TRUSTAbyss.com - Alert!

 
Post new topic   Reply to topic    Aprelium Forum Index -> Off Topic Discussions
View previous topic :: View next topic  
Author Message
TRUSTAbyss
-


Joined: 29 Oct 2003
Posts: 3752
Location: USA, GA

PostPosted: Wed Jun 15, 2005 3:08 pm    Post subject: TRUSTAbyss.com - Alert! Reply with quote

I found a message in my inbox today that wasn't written from me but it
came from my Server , if your going to use PHP for mail , make sure you
set it to allow localhost only. I guess they found a way to send spam.

The E-mail you may recieve could look like

Quote:

Dear user name,

You have successfully updated the password of your Trustabyss account.

If you did not authorize this change or if you need assistance with your account, please contact Trustabyss customer service at: support@trustabyss.com

Thank you for using Trustabyss!
The Trustabyss Support Team






+++ Attachment: No Virus (Clean)
+++ Trustabyss Antivirus - www.trustabyss.com


--------------------------------------------------------------------------------


Attachment accepted-password.zip has been removed by ArGoSoft Mail Server


Note: My E-mail Server automaticly removes attachments so if this was
a virus , you will not recieve it. This will never happen again. LateR! :-)

Sincerely , TRUSTpunk
Back to top View user's profile Send private message Visit poster's website
MonkeyNation
-


Joined: 05 Feb 2005
Posts: 921
Location: Cardiff

PostPosted: Wed Jun 15, 2005 5:11 pm    Post subject: Re: TRUSTAbyss.com - Alert! Reply with quote

TRUSTpunk wrote:
I found a message in my inbox today that wasn't written from me but it
came from my Server , if your going to use PHP for mail , make sure you
set it to allow localhost only. I guess they found a way to send spam.

The E-mail you may recieve could look like

Quote:

Dear user name,

You have successfully updated the password of your Trustabyss account.

If you did not authorize this change or if you need assistance with your account, please contact Trustabyss customer service at: support@trustabyss.com

Thank you for using Trustabyss!
The Trustabyss Support Team






+++ Attachment: No Virus (Clean)
+++ Trustabyss Antivirus - www.trustabyss.com


--------------------------------------------------------------------------------


Attachment accepted-password.zip has been removed by ArGoSoft Mail Server


Note: My E-mail Server automaticly removes attachments so if this was
a virus , you will not recieve it. This will never happen again. LateR! :-)

Sincerely , TRUSTpunk


I found that out the hard way too, saw 1000s of mesages in the queue =/
_________________
Back to top View user's profile Send private message AIM Address Yahoo Messenger MSN Messenger ICQ Number
Anonymoose
-


Joined: 09 Sep 2003
Posts: 2192

PostPosted: Wed Jun 15, 2005 7:41 pm    Post subject: Reply with quote

This is the result of the MyTob worm, nothing to do with anyone's PHP. I'm seeing a lot of variants on these messages in the rejected mail on the domains I manage at work.

I can't link directly to the explanation on Sophos's website, but go to http://www.sophos.com/virusinfo/analyses/w32mytobat.html and read the Advanced section for more details on one variant of the worm.
Back to top View user's profile Send private message
TRUSTAbyss
-


Joined: 29 Oct 2003
Posts: 3752
Location: USA, GA

PostPosted: Thu Jun 16, 2005 1:53 am    Post subject: Reply with quote

Their is no way my Server is infected with this worm because I don't go
online with it , all my server does it serves up web pages. impossible!

I believe it was an Anonymous user doing it.
Back to top View user's profile Send private message Visit poster's website
MonkeyNation
-


Joined: 05 Feb 2005
Posts: 921
Location: Cardiff

PostPosted: Thu Jun 16, 2005 2:06 am    Post subject: Reply with quote

TRUSTpunk wrote:
Their is no way my Server is infected with this worm because I don't go
online with it , all my server does it serves up web pages. impossible!

I believe it was an Anonymous user doing it.


As long as it is connected, it is vunerable to a degree.
_________________
Back to top View user's profile Send private message AIM Address Yahoo Messenger MSN Messenger ICQ Number
aprelium
-


Joined: 22 Mar 2002
Posts: 6800

PostPosted: Thu Jun 16, 2005 12:16 pm    Post subject: Re: TRUSTAbyss.com - Alert! Reply with quote

TRUSTpunk,

We get hundreds of such emails everyday (and 50% of them pretend they were sent by aprelium.com)! Check the headers of the these mails to see which IP was the cause of the this spam, then download "WhoIs View" from http://www.whoisview.com/products/whoisview/ (free tool), and use it to know which ISP/company the IP belongs to. "WhoIs view" will display also the abuse report addresses/phones. Contact them to report the spam (give them the mail with all its headers).
_________________
Support Team
Aprelium - http://www.aprelium.com
Back to top View user's profile Send private message Send e-mail
Anonymoose
-


Joined: 09 Sep 2003
Posts: 2192

PostPosted: Thu Jun 16, 2005 2:17 pm    Post subject: Reply with quote

TRUSTpunk wrote:
Their is no way my Server is infected with this worm because I don't go
online with it , all my server does it serves up web pages. impossible!

