Cycling Equipment · Public discussion

SWEN WORM

Started by Ella · · Last activity · 48 posts · 2,534 views

Thread navigation

Jump through the discussion

Go to the original post, the replies on this page, or the latest preserved contribution.

Thread details

What we know about this thread

Original section
Cycling Equipment
Published
21 September 2003
Last activity
7 November 2003
Original author
Ella
Posts
48
Discussion status
Public discussion
Total views
2,534
Views / 30 days
0

The navigation and discussion metadata provide context. Posts remain in their original chronological order.

Showing posts 21–40 of 48
Posts remain in their original chronological order.

Text size
  1. RE/

    Quoted message said:

    the monkey business from Verisign.

    If their mail servers are being deluged now, maybe there's at list a little justice in the
    universe...-)
    -----------------------
    PeteCresswell

  2. GoCycle said:

    The idiot at my server told me to open up these bogus virus e-mails and send them to [email hidden].
    WOW!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! "David Damerell" <[email hidden]> wrote in
    message "]news:[email hidden]...

    Quoted message said:
    ella said:

    how do i get rid of this worm .

    Get a real mail client and newsreader.
    --
    David Damerell <[email hidden]> Distortion Field!

    Mine told me to forward a couple of them to [email hidden] with a note explaining the problem
    (I'm an earthlink subscriber). I did that and they simply added them to their spam block list, and
    as far as I can tell, didn't do anything else <sigh>.

    If I don't stay logged-on downloading my mail every 10 minutes or so, my mail box on the server side
    fills exceeds my 10 Meg quota in 1-2 hours. Since I'm on a modem, that's a bit of a pain. And, since
    it's the host side with the problem -- linux (or MY favorite, OS/2) wouldn't fare any better <sigh>.
    Mozilla's having no problems identifying them as trash and moving them for me, so inbox clutter's
    not a problem either. It's just the deluge...

    David

  3. David Kunz <[email hidden]> spake thusly on or about Tue, 23 Sep 2003 23:00:00 UTC

    -> Since I'm on a modem, that's a bit of a pain. And, since it's the -> host side with the problem
    -- linux (or MY favorite, OS/2) wouldn't fare -> any better <sigh>.

    I had 350 notices that my isp had stripped the swen.a virus this am. I just filter them out but I
    wish they would put something in the header or subject that would enable me to delete w/o
    downloading.

    --
    I hurt before the ride so fibro gives me a head start on the rest of the pack. silver lining?
    [email hidden]

  4. My Linux and Mac OS X machines have had no issues with this, nor any, worm.

    Linux: the Ultimate Windows Service pack! Pick one: linuxiso.orglinuxiso.org

    ella said:

    how do i get rid of this worm . it started right after i posted to this site the other night. now
    i keep getting all the emails . i haven't opened any and the anti virus doesn't find any virus. i
    keep getting the emails though.

  5. Ahahaha...

    NERD!!

    My commodore 64 doesn't have any viruses too, feel free to switch to that..

    Mike mikebeauchamp.commikebeauchamp.com

    "BoulderGeek" <[email hidden]> wrote in message
    "]news:[email hidden]...

    Quoted message said:

    My Linux and Mac OS X machines have had no issues with this, nor any,


    worm.

    Quoted message said:


    Linux: the Ultimate Windows Service pack! Pick one: linuxiso.orglinuxiso.org

    ella said:

    how do i get rid of this worm . it started right after i posted to this


    site

    Quoted message said:
    Quoted message said:

    the other night. now i keep getting all the emails . i haven't opened


    any

    Quoted message said:
    Quoted message said:

    and the anti virus doesn't find any virus. i keep getting the emails


    though.

  6. Mike Beauchamp <[email hidden]> wrote:
    : My commodore 64 doesn't have any viruses too, feel free to switch to that..

    The Contiki desktop environment is a highly portable, open source, Internet-enabled, multitasking,
    graphical operating system that runs on a variety of constrained systems, ranging from modern
    embedded 8-bit microcontrollers to old 8-bit homecomputers like the Commodore 64.
    dunkels.comcontiki

    here's an ethernet card for the C64. jschoenfeld.denews88 e.htm
    --
    david reuteler [email hidden]

  7. Mike Beauchamp said:

    Ahahaha...

