Internet Security Update

Magnus Bodin magnus@bodin.org
Wed, 13 Mar 2002 19:06:25 +0100


On Mon, Mar 11, 2002 at 10:10:53PM +0530, Udhay Shankar N wrote:
> At 09:03 AM 3/10/02 -0800, Gregory Alan Bolcer wrote:
> >
> >> You've been social engineered. See below.
> >>
> >> Udhay
> >>
> >
> >Well, I think the first thing I did was go to the MSFT
> >site and see if there really was a patch.  If you mean socially
> >engineered to "must go to Microsoft.com" then I fell for it.  8-)
> 
> Your earlier mail appeared to say that you believed it was from Microsoft, 
> which was what I was referring to. ;-)
> 
> Interesting thought: I'm guessing that most members of this group will 
> believe any kind of stupidity from Microsoft (including myself), so the 
> above hoax would not even set off alarms...

The worst thing with this mail worm is that its timing with this MSIE-hole
is perfect:

	<http://www.newsbytes.com/news/02/175185.html>

	Test-URL here: (just fires up the calculator)

		http://x42.com/test/calc.jpg


I've actually seen REAL MS-mails about this hole recently, but they got
filtered down in my spam-folder...


/magnus

-- 
http://x42.com/