[plug] tricksy email and strange attachments

Matt Kemner zombie at penguincare.com.au
Thu Feb 27 13:42:38 WST 2003


On Thu, 27 Feb 2003, quoth sol:

> Two problems:
> 1) I checked with the approved poster, and he hadn't sent any email, let alone
> strange attachments. I think that someone is "faking" the email address
> headers. Is this possible? How can it be blocked?

Faking an email From: address is as easy as sending someone a postcard
with a fake return address.  There is no authentication in sending email.

This is why cryptographic email signatures are so popular - it is the only
way to know for sure who sent it (providing you "trust" their key, either
directly or via a web-of-trust)

I haven't seen any mailing list software that checks those signatures, but
it would be a very useful feature.

> 2) Has anyone come across "press.scr"? I suspect it's a 'doze virus and that
> half of my email list is about to get it. NOT HAPPY BILL!

I don't know of it, but with an extension of .scr (which is what win3.x
used to call screensavers) it is almost undoubtedly a trojan of some sort.

 - Matt



More information about the plug mailing list