    NERD!!

    Look around. This is usenet. We're all nerds. You, too.

    --

    David L. Johnson

    __o | This is my religion. There is no need for temples; no need for _`\(,_ | complicated
    philosophy. Our own brain, our own heart is our (_)/ (_) | temple. The philosophy is kindness.
    --The Dalai Lama

  8. Wow.. Contiki looks awesome! I think I've seen that site before.. The only graphical OS I've used
    for my C64 was GEOS. I haven't tried surfing the net with it yet, although I think I should
    eventually..

    Mike mikebeauchamp.commikebeauchamp.com

    "David Reuteler" <[email hidden]> wrote in message
    "]news:[email hidden]...

    Quoted message said:

    Mike Beauchamp <[email hidden]> wrote:
    : My commodore 64 doesn't have any viruses too, feel free to switch to


    that..

    Quoted message said:


    The Contiki desktop environment is a highly portable, open source, Internet-enabled, multitasking,
    graphical operating system that runs on a variety of constrained systems, ranging from modern
    embedded 8-bit microcontrollers to old 8-bit homecomputers like the Commodore 64.
    dunkels.comcontiki

    here's an ethernet card for the C64. jschoenfeld.denews88 e.htm
    --
    david reuteler [email hidden]

  9. They didn't have the Debian 37MB netinstall images there. 🙁

    BoulderGeek said:

    My Linux and Mac OS X machines have had no issues with this, nor any,


    worm.

    Quoted message said:


    Linux: the Ultimate Windows Service pack! Pick one: linuxiso.orglinuxiso.org

    ella said:

    how do i get rid of this worm . it started right after i posted to this


    site

    Quoted message said:
    Quoted message said:

    the other night. now i keep getting all the emails . i haven't opened any and the anti virus
    doesn't find any virus. i keep getting the emails


    though.

    --
    Mark Wolfe wolfenet.orgwolfenet.org gpg fingerprint = 42B6 EFEB 5414 AA18 01B7 64AC EF46 F7E6 82F6
    8C71 He who makes a beast of himself gets rid of the pain of being a man. -H.S. Thompson

  10. are there people working to rid the system I'm in of this virus? or am I responsible for killing it?

  11. [email hidden] (g.daniels) wrote in message
    news:<[email hidden]>...

    Quoted message said:

    are there people working to rid the system I'm in of this virus? or am I responsible for
    killing it?

    Dear Gene,

    Here are a few yahoo.com posters who might have suggestions about your specific ISP's settings or
    anti-virus programs:

    Appkiller ([email hidden]) [email hidden] claire petersky [email hidden]

    Good luck,

    Carl Fogel

  12. I got nothin' for ya (except for an in-box fulla fake microsoft spam).

    Sorry,

    App

    Who thinks Claire would at least offer some solace for the soul, if not a direct solution.

  13. (g.daniels) may have said:

    are there people working to rid the system I'm in of this virus? or am I responsible for
    killing it?

    In a perfect world, admins everywhere would be allowed to install whatever filtering and
    infestation-transmission spotting measures were needed, and would have the manpower to contact their
    afflicted users and give them the assistance required to clean up the problem. Sadly, this is not a
    perfect world, and some system admins lack such resources, either for policy or fiscal constraint
    reasons. (Some others are insufficiently enlightened to understand the need for them.) As such,
    while I can't say that it is any user's *responsibility* to clean up the mess created by the
    cluelessness of the Swen-infected users, it is certainly good form to apply whatever resources are
    at one's disposal to addressing the problem if time and circumstances permit.

    In the case of Swen, headers reliably show only the IP address (and often mailer domain name) of the
    infested user's system. Parsing the first two Received: lines of the headers will generally identify
    the place where a heads-up should be sent (to abuse@ if it exists, to postmaster@ or whatever else
    may be appropriate if there's no abuse@ address active). Be sure to include a brief note explaining
    that a Swen distribution email originated from the source indentified in the headers. Remember that
    the person who will be receiving the message is probably not in a position to make policy, but can
    usually act on a direct report of a problem; be helpful, not accusative or denigrating. It is a good
    idea to relay only the headers in such a case, as the body and attachment are not really required
    for such incidents...and most admins will appreciate the saving of bandwidth.

