PaulW
Member
Registered: 26th Jan 03
Location: Atherton, Greater Manchester
User status: Offline
|
I leave my dsl connected 24/7, as its running on one of my servers...
past few days, the firewall's been getting about 50-80 attacks a min, but don't worry too much!
Now I just received an email to my orange account, supposedly from orange themselves & this contained the W32.Beagle.A@mm virus as an attachment 
do some people really think I'm thick enough NOT to run any sort of weak firewall or not have antivirus installed? FFS I paid enough buying norton antivirus coorporate edition 7.6 with 25 client liscence & i aint exactly NOT gona use it!!
I'm gona hunt these down & have some fun!
Or I could read up on how beagle works & write something to 'simulate' how it sends & receives remote control commands via port 6677 or whatever it is & then get the nooooob's IP

ooooh I feel a fun night coming up!!
quote: This is the email I received
Return-path: <tutorial@graphiland.fr>
Received: from triplesec.orange.co.uk (triplesec.orange.co.uk [193.35.131.135])
by mail0.orange.net
(iPlanet Messaging Server 5.2 HotFix 1.23 (built Nov 19 2003))
with ESMTP id <0HU000E72PNVYF@mail0.orange.net> for pdwollaston@orange.net;
Wed, 03 Mar 2004 20:45:31 +0000 (GMT)
Received: from Belge ([62.147.150.18]) by triplesec.orange.co.uk
(Netscape Messaging Server 4.15 triplesec Jul 30 2001 12:58:33)
with SMTP id HU0PNM00.P8N for <pdwollaston@orange.net>; Wed,
03 Mar 2004 20:45:22 +0000
Date: Wed, 03 Mar 2004 21:45:21 +0100
From: noreply@orange.net
Subject: Email account utilization warning.
To: pdwollaston@orange.net
Message-id: <scfysqagipeqhstwqyn@orange.net>
MIME-version: 1.0
Content-type: multipart/mixed; boundary=--------tbloyxwnndybklexcain
Original-recipient: rfc822;pdwollaston@orange.net
----------tbloyxwnndybklexcain
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Dear user, the management of Orange.net mailing system wants to let you know that,
Our antivirus software has detected a large ammount of viruses outgoing
from your email account, you may use our free anti-virus tool to clean up
your computer software.
For further details see the attach.
Cheers,
The Orange.net team http://www.orange.net
----------tbloyxwnndybklexcain
Content-Type: application/octet-stream; name="Info.pif"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="Info.pif"
**REMOVED IT (don't wana be bitched at by ian & tim for putting a virus up on CS!)**
|