Cycling Equipment · Public discussion

OT, but important SWEN virus

Started by Chris Zacho "Th · · Last activity · 7 posts · 720 views

Thread navigation

Jump through the discussion

Go to the original post, the replies on this page, or the latest preserved contribution.

Thread details

What we know about this thread

Original section
Cycling Equipment
Published
3 October 2003
Last activity
4 October 2003
Original author
Chris Zacho "Th
Posts
7
Discussion status
Public discussion
Total views
720
Views / 30 days
0

The navigation and discussion metadata provide context. Posts remain in their original chronological order.

Showing posts 1–7 of 7
Posts remain in their original chronological order.

Text size
  1. I think someone on this group may have it, because every time I have opened posts in this group, My
    mailbox is filled of "returned" messages and "MicroSoft security update" notices.

    I cleared my RAM cache before posting this, so this post should be clean (WebTV has no hard drive to
    infect). I'm not accusing anyone, just letting you all know it is possible one or more of you may be
    infected, and therefor could possibly infect others.

    You may wish to update your anti-virus programs and run a scan, just to be sure!

    "May you have the wind at your back. And a really low gear for the hills!"

    See you on the road. Chris Chris'Z Corner geocities.comczcorner

  2. On Fri, 3 Oct 2003 10:46:58 -0400 (EDT), [email hidden] (Chris Zacho "The Wheelman"😉 may

    have said:

    I think someone on this group may have it, because every time I have opened posts in this group, My
    mailbox is filled of "returned" messages and "MicroSoft security update" notices.

    I cleared my RAM cache before posting this, so this post should be clean (WebTV has no hard drive
    to infect). I'm not accusing anyone, just letting you all know it is possible one or more of you
    may be infected, and therefor could possibly infect others.

    You may wish to update your anti-virus programs and run a scan, just to be sure!

    It is unlikely that the people whose systems are sending you these Swens are even reading this
    group at all.

    The virus has been confirmed to have the following relevant operational characteristics:

    Upon infecting a target system, it searches for the user's news server identity and login
    information. If it finds this, it will use it to log in to the server and collect *just headers*
    from a randomly selected newsgroup. (It would be sheer coincidence if the system's user also
    participated in that group.) It then will send two copies of its distribution emails to each address
    scraped from those headers.

    If the user's system does not have a news server configured, it has an internal list of servers that
    it will try, with the same result.

    To reduce the number of WW.Swen virus emails you receive, munge your address in your user
    identification setup; what the virus can see in the From: field of the headers will determine how
    much Swen [censored] you'll get. If you start now, within a week you will probably only be getting Swen
    mail from users who have access to long-retention spools like Easynews. Most users' news feeds age
    out in less than a week. Swen does not access the Google archives; it scrapes from conventional nntp
    servers only.

    --
    My email address is antispammed; pull WEEDS if replying via e-mail. Yes, I have a killfile. If I
    don't respond to something, it's also possible that I'm busy.

  3. "Chris Zacho "The Wheelman"" <[email hidden]> wrote in message
    "]news:[email hidden]...

    Quoted message said:

    I think someone on this group may have it, because every time I have opened posts in this group,
    My mailbox is filled of "returned" messages and "MicroSoft security update" notices.

    I cleared my RAM cache before posting this, so this post should be clean (WebTV has no hard drive
    to infect). I'm not accusing anyone, just letting you all know it is possible one or more of you
    may be infected, and therefor could possibly infect others.

    You may wish to update your anti-virus programs and run a scan, just to be sure!

    This was big news...TWO WEEKS AGO!

    Bill "prolly around same time some unknown person used an unknown 'h' word?"
    S.

  4. Werehatrack <[email hidden]> wrote in message
    news:<[email hidden]>...

    Quoted message said:


    To reduce the number of WW.Swen virus emails you receive, munge your address in your user
    identification setup; what the virus can see in the From: field of the headers will determine how
    much Swen [censored] you'll get. If you start now, within a week you will probably only be getting Swen
    mail from users who have access to long-retention spools like Easynews. Most users' news feeds age
    out in less than a week. Swen does not access the Google archives; it scrapes from conventional
    nntp servers only.

    Hi, how do you change your email address to something corrupted, when it requires email
    confirmation, to change it? Thank you, Jeff

  5. (Jeff Starr) may have said:

    Werehatrack <[email hidden]> wrote in message
    news:<[email hidden]>...

    Quoted message said:


    To reduce the number of WW.Swen virus emails you receive, munge your address in your user
    identification setup; what the virus can see in the From: field of the headers will determine how
    much Swen [censored] you'll get. If you start now, within a week you will probably only be getting Swen
    mail from users who have access to long-retention spools like Easynews. Most users' news feeds
    age out in less than a week. Swen does not access the Google archives; it scrapes from
    conventional nntp servers only.

    Hi, how do you change your email address to something corrupted, when it requires email
    confirmation, to change it?

    If you're using a web interface to read Usenet postings, you're probably not going to be able to do
    anything about the issue. If your ISP provides a news feed, I'd suggest downloading a news reader
    client and working through that instead; then you can have any identity that you want.

    --
    My email address is antispammed; pull WEEDS if replying via e-mail. Yes, I have a killfile. If I
    don't respond to something, it's also possible that I'm busy.

  6. [email hidden] (Werehatrack) suggested:

    Quoted message said:

    To reduce the number of WW.Swen virus emails you receive, munge your address in your user
    identification setup

    "Munge"?

    "May you have the wind at your back. And a really low gear for the hills!"

    See you on the road. Chris Chris'Z Corner geocities.comczcorner

  7. On Sat, 4 Oct 2003 12:26:45 -0400 (EDT), [email hidden] (Chris Zacho "The Wheelman"😉 may

    have said:

    [email hidden] (Werehatrack) suggested:

    Quoted message said:

    To reduce the number of WW.Swen virus emails you receive, munge your address in your user
    identification setup

    "Munge"?

    Look atthe way my address is given in the headers. There's something in it to keep spambots (and
    now, Swen, although that wasn't why I did
    it) from grabbing the address off of my Usenet postings. This is known as "munging" among admins and
    old-time Usenetters. The idea is to make the address useless to a data harvester bot because it
    won't work without intervention by a human to fix it. I.e., make it broken in a simple and
    obvious (preferablt self-evident, though that's less easy) manner.

    Frequently, a clue to the munging is given in the user's sigfile, as is the case in mine.

    A couple of the more clever munges, as made obvious by sigfile notes:

    Remove YOUR_CLOTHES to reply via email.

    Unreachable via email while FOIL_HAT is in place.

    More common munges include simply putting a space before and after the @ in the address, or
    replacing @ with AT and the dots with DOT. Some munges on admin-heavy groups can only be decoded
    using a Perl programming expression that is in the sigfile. (I doubt that this would be a safe dodge
    here.) A common munge is the inclusion of something like SPAMBLOCK in the username or domain name.
    And no, the munge does not have to be all caps, although that's a common method of highlighting it
    for humans.

    --
    My email address is antispammed; pull WEEDS if replying via e-mail. Yes, I have a killfile. If I
    don't respond to something, it's also possible that I'm busy.

Active in the last 60 minutes

Active in this thread

0 users · 0 guests ·0 bots ·0 total

No signed-in users are active right now.

No known search crawlers active right now.