    This will probably not reduce your Swen burden much, however.

    To realize a drop in the Swen traffic that is hitting your inbox, a different tactic is effective.
    When posting to Usenet, it has proven to be highly advisable to use an address obfuscation technique
    to make your own email address less virus-accessible. By way of comparison: For two addresses which
    were both used extensively on Usenet for the past year, one obfuscated and one not, the Swen hit
    rate as of last week for the former was 2 total since the Swen virus appeared, while the latter had
    received over 7500 Swens; at 100Kb per, that's 750Mb of junk that had to be filtered at the user's
    end. Two weeks ago, the previously non-obfuscated address ceased to be used on Usenet in a
    harvestable form, and most of the harvestable incidences of that address have now aged off of news
    spools; as a result, for the past 24 hours, the Swen hit rate for that previously-swamped address
    was down to less than one per hour average, while a third still-harvestable address reports a hit
    rate that has remained fairly steady at a much higher level.

    Birefly then, to help get rid of Swen, appropriately report the infestations. To keep from being
    bothered by it to begin with, don't post to Usenet with an unobfuscated address.

    --
    My email address is antispammed; pull WEEDS if replying via e-mail. Yes, I have a killfile. If I
    don't respond to something, it's also possible that I'm busy.

  14. On Tue, 28 Oct 2003 02:10:55 GMT, Werehatrack <[email hidden]> wrote:

    <snip>

    Quoted message said:

    Birefly then, to help get rid of Swen, appropriately report the infestations. To keep from being
    bothered by it to begin with, don't post to Usenet with an unobfuscated address.

    Of course, one might be unfortunate enough for some kind soul to post it for you.

  15. Chris B. bikerider@-NOSPAM_THANKS-rogers.com may have said:

    On Tue, 28 Oct 2003 02:10:55 GMT, Werehatrack <[email hidden]> wrote:

    <snip>

    Quoted message said:

    Birefly then, to help get rid of Swen, appropriately report the infestations. To keep from being
    bothered by it to begin with, don't post to Usenet with an unobfuscated address.

    Of course, one might be unfortunate enough for some kind soul to post it for you.

    One post won't produce much of a problem; I'm pretty sure that such an incident generated the single
    pair of Swen hits on the address I mentioned that had been otherwise Swen-free. Of course, there was
    an additional bit of luck involved; the post with the address was about a month prior to the first
    flood of Swen hits, so it was probably long since spooled off of a lot of servers.

    In any event, it has been determined that Swen only reads the headers, so the likelihood of getting
    flooded due to a post in a message body seems negligible...although the spammers will certainly make
    up for any lack of Swens in that case.

    --
    My email address is antispammed; pull WEEDS if replying via e-mail. Yes, I have a killfile. If I
    don't respond to something, it's also possible that I'm busy.

  16. Chris B. <bikerider@-NOSPAM_THANKS-rogers.com> wrote in message
    news:<[email hidden]>...

    Quoted message said:

    On Tue, 28 Oct 2003 02:10:55 GMT, Werehatrack <[email hidden]> wrote:

    <snip>

    Quoted message said:

    Birefly then, to help get rid of Swen, appropriately report the infestations. To keep from being
    bothered by it to begin with, don't post to Usenet with an unobfuscated address.

    Of course, one might be unfortunate enough for some kind soul to post it for you.

    Dear Chris,

    Aaargh! I just finished apologizing to my three victims. Now I have to thank you for pointing out my
    idiocy so gently--"jackass" would be more accurate than "soul."

    Now for the ritual hari-kari, which is all that I can offer in expiation . . .

    [email hidden]

    . . . apart from promising not to do it to anyone else.

    Again, I'm awfully sorry.

    Carl Fogel

  17. "g.daniels" <[email hidden]> wrote in message
    "]news:[email hidden]...

    Quoted message said:

    are there people working to rid the system I'm in of this virus? or am I responsible for
    killing it?

