Home  | Software

Home>>Software>>A'i sending virusi's to win workstation

News Archive

MP3 Support for noatun
Help with multi-lang in
BT client possible solu
About default gdm sessi
Fedora + Gnomemeeting +
fedora and Realplayer
wxPythonGTK.rpm ????
kmix popping up arbitra
Yum Bittorrent-gui
Matroska playback on Mp

For more info

cobol compiler
Burning mp3 CDs
problems with gcc
Fedora hangs for no app
Adding Fedora PC to W2K
"Makefile.PL:  command 
installing from tar's
MySQL working on FC1?
How to edit Options in 
g++ compiler informatio

TOP

A'i sending virusi's to win workstation

Igoraus
2004-05-12, 04:16 AM PDT
HI

My problem is that My FedoraC1 sending virusis to Microsoft workstation, I used thunderbird for collect mail.

So; anyone know good program that intercept mail's with virusi's or other infected stuff.

When whas on Windows2000 I used Nod32. Anyone used Nod32 on Linux, I like Nod32.

Thenx to all.

ilja
2004-05-12, 04:31 AM PDT
As far as I understood your Fedora is your mail server ? If so http://fedoranews.org/contributors/ron_goulard/clamav describes how to install an anti-virus scanner on your fedora.

Igoraus
2004-05-12, 04:38 AM PDT
no is not mail server, just my workstation, I used to read my mail, print some documents, and surf over the internet,...
When I got mail with virus and clik on mail, virus not harm my Fedora but send himself to everybody in my adressbook and if sameon on Microsoft then fuck.

And I dont use sendmail, just smtp of mail meil server.


:D

ilja
2004-05-12, 04:41 AM PDT
Originally posted by Igoraus

When I got mail with virus and clik on mail, virus not harm my Fedora but send himself to everybody in my adressbook and if sameon on Microsoft then fuck.


When it does, then it harmed your fedora. But I don't think that it was that way. Someone of your friends got infected and his Windows-Machine send this mail with viruses to all the contacts. And it faked your Email-Adress as sender. If really your computer was sending /is sending this viruses, then it is infected and that would be the first infected Linux I heard of.

Igoraus
2004-05-12, 04:52 AM PDT
:eek: :eek:

If I click on infected mail, nothing can heppend to my FedoraC1 :eek: :eek: :eek: this is true ???

ilja
2004-05-12, 04:55 AM PDT
Originally posted by Igoraus
:eek: :eek:

If I click on infected mail, nothing can heppend to my FedoraC1 :eek: :eek: :eek: this is true ???

The problem is, that most of the viruses are in .exe .pif and .com format and you can't execute them in linux without a windows-emulation. I heard, that there are 7 or so linux viruses, but there are not in wild, so we needn't care about them. I'm not a security expert, but I would say if you click on a Windows virus in your Fedora nothing can happen.

Igoraus
2004-05-12, 05:03 AM PDT
But I heard that some virusi's had inside his one smpt sender or something, am dont andustud a'lot bat that virusis send demself to everibady in adressbook.

Im panick becose som frend coll me andd sey : whay you sedn me virus.

Now I'm scered ....

ilja
2004-05-12, 05:06 AM PDT
Originally posted by Igoraus
But I heard that some virusi's had inside his one smpt sender or something, am dont andustud a'lot bat that virusis send demself to everibady in adressbook.

Yes there are a plenty of them. But these are Windows viruses. There is no danger for Linux users.
Originally posted by Igoraus

Im panick becose som frend coll me andd sey : whay you sedn me virus.

Now I'm scered ....
Explain your friend, that such viruses fake the header of mails. So they write a wrong sender adress. I get about 20 viruses per day with faked sender. And some get virus-mails with my adress. You can't do anything against it. And it is also hard to find out, whose Computer is infected.

Igoraus
2004-05-12, 05:18 AM PDT
ok, naw I'm come down.


thenx to tolk with me.

Drugače bi se lahko po slovenk pogovorila mi se zdi da zna?

