 |
 |
Mac trojaned or willing spammer?
|
 |
|
 |
|
Addicted to MacNN
Join Date: Feb 2001
Location: zurich, switzerland
Status:
Offline
|
|
(Mods: If this is considered OT please move it to the right topic, whatever that may be)
The story goes like this:
I have the usual junk filter running in Mail for the almost daily trip of hundreds of copies of the sobig worm still being mailed to me, since I was dumb enough to place my mail address in a usenet group. I also have image display turned off so that spam servers can't track me using my IP.
Usually I just delete all the crap in junk mail regularly, but on occaision I view the whole header to try and follow who is sending this junk. (The mail in question looks like a page from Microsoft, which I'm sure a lot of you have seen. It has a supposed warning about a security vulnerability on windows machines and includes an EXE attachment and instructions on how to install it).
A few minutes ago I did a traceroute on one of the headers (the from address was spoofed of course) which turned up the following address: dialup-67.75.10.201.dial1.boston1.level3.net (67.75.10.201)
I then did a portscan to see if any ports were open (I was interested to see if this was a trojaned machine and if it had opened up some ports) and lo and behold port 80 (http) was open.
After this I did a curl -I and discovered that this is a Mac running OS 8.x or 9.x with personal web sharing (you can check it in the browser).
Now, I'm dumbfounded. If the Mac has been trojaned so that these things get sent automatically, why haven't we heard of it, and does this mean that Mac OS8 and Mac OS9 are vulnerable to certain trojans in the wild? Or is this some bastard doing this on purpose? (i.e. Do Windows spam or Trojan tools exist on the Mac)
|
|
weird wabbit
|
| |
|
|
|
 |
|
 |
|
Professional Poster
Join Date: Apr 2001
Location: Capital city of the Empire State.
Status:
Offline
|
|
Might that machine be running Virtual PC? If so, it would certainly be vulnerable to Windoze viral infections.
|
|
/mal
"I sentence you to be hanged by the neck until you cheer up."
MacBook Pro 15"/2.4 GHz Intel Core 2 Duo/4 GB DDR2 SDRAM/200 GB Hitachi HD/8x SuperDrive/Mac OS X 10.6.1
|
| |
|
|
|
 |
|
 |
|
Grizzled Veteran
Join Date: Dec 2000
Location: Málaga, Spain, Europe, Earth, Solar System
Status:
Offline
|
|
Maybe they just have a email server with a Really Big™ security hole.
I bet for it.
|
|
|
| |
|
|
|
 |
|
 |
|
Addicted to MacNN
Join Date: Feb 2001
Location: zurich, switzerland
Status:
Offline
|
|
Originally posted by malvolio:
Might that machine be running Virtual PC? If so, it would certainly be vulnerable to Windoze viral infections.
It would mean that our entrepid user uses Outlook on his Mac for his mails (Via VPC). It might be, but I somehow doubt it. In any case I've mailed his ISP with the header to see if they get a response.
|
|
weird wabbit
|
| |
|
|
|
 |
|
 |
|
Professional Poster
Join Date: Oct 1999
Location: :ИOITAↃO⅃
Status:
Offline
|
|
The most likely explanation is that the user with that IP address when the email was sent is not the user with that IP address when you went looking.
|
|
|
| |
|
|
|
 |
|
 |
|
Addicted to MacNN
Join Date: Feb 2001
Location: zurich, switzerland
Status:
Offline
|
|
Originally posted by Mithras:
The most likely explanation is that the user with that IP address when the email was sent is not the user with that IP address when you went looking.
I doubt it, it's still up now: 67.75.10.201 (and has been so for the past hour)
|
|
weird wabbit
|
| |
|
|
|
 |
|
 |
|
Professional Poster
Join Date: Jun 2001
Location: Northwest Ohio
Status:
Offline
|
|
Originally posted by theolein:
I doubt it, it's still up now: 67.75.10.201 (and has been so for the past hour)
It is a dial up account. You posted at 6:33 and then again at 7:00. When I was on dialup sometimes I would spend 5 or 6 hours online... wait until tomorrow, then look it up. It probably won't be a Mac.
Besides, most spammers won't use dial up hosts anyways. No reliability.
|
|
|
| |
|
|
|
 |
|
 |
|
Addicted to MacNN
Join Date: Feb 2001
Location: zurich, switzerland
Status:
Offline
|
|
Originally posted by Person Man:
It is a dial up account. You posted at 6:33 and then again at 7:00. When I was on dialup sometimes I would spend 5 or 6 hours online... wait until tomorrow, then look it up. It probably won't be a Mac.
Besides, most spammers won't use dial up hosts anyways. No reliability.
So it was you! 
|
|
weird wabbit
|
| |
|
|
|
 |
|
 |
|
Professional Poster
Join Date: Jun 2001
Location: Northwest Ohio
Status:
Offline
|
|
|
|
|
|
| |
|
|
|
 |
 |
|
 |
|
|
|
|
|

|
|
 |
Forum Rules
|
 |
 |
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
|
HTML code is Off
|
|
|
|
|
|
 |
 |
 |
 |
|
 |
|