[Towertalk] FYI - Virus Address Spoofing

mwdink@eskimo.com mwdink@eskimo.com
Wed, 24 Apr 2002 08:38:56 -0700


FYI - just as a trivial interest

A lot of mail has been going around about the latest
virus behavior and address spoofing. Got a good example
of it in the 3830 administration hold box this morning.


A post FROM "3830-request" TO "3830".

3830-request would never originate mail - it is used
for incoming list administration requests. You would normally
post TO "3830-request". Obviously, some one has both these 
addresses in their address book and the random combination 
finally popped up.

So, the moral is (if there is one), watch who you 
accuse of sending viruses. :>(

73 and have good day
dink, n7wa