Server Help

Trash Talk - Miney

Anonymous - Fri Apr 30, 2004 1:20 pm
Post subject: Miney
WTF??

Code: Show/Hide

Return-path: <>
Received: from mxin4.netvision.net.il ([194.90.9.34]) by msg2s.netvision.net.il
(iPlanet Messaging Server 5.2 HotFix 1.14 (built Mar 18 2003))
with ESMTP id <0HWW00HEW8ILEB@msg2s.netvision.net.il>; Wed,
28 Apr 2004 21:25:33 +0300 (IDT)
Received: from server2a.woolnet.net ([64.91.230.181]) by mxin4.netvision.net.il
(iPlanet Messaging Server 5.2 HotFix 1.21 (built Sep  8 2003))
with ESMTP id <0HWW00C168IJXV@mxin4.netvision.net.il> for
ori_kl@netvision.net.il (ORCPT ori_kl@netvision.net.il); Wed,
28 Apr 2004 21:25:33 +0300 (IDT)
Received: from mailnull by server2a.woolnet.net with local (Exim 4.24)
   id 1BItkQ-0006RO-SH   for ori_kl@netvision.net.il; Wed,
28 Apr 2004 14:25:30 -0400
Date: Wed, 28 Apr 2004 14:25:30 -0400
From: Mail Delivery System <Mailer-Daemon@server2a.woolnet.net>
Subject: Mail delivery failed: returning message to sender
To: ori_kl@netvision.net.il
Message-id: <E1BItkQ-0006RO-SH@server2a.woolnet.net>
Auto-submitted: auto-generated
Content-transfer-encoding: 7BIT
X-Failed-Recipients: mgb@minegoboom.com
X-AntiAbuse: This header was added to track abuse,
please include it with any abuse report
X-AntiAbuse: Primary Hostname - server2a.woolnet.net
X-AntiAbuse: Original Domain - netvision.net.il
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain -

This message was created automatically by mail delivery software.

A message that you sent could not be delivered to one or more of its
recipients. This is a permanent error. The following address(es) failed:

  mgb@minegoboom.com
    This message has been rejected because it has
    a potentially executable attachment "Info.com"
    This form of attachment has been used by
    recent viruses or other malware.
    If you meant to send this file then please
    package it up as a zip file and resend it.

------ This is a copy of the message, including all the headers. ------

Return-path: <ori_kl@netvision.net.il>
Received: from [213.84.253.33] (helo=partyman.org)
   by server2a.woolnet.net with smtp (Exim 4.24)
   id 1BItkP-0006RI-1v
   for mgb@minegoboom.com; Wed, 28 Apr 2004 14:25:29 -0400
Date: Wed, 28 Apr 2004 20:25:38 +0100
To: mgb@minegoboom.com
Subject: Re: Msg reply
From: ori_kl@netvision.net.il
Message-ID: <klksxcimsowjgwmkozb@minegoboom.com>
MIME-Version: 1.0
Content-Type: multipart/mixed;
        boundary="--------gfuyvfzagrfnvbnohmgd"

----------gfuyvfzagrfnvbnohmgd
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: 7bit

<html><body>
Message  is in  attach<br><br>

<br>
</body></html>

----------gfuyvfzagrfnvbnohmgd
Content-Type: application/octet-stream; name="Info.com"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="Info.com"

[...]

----------gfuyvfzagrfnvbnohmgd--

CypherJF - Fri Apr 30, 2004 2:46 pm
Post subject:
Worm got your email, gg! icon_smile.gif Someone had it in an outlook address book methinks
D1st0rt - Fri Apr 30, 2004 6:32 pm
Post subject:
its secret squirrel code, maybe Qndre can break the encryption
Mine GO BOOM - Fri Apr 30, 2004 8:09 pm
Post subject:
Well, someone doesn't know how to read email headers very well, nor understands how viruses work.

Let me explain: Thats a bonus-back email because my email provider, by default, didn't like seeing a virus in the email. It was sent to me, from which you can see by this chunk of the header:
Received: from [213.84.253.33] (helo=partyman.org) by server2a.woolnet.net with smtp (Exim 4.24)

Also, viruses no longer even bother with read return addresses. They pick a random to address, and a random send address, and fake it all. Hell, I've gotten a few spams sent to mgb@ from mgb@, but of course, those Received headers don't lie. At some point, the email will hit a real provider, and it will record the IP it received it from.

For the record, I edited your post to removed the attached virus. Since email is in plain text, all binary attachments are sent in base64, and thus you attached the actual virus, just in text form.
pixelsoft - Sat May 01, 2004 3:53 pm
Post subject:
D1st0rt wrote:
its secret squirrel code, maybe Qndre can break the encryption

HAHAHAHAH hahah HRoflF RlO LOL FOMFG OMFG LMAO FLAHAHAHA
Solo Ace - Sat May 01, 2004 11:26 pm
Post subject:
pixelsoft wrote:
D1st0rt wrote:
its secret squirrel code, maybe Qndre can break the encryption

HAHAHAHAH hahah HRoflF RlO LOL FOMFG OMFG LMAO FLAHAHAHA

Lol, yes, that was funny, had me laughing for a few seconds. tongue.gif biggrin.gif
All times are -5 GMT
View topic
Powered by phpBB 2.0 .0.11 © 2001 phpBB Group