CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Help! How to stop flood attack against my mailbox?
Goto page 1, 2  Next
 
Post new topic   Reply to topic       All -> FavForums -> Trend Micro HijackThis Logs [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Walt

Sergeant
Sergeant


Joined: Mar 15, 2003
Posts: 91
Location: USA

PostPosted: Sat Sep 20, 2003 11:22 am    Post subject: Help! How to stop flood attack against my mailbox?
Reply with quote

I am receiving hundreds and hundreds of emails per hour. Most
with some variation claiming to be a security patch from Microsoft.

I can't delete them fast enough. They quickly fill up my mailbox,
and my ISP starts to reject all additional, new, email after
that. This includes the few, real, emails I need and want to get.

My ISP is of no help since all these emails are originating from
several other ISP's. They can only suggest sending email to
those other ISP's "abuse" accounts. Well, there is just too many
of them for me to download and try to figure out the headers
(if that is at all really possible).

I really can't keep sitting here 24/7, and doing nothing but deleting
email.

Is there any thing that can done to help a victim like me, from
these types of attacks? Crying or Very sad Crying or Very sad Confused Crying or Very sad Crying or Very sad

Back to top
View users profile Send private message
BillC

Captain
Captain
Premium Member

Joined: Jun 25, 2003
Posts: 456

MVP Premium

PostPosted: Sat Sep 20, 2003 12:10 pm    Post subject:
Reply with quote

Unfortunately, the answer is no. The flood of e-mails generated by the two lastest nasty viruses, W32/Gibe-F and W32/Swen@MM are being sent from infected machines. And, as the domaine of infected machines grows, then the number of mailings grow exponentially. Ugh.

Of courrse, don't open any attachments and have comfort in the fact it is not you that is the infected one.

More information on the viruses:
http://www.sophos.com/virusinfo/analyses/w32gibef.html
http://securityresponse.symantec.com/avcenter/venc/data/w32.swen.a@mm.html

Sorry about that. Sad

Back to top
View users profile Send private message Visit posters website
Walt

Sergeant
Sergeant


Joined: Mar 15, 2003
Posts: 91
Location: USA

PostPosted: Sat Sep 20, 2003 3:03 pm    Post subject:
Reply with quote

Ah, well, I was afraid of that. Crying or Very sad Confused Crying or Very sad

All I can do, I guess, is hope that all these people either clean up there machines, or that their ISP's notice what is going on, and cut off their service (until they do clean up their machine).

One of the benefits of a direct DSL or Cable connection. One can leave their computer connected to the internet, and allow it to attack a full 24/7.

I do, however, want to say "thanks" for replying.

As a related side note, why is it so difficult for ISP's to develop a filter to kill all email which pretends to be an Official Patch from Microsoft? There must be a way to detect these types of SPAM by examining their attachment. As in my case, I use to get just one or two a day of these types of SPAMs. Now I am getting one or two a minute.

Back to top
View users profile Send private message
BillC

Captain
Captain
Premium Member

Joined: Jun 25, 2003
Posts: 456

MVP Premium

PostPosted: Sat Sep 20, 2003 3:21 pm    Post subject:
Reply with quote

Quote:
why is it so difficult for ISP's to develop a filter to kill all email which pretends to be an Official Patch from Microsoft? There must be a way to detect these types of SPAM by examining their attachment


One man's trash is another man's treasure? I think it is just too difficult for an ISP to decide what is good or bad for all their customers. Freedom of expression is the cornerstone of our society. All "speech" good or bad is protected I guess. Besides, what would all those vendors selling firewalls, anti-virus, anti-trojan, anti-spam, anti-'you name it' software do to make a living? Very Happy

Back to top
View users profile Send private message Visit posters website
Walt

Sergeant
Sergeant


Joined: Mar 15, 2003
Posts: 91
Location: USA

PostPosted: Sat Sep 20, 2003 5:24 pm    Post subject:
Reply with quote

Well, we are talking about only unsolicited so-called Microsoft Patches here. I don't think Microsoft freely emails true Windows Patches to people (one needs to download them from windowsupdate.microsoft.com).

I think any ISP could (1) detect that the email did not actually originate from Microsoft by examining the all the info in the headers, (2) detect that the attachment contains a virus, and (3) note that the size of the attachment matches the "work" of the viruses mentioned above.

If all are true, delete it. Or at least have their existing anti-SPAM software tag it as being a known SPAM.

While my PC's own software could get rid of such SPAM, as it does other SPAM, my dial-up connect just can't download this deluge of SPAM as fast as it is showing up. Therefore, my mailbox overflowith.

In other words, none of these 1,000's and 1,000's of emails I am receiving daily are treasure to me. Sorry, but I really doubt anyone else would call these particular emails a treasure either.

Back to top
View users profile Send private message
Jamming

Colonel
Colonel
Premium Member

Joined: Jun 22, 2002
Posts: 1874

Premium

PostPosted: Sat Sep 20, 2003 7:40 pm    Post subject:
Reply with quote

Do you know how to make a message rule for your program? You could set the message rule to Delete it at the Server, but you would have to have some common thing about them to detect like the title or part of the title.

