[Intrusions] New SPAM Technique?

Tom Liston tliston at premmag.com
Thu Jun 3 15:12:16 GMT 2004


On 3 Jun 2004 at 10:07, Hillery wrote:

> Sources are a variety of places - many .cn and .kr, some us dsl &
> broadband.  I haven't been able to get anything from a machine where they
> were outbound (the src), and have only seen the dst traffic.

Folks,

This is single packet pop-up spam sent via UDP... It's connectionless.  So 
if the people sending this stuff have ANY brains at all, the source IP is 
about as useful as the "From" line in email.

-TL



More information about the Intrusions mailing list