    Dear G. Daniels:

    Yahoo does not seem to be interested in doing anything about this worm. Yes, it has slowed down from
    100 copies an hour to maybe 100 copies a day, but that's probably due to other people working
    against it, not yahoo. Yahoo kindly puts most of these wormy messages in a spam folder, but they do
    not automatically flush it out. As a result, your experience is probably similar to mine -- you wake
    up in the morning, and your yahoo box is shut down because you receive a couple dozen copies during
    the night. If you don't flush it out every few hours, the box gets overwhelmed again. Legitimate
    email can't get through.

    Yahoo has no interest in working against the worm. You, like me, get the yahoo account for free,
    right? They'd like us all to pay for our yahoo account. One way to get us to pay for it is to have
    our boxes regularly jammed, so that we pay for Yahoo Plus (or whatever they call it) and get more
    storage space. For all I know, those who have paid accounts also get their sven virus copies
    filtered out.

    What I've done is abandoned my yahoo account. I monitor it and flush it, because I've been at that
    address for so long, and lots of people have it as my email address. It's also on my web site, and
    I'd like to monitor the account to reply to people who are responding to that site.

    For all other email, including bookcrossing and all my mailing lists, I am now doing from my regular
    ISP. For usenet postings, I am munging the email address in the from and reply line using
    mouse-potato.com as the domain. I recommend mouse-potato.com as a munged domain name because it is
    set up such that spam sent to that address never leaves the computer it is sent on. Not only will no
    one ever receive it, it won't burden servers, relays, or any other infrastructure of the internet.

    If you don't have an ISP -- let's say you're someone who only uses google and yahoo from your local
    library, then I'm wondering if you couldn't at least set up an account through spamex (on their free
    trial) so at least later sven worm virii and related will go to a disposable address.

    I hope this is helpful to you, and to others using yahoo (or some other web-based address) and
    google for posting.

    --
    Warm Regards,

    Claire Petersky Please replace earthlink for mouse-potato and .net for .com

    Home of the meditative cyclist: home.earthlink.netWelcome.htm

    Books just wanna be FREE! See what I mean at: bookcrossing.comCpetersky

  18. Chris B. <bikerider@-NOSPAM_THANKS-rogers.com> wrote in message
    news:<[email hidden]>...

    Quoted message said:

    On Tue, 28 Oct 2003 02:10:55 GMT, Werehatrack <[email hidden]> wrote:

    <snip>

    Quoted message said:

    Birefly then, to help get rid of Swen, appropriately report the infestations. To keep from being
    bothered by it to begin with, don't post to Usenet with an unobfuscated address.

    Of course, one might be unfortunate enough for some kind soul to post it for you.

    Dear Chris and others,

    My newsgroup connection eventually let me delete the post that listed the unmunged email addresses
    of three yahoo.com posters whom I suggested might help with Gene's question.

    This is why this thread may now seem somewhat puzzling--imagine a well-meant post, just below the
    post from g.daniels , that says here are three people who might help.

    Regrettably, my dumb listing is probably still visible on other newsgroup servers.

    Carl Fogel

  19. On 29 Oct 2003 11:39:36 -0800, [email hidden] (Carl Fogel) wrote:

    <snip>

    Lighten up! It matters not as regards the Swen worm since only the headers of the post are examined
    as Werehatrack pointed out.

  20. Chris B. <bikerider@-NOSPAM_THANKS-rogers.com> wrote in message
    news:<[email hidden]>...

    Quoted message said:

    On 29 Oct 2003 11:39:36 -0800, [email hidden] (Carl Fogel) wrote:

    <snip>

    Lighten up! It matters not as regards the Swen worm since only the headers of the post are
    examined as Werehatrack pointed out.

    Dear Chris,

    I appreciate what I hope is cheerful encouragement, not irritated admonishment. (Hard to tell, isn't
    it? I opt to read your lines as friendly.)

    But Werehatrack added that "the spammers will certainly make up for any lack of Swens in that case,"
    didn't he?

    It's hard to say "Lighten up!" to the surprising number of private posts chiding me for such
    cluelessness (none, I'm relieved to say, from my actual victims--so far).

    Light-heartedly yours,

    Carl Fogel

Active in the last 60 minutes

Active in this thread

0 users · 0 guests ·0 bots ·0 total

No signed-in users are active right now.

No known search crawlers active right now.