Back to top
View users profile Send private message
tyucikas

Guest
IP: 66.63.*.*






PostPosted: Fri Sep 26, 2003 4:42 am    Post subject: method for deleting spam
Reply with quote

the flood of "MS security patches" etc takes a long time
to download from ISP, but if instead of launching email
program, just surf to your ISP's home page and loging
there .. then look at the email headers without having to
sit and wait for all those 144k and 156k messages to
be delivered to your own puter. It's easy to delete them
while just looking at the subject, 'From" etc ... saves a
ton of time.

(works for me anyway)

Back to top
Walt

Sergeant
Sergeant


Joined: Mar 15, 2003
Posts: 91
Location: USA

PostPosted: Fri Sep 26, 2003 8:25 pm    Post subject:
Reply with quote

I have tried to do just that. However, that involves me having to connected up to my email through my ISP's webpage once an hour. That is once an hour, every hour, all day long and all night long.

However, between having to go to work and catching a few hours of sleep every night, I just can't do that once every hour.

So, what happens is that my mail box fills up within an hour of my last deleting. At that point, my ISP shuts down my email totally. I can't any more bogus Microsoft patches, and I can't get any more of my valid email. Crying or Very sad

Back to top
View users profile Send private message
shafted

Cadet
Cadet


Joined: May 07, 2003
Posts: 2
Location: USA

PostPosted: Fri Sep 26, 2003 8:30 pm    Post subject:
Reply with quote

Post the headers from the email. I will tell you the IP it is coming from. Then you need to contact the ISP abuse dept to and have them locate their customer to fix their problem.

Back to top
View users profile Send private message AIM Address Yahoo Messenger
Walt

Sergeant
Sergeant


Joined: Mar 15, 2003
Posts: 91
Location: USA

PostPosted: Fri Sep 26, 2003 8:47 pm    Post subject:
Reply with quote

I really appreciate the offer, but I no longer think that is the answer.

I was saving the headers, to send to my ISP's anti-spam department, but stopped after collecting 200 unique ones.

Most were from outside the USA too. The very few from within the USA, I did send a copy to their ABUSE id. From those, one and only one replied.

Back to top
View users profile Send private message
IP: 24.98.*.*

Guest






PostPosted: Fri Sep 26, 2003 9:50 pm    Post subject:
Reply with quote

Walt,

Do you use webmail or do you have an e-mail client like Outlook Express? I know of a way to block all mail in OE except those in your address book. Would that solve the problem?

I'm also curious, are you a member of a news group? I'm wondering how you get so many. Sorry about the problem you are having.

Back to top
TimeGhost

Major
Major


Joined: Apr 11, 2003
Posts: 750
Location: USA
Team F@H

PostPosted: Mon Sep 29, 2003 3:21 pm    Post subject:
Reply with quote

One of the Mailwasher Pro users came up with a way to auto-delete by downloading a program that's made to automate keypresses. I'd figure out a way to schedule that if I were you.

Good luck.

Back to top
View users profile Send private message
salva

Guest
IP: 217.230.*.*






PostPosted: Thu Oct 02, 2003 8:07 am    Post subject: use yaspi!
Reply with quote

Idea if your mailbox is being bombed by virusen, you should try yaspi:

http://yaspi.sourceforge.net

- Salva[/b]

Back to top
IP: 80.46.*.*

Guest






PostPosted: Sun Oct 05, 2003 6:51 pm    Post subject:
Reply with quote

Do you use webmail or do you have an e-mail client like Outlook Express? I know of a way to block all mail in OE except those in your address book. Would that solve the problem?

Hi who ever u r, the above would help me, as for Walt, I feel sorry for you, thought I was getting enough but not as many as you, I now look at e-mails I want to, put the ones I want into a folder, then 'select all' delete, then go to delete folder and clear them off, that way you are not opening them, but my anti virus gets rid of it OK, but as you say it is bl**dy annoying, Ann

Back to top
BillC

Captain
Captain
Premium Member

Joined: Jun 25, 2003
Posts: 456

MVP Premium

PostPosted: Sun Oct 05, 2003 8:15 pm    Post subject:
Reply with quote

Ann,

If you just want to allow e-mails in from those folks in your address book, try these rules:

Outlook Express to allow only certain people in..

Go to OE/Tools/Message Rules/Mail/New/ Tick the first item "Where the from line contains people"/ Tick an item in the #2 box (You have a choice to copy, delete, move to folder, do not download it from server or delete it form server) you might want to set up a junk folder and put them there. Now click "contains people" under box #3/click "address book"/highlight the first name and scroll down to bottom of list and hold "Shift key" and click the last name/click "From" at top right and it will copy address to "Rule Addresses"/click "ok"/click "options"/tick "Message does not contain the people below"/click "ok"/click "ok"/Then click "Specified Folder(if you chose that option earlier)/pick a folder/ click "oK".

I've not tried it myself but it seems as if it should work. I guess I'm just not popular because I've only recieved 4 of these "virus e-mails" But that is a good thing.

Of couse this will stop mail from every other source too, including some you might want until you add the sender to your list.

BillC

Back to top
View users profile Send private message Visit posters website
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Trend Micro HijackThis Logs All times are GMT
Goto page 1, 2  Next
Page 1 of 2

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer