[Top][All Lists]
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Hey, ya! =))
From: |
Erik Sandberg |
Subject: |
Re: Hey, ya! =)) |
Date: |
Tue, 2 Mar 2004 21:59:54 +0100 |
User-agent: |
KMail/1.5.4 |
On Tuesday 02 March 2004 14.14, Rutger Hofman wrote:
> According to the headers, this comes from 51.78.92.200 helo=ENTHUSIA.
> If I do a DNS lookup, I get:
> 61.78.92.200.in-addr.arpa domain name pointer
> customer-TEP-78-61.megared.net.mx.
>
> Anybody on the list recognizes themselves in this domain megared.net.mx.?
> Then please take action to eliminate your virus/worm/, the list is getting
> a bit overloaded...
This trick doesn't seem to help, the ip:s seem to be faked somehow... each
worm-infected message has a unique ip which its headers says it comes from.
Erik