I believe it was an Anonymous user doing it.


If I go to the trouble of giving you a reference, at least take the time to read it before squawking about your server being uninfected. I never said your server was infected, I said the spoofed emails you are receiving are the result of the MyTob worm.

A quick read of the explanation on Sophos would have given you

Quote:

W32/Mytob-AT can spread by sending itself as an email attachment to email addresses harvested from the infected computer. W32/Mytob-AT spoofs the sender's email address so that the sent email appears to be from the same domain from one of the following users:

admin
administrator
info
mail
register
service
support
webmaster

For example if sending itself to name@example.com, W32/Mytob-AT might send the email as if from admin@example.com.
Back to top View user's profile Send private message
TRUSTAbyss
-


Joined: 29 Oct 2003
Posts: 3752
Location: USA, GA

PostPosted: Thu Jun 16, 2005 2:24 pm    Post subject: Reply with quote

Are you saying that this could have been from someone else's infected PC ?
Back to top View user's profile Send private message Visit poster's website
Anonymoose
-


Joined: 09 Sep 2003
Posts: 2192

PostPosted: Thu Jun 16, 2005 4:51 pm    Post subject: Reply with quote

I'm saying it is from someone else's infected PC. The email headers should show a different IP to your own server.
Back to top View user's profile Send private message
TRUSTAbyss
-


Joined: 29 Oct 2003
Posts: 3752
Location: USA, GA

PostPosted: Thu Jun 16, 2005 6:07 pm    Post subject: Reply with quote

I will check it out. Thanks for the reponse on this matter. LateR!
Back to top View user's profile Send private message Visit poster's website
jlp09550
-


Joined: 05 Jun 2005
Posts: 123
Location: Louisiana, USA

PostPosted: Fri Jun 17, 2005 5:23 am    Post subject: Reply with quote

I know how to fix it!

Either go and install the new security updates @ http://windowsupdate.microsoft.com/

Or... download the removal tool: http://securityresponse.symantec.com/avcenter/FixMytob.exe

Yes, try out the removal tool & visit windows update ASAP. The removal tool deletes registery and files you tought weren't even there! I tried it and it is now gone!

P.S. It may block you from downloading the removal tool, so, download it here: http://lightfaeries.com/FixMytob.exe
_________________
Hosted Abyss Sites-
http://jared.chibipaws.com/ - My Stuffs
http://jaredblog.chibipaws.com/ - My Blog
Back to top View user's profile Send private message Send e-mail Visit poster's website AIM Address Yahoo Messenger MSN Messenger
Anonymoose
-


Joined: 09 Sep 2003
Posts: 2192

PostPosted: Fri Jun 17, 2005 1:53 pm    Post subject: Reply with quote

jlp09550 wrote:
I know how to fix it!
<snip pointless post>


That's nice, but if you read the topic you'd see TRUSTPunk isn't infected.
Back to top View user's profile Send private message
jlp09550
-


Joined: 05 Jun 2005
Posts: 123
Location: Louisiana, USA

PostPosted: Sat Jun 18, 2005 6:50 am    Post subject: Reply with quote

NO! You will not find out as NO anti-virus programs are updated to check for that! -chills down-

OK... I should say that is another computer is infected, you will have to live with it until it stops, like me... I had 100 emails one day in my inbox.... but, if you are very unlucky, it WILL use your email address to send to ALOT of people and you WILL get undeliverable messenges until it desides to move to someone else!
_________________
Hosted Abyss Sites-
http://jared.chibipaws.com/ - My Stuffs
http://jaredblog.chibipaws.com/ - My Blog
Back to top View user's profile Send private message Send e-mail Visit poster's website AIM Address Yahoo Messenger MSN Messenger
TRUSTAbyss
-


Joined: 29 Oct 2003
Posts: 3752
Location: USA, GA

PostPosted: Sat Jun 18, 2005 3:21 pm    Post subject: Reply with quote

I believe you , Mail Servers need to be more powerful. I blocked the range
of the sender so that the virus cannot continue with its evil plans lol. LateR!

I haven't seen one e-mail after doing what Aprelium recommended.

Sincerely , TRUSTpunk
Back to top View user's profile Send private message Visit poster's website
TRUSTAbyss
-


Joined: 29 Oct 2003
Posts: 3752
Location: USA, GA

PostPosted: Sat Sep 24, 2005 1:38 am    Post subject: Reply with quote

Enable SMTP Authentication And Disable E-mail sendings with accounts that
don't exist on the server. This is how I got rid of the spammers. LateR! :-)

Sincerely , TRUSTpunk
Back to top View user's profile Send private message Visit poster's website
Display posts from previous:   
Post new topic   Reply to topic    Aprelium Forum Index -> Off Topic Discussions All times are GMT + 1 Hour
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB phpBB Group