Text up is in slovenian language.

fjleal
2004-05-12, 07:35 AM PDT
And I thought my english was bad... ;)

Bobmeister
2004-05-12, 02:11 PM PDT
But to clarify for you (bad English or not)...the virus attacks on address books attack the MICROSOFT OUTLOOK type of address books. NONE that I know of can figure out the Mozilla style address books (yet)...and again as stated above, if it worked, it would be in Windows machines.

To answer your first question, if you would like to feel better, f-prot provides for FREE a great virus scanner for Linux workstations (home users). It is easy to install, and easy to run. It is command-line based and you can scan any directory or even your entire system if you want. It has an updater to keep the virus definitions up to date and they update at least once every other day.

Go to http://www.f-prot.com. get the read-me files and there are very simple instructions on installation and running it.

Don't worry so much...

ghaefb
2004-05-12, 03:49 PM PDT
Igoraus :)
ti si slovenc!?
cool

Igoraus
2004-05-16, 11:14 PM PDT
my mail is : igoraus@email.si

Ok, what will you think if receive mail like this:



subject: Mail delivery failed: returning message to sender


body:

This message was created automatically by mail delivery software.

A message that you sent could not be delivered to one or more of its
recipients. This is a permanent error. The following address(es) failed:

igor_petrovic@mettron.si
This message has been rejected because it has
a potentially executable attachment "Information.cpl"
This form of attachment has been used by
recent viruses or other malware.
If you meant to send this file then please
package it up as a zip file and resend it.

------ This is a copy of the message, including all the headers. ------

Return-path: <igoraus@email.si>
Received: from [213.250.17.74] (helo=maitim.net)
by nelson.uknoc.co.uk with smtp (Exim 4.24)
id 1BOzNc-0001hM-LV
for igor_petrovic@mettron.si; Sat, 15 May 2004 14:39:08 +0100
Date: Sat, 15 May 2004 15:39:00 +0100
To: "Igor" <igor_petrovic@mettron.si>
From: "Igoraus" <igoraus@email.si>
Subject: Notification
Message-ID: <jwkfnfnbmplvsnkyhqk@mettron.si>
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="--------vkxwxgakebtfdqwjiezo"

----------vkxwxgakebtfdqwjiezo
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: 7bit

<html><body>


<br>
</body></html>

----------vkxwxgakebtfdqwjiezo
Content-Type: application/octet-stream; name="Information.cpl"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="Information.cpl"

crackers
2004-05-16, 11:43 PM PDT
Yes, somebody that has your e-mail address in their Outlook addressbook is infected. As above, viruses (virii?) use an address from that addressbook to send itself to others in the addressbook.

What you quoted was a "bounced" message from someone's mail server that has a virus-scanner running on it. Since the "From" address was yours, you get the nasty e-mail saying you sent the virus. Most virus-scanners are now configured to not do this, for this very reason - it confuses the person whose address was hijacked.

Just wait until a spammer starts using your e-mail address. That's a lot of fun, too...

Jman
2004-05-17, 07:58 PM PDT
I didn't even know .cpl was executable. Silly Windows relying on extensions to determine whether a file is executable or not.

If you meant to send this file then please
package it up as a zip file and resend it. They even tell you how to get around it! Unfortunately clueless users will unzip and run a zipped virus.

I'm waiting for the day when email servers actually verify your email address instead of just going along with the forgery.

bamboo_spider
2004-07-15, 02:17 PM PDT
Hi This forum

I am a neoconvert to Linux running FC 1 on a P III , 866 Mhz, 20 Gb Hardisk (make ??) 386 mb Ram Laptop

The virus and antivirus content has got me really impressed and further ratifies the decision to switch to Linux

Thank you
Bamboo


Related stories:

MP3 Support for noatun
Help with multi-lang in gnome
BT client possible solution
About default gdm session
Fedora + Gnomemeeting + Quicknet PhoneJackPCI
fedora and Realplayer
wxPythonGTK.rpm ????
kmix popping up arbitrarily
Yum Bittorrent-gui
Matroska playback on Mplayer or Xine

Copyright@2004-2005 www.linux521.com All Right Reserved