Fighting back against Swen/Gibe.F

Fraser Campbell fraser-Txk5XLRqZ6CsTnJN9+BGXg at public.gmane.org
Mon Oct 20 15:23:25 UTC 2003


Hi,

I have received over 1,200 copies of this virus since Wednesday morning.  
Ignoring, or just filtering, is not an option.

Yesterday I wrote a few perl and shell scripts to find out who sent the email 
and automatically complains to their ISP.

I was a bit worried that sending 1,200 complaint letters out might get me in 
trouble with a few people but I've had nothing but positive feedback.  3 or 4 
people have lost their Internet connectivity as a result of my email, several 
virus sources have been found and corrected.

I've had quite a few personal letters of thanks from admins around the world 
and of course floods of autoreplies from abuse departments.  I've also found 
out that a lot of people don't have very well setup email systems (no abuse@ 
or even postmaster at aliases).  An interesting one is that Sympatico has an MX 
records for qc.sympatico.ca but doesn't actually accept any email there.  
I'll be following up to all the crappy mail admins with additional emails.

If anyone else is having a problem with this and is interested in my scripts 
just say the word.

-- 
Fraser Campbell <fraser-Txk5XLRqZ6CsTnJN9+BGXg at public.gmane.org>                 http://www.wehave.net/
Halton Hills, Ontario, Canada                       Debian GNU/Linux

--
The Toronto Linux Users Group.      Meetings: http://tlug.ss.org
TLUG requests: Linux topics, No HTML, wrap text below 80 columns
How to UNSUBSCRIBE: http://tlug.ss.org/subscribe.shtml





More information about the Legacy mailing list