Sobig

Dan Oetting dan_oetting@qwest.net
Tue, 26 Aug 2003 18:27:14 -0600


On Tuesday, August 26, 2003, at 04:58  PM, delta trinity wrote:

> ... some ISP or MSP detect the virus and send it back to the [FORGED] 
> mail 'sender' field (in that specific case, gmp-discuss).  Then, GMP 
> forward the warning as if it was regular mail.
>
> Correct me if I'm wrong...

You're not wrong.

The problem is that the GMP mailing list allows ANYBODY to post instead 
of restricting posts to subscribers only or verifying the address of 
non-subscribers. Every other mailing list that I am subscribed to would 
automatically block the virus mail because the forged sender address is 
unlikely to be another subscriber.

I'll probably be dropping off this list if the administrators can't 
lock it down.

-- Dan Oetting