View Full Version : hey Larry
SlasherX
06-30-2002, 04:44 PM
I think while I was gone, someone tried to hack into my account. I got an email through teh clemson server that showed i was sent a virus(which Clemson scans all email for--computers fine) and also script from the webmaster of nc.org
If you want a copy, let me know. the person's return email address is:
krnprelude84@comcast.net
larryd
06-30-2002, 07:03 PM
nah, thats prolly the KLEZ worm.. its going around..
SlasherX
06-30-2002, 09:57 PM
Originally posted by larryd
nah, thats prolly the KLEZ worm.. its going around..
Then you have it..or whoever the webmaster is..
unless I'm reading the forward strings wrong..(possible)
larryd
06-30-2002, 10:09 PM
actually I did have it on my local machine.. but alot of people have it and dont know.. and its not necesarily the email address that comes to you, basically the worm copies entries of email addresses youve sent to or from in the past and sends from that address to other addresses..
SlasherX
06-30-2002, 10:32 PM
X-Time: <200206272050.g5RKoHM20380>
Return-Path: <krnprelude84@comcast.net>
Received: from smtp.comcast.net (smtp.comcast.net [24.153.64.2])
by CLEMSON.EDU (8.11.6/8.11.6) with ESMTP id g5RKoHM20380
for <spierd@clemson.edu>; Thu, 27 Jun 2002 16:50:17 -0400 (EDT)
Received: from Qvjmzolom (pcp397067pcs.parkvl01.md.comcast.net [68.34.8.248])
by mtaout01.icomcast.net
(iPlanet Messaging Server 5.1 HotFix 0.8 (built May 13 2002))
with SMTP id <0GYD00KCSTUDT9@mtaout01.icomcast.net> for spierd@clemson.edu;
Thu, 27 Jun 2002 16:49:34 -0400 (EDT)
Date: Thu, 27 Jun 2002 16:49:25 -0400 (EDT)
Date-warning: Date header was inserted by mtaout01.icomcast.net
From: webmaster <webmaster@newcelica.org>
Subject: Hi,spierd,please try again
To: spierd@CLEMSON.EDU
Message-id: <0GYD00KCTTUDT9@mtaout01.icomcast.net>
MIME-version: 1.0
Content-type: multipart/alternative;
boundary="Boundary_(ID_D8iWRlVTAEUAIVVTXgBoAA)"
This message used to contain a virus. Clemson's mail
server has replaced the virus with the text you are
now reading. The "fingerprint" of the removed virus
was: aAIAAID/FUzQQACFwA+FtwAAAFNWV7uLCUEAUFPo1CIAAFmJRfRZjYXw/v//aAQBAABQ/3X4
Fun stuff :)
Ok cool, my account is safe ;)
Thanks
vBulletin® v3.8.6, Copyright ©2000-2012, Jelsoft Enterprises Ltd.