PM
|
#12
|
|
Raw Wave
Join Date: Jun 2000
Location: Nashville
Posts: 2,635
|
okay, the way the SoBig-F variant works is this:
1. User opens attachment
2. SoBig accesses address book
3. Sobig picks a name at random from address book
4. SoBig emails everyone else in your address book and spoofs the random person's email.
If users got an email seemingly from you that had the virus, it wasnt you.
__________________
Debt as of 1/1/05: $34,354.48
Debt as of July 4, 2007: $0.00 explanation
Total spent on wedding so far: $3885.79
Thanks to everyone for your support.
I'M DEBT FREE!!
|
|
|
08-22-2003, 12:54 PM
|
#13
|
|
Super Moderator
Join Date: May 2002
Location: Albany, NY
Posts: 1,802
|
In outlook you don't even need to open the attachement. In un-patched versions they can just write some js code to auto exc the virus. Thats why I banned users from using outlook for the company i worked for.
__________________
'98 Explorer Sport
http://mp3car.zcentric.com (down atm)
AMD 800mhz 192megs RAM 60gig hard drive 9 inch widescreen VGA
80% done
|
|
|
08-22-2003, 01:00 PM
|
#14
|
|
Registered User
Join Date: May 2002
Location: Warrington UK
Posts: 1,484
|
OK. I don't know if I'm patched at Outlook/OS level.
But I have all the latest updates to F-Prot AV.
I'm not infected according to F-Prot.
My Mail server (on the same Lan) also uses F-Prot both as an OS Anti Virus, and as part of the Mailserver as an internal AV extension.
My machine scans fine. the mailserver machine scans fine.
The Mailer Daemon and its AV subsystem is picking up bucket loads of SoBig attachments and rendering them harmless/deleting them. So I pretty much have to be clean. You would hope.
__________________
4x4 in a turbo stylee.
|
|
|
08-22-2003, 01:14 PM
|
#15
|
|
Super Moderator
Join Date: May 2002
Location: Albany, NY
Posts: 1,802
|
Skraggy_uk, one would hope
__________________
'98 Explorer Sport
http://mp3car.zcentric.com (down atm)
AMD 800mhz 192megs RAM 60gig hard drive 9 inch widescreen VGA
80% done
|
|
|
|
Sponsored links
|
|
Advertisement
|
|
| Thread Tools |
|
|
| Display Modes |
Linear Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT -5. The time now is 01:06 PM.
| |