4916
<<
Message Index
>>
4918
Number: 4917
From: tasmaniac1
Date: Mon Apr 12, 2004 6:19 pm
Subject: [ASC McLaren ] Re: I WOULD NOT OPEN HOT SINGLE
Body:
[ASC McLaren ] Re: I WOULD NOT OPEN HOT SINGLE
|
|
Hi Marq,
Appreciate your input and not flaming me as yes I am learning
something new here. I just don't understand how someone can use
someone elses info unless it was trojan based especially when an
outsider would have no clue as to the members email addresses inside
of a group unless they are a member themselves and the other members
allow their email addresses to be seen. As far as new addresses
coming on as I mentioned we gotta fight back by deleting them before
they cause harm to someones computer. Is the owner still frequently
visiting this site? If not how many active moderators does he have
to prevent this from happening? Maybe he can recruit someone like
you or someone else who may have the time to prevent these people
from attacking our systems or unnecessary spam.
-Nick
--- In ascmclaren@yahoogroups.com, "SNP Marq" <infosyssec@i...>
wrote:
> Spoofing e-mail addresses is no magical trick... viruses do it
everyday to spread themselves. In fact we have seen that happen
here where innocent members found their e-mail address used by
viruses to post to this group....
>
> It is just as simple to manually spoof a person's e-mail and there
are a slew of hacker programs available just for that purpose.
>
> The spammers have programs that have automated the flooding of
forum web sites, ALT news groups and groups such as the ones hosted
via Yahoo. They also do similar stunts against Microsoft IM's and
other types of IM's.
>
> But possibly you are not familiar with my background and what I do
for a living. Here is a hint : My handle here is InfoSysSec -
which is the acronym for Information System Security - which is
short for CISSP - which is Certified Information System Security
Professional ;)
>
> On the topic of spoofing e-mails, whether by virus/trojans or by
the use of programs designed for that task... the
> messages look like they came from you, but they did not. This is
called
> email spoofing. The insecure nature of email easily enables anyone
to
> assume anyone else's email identity. Not to worry, however. If
your
> Purdue anti-virus software has not complained about a virus on
your
> computer, and you have not opened an email attachment, chances are
good
> that your computer is not infected and you can tell people "it
wasn't me
> who sent you that email message, it was someone pretending to be
me in a
> parallel universe". Or something like that. J
>
> An overview of email spoofing from CERT:
> http://www.cert.org/tech_tips/email_spoofing.html
>
>
> News articles explaining more about email spoofing:
> http://reviews.cnet.com/4520-3513_7-5128949-1.html
> http://antivirus.about.com/library/weekly/aa042502a.htm
>
>
> But you are right that it is a pain when 'someone' or 'some
automated spamming program' can simply register and immediately gain
the ability to bomb a group with SPAM. And yes, the user account
should be nuked for now... but that is no guarantee they won't be
back using the same to take advantage of the openess of the posting
of messages here using yet another expendable e-mail address.
>
> Marq