I've gotten about 50 of these faked headers over the last 2 weeks. One was from an email account I own, but isn't in use.
"The file attached to this email was removed because it is infected with the [EMAIL PROTECTED] virus." http://securityresponse.symantec.com/avcenter/venc/data/[EMAIL PROTECTED] -----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of agenthh Sent: April 4, 2004 9:29 PM To: [EMAIL PROTECTED] Subject: Re: [hlds_linux] sv_downloadurl & HLTV [EMAIL PROTECTED] wrote: > Yes, this is more the than likely the case. None of the windows machines here > use Outlook. I use IMP exlusively. > > Patrick > > Quoting Alex Brett <[EMAIL PROTECTED]>: >>It's possible that it isn't him that is infected. If anybody has both >>his e-mail address, and this list's email address in their address book, >>and gets hit by one of the many worms around, then it could quite >>feasibly send out an e-mail to this list using his address as a forged >>from address. This seems even more likely since his legitimate e-mail >>has a note at the bottom saying sent through IMP (a webmail client that >>can't get infected). You should check the headers of the message as well. Patrick's messages come from the cyotix.com domain, on a 66.x.x.x subnet. The last two virus-laden emails came from 83.33.26.129. It's safe to say from this info that it's not Patrick's computer (at least at work) that is infected. --AgentHH _______________________________________________ To unsubscribe, edit your list preferences, or view the list archives, please visit: http://list.valvesoftware.com/mailman/listinfo/hlds_linux

