From jfarkas at calpoly.edu Wed Jan 14 19:43:43 2004 From: jfarkas at calpoly.edu (Jacob Farkas) Date: Wed, 14 Jan 2004 19:43:43 -0800 Subject: [CPLUG Chatter] Old floppy disks Message-ID: <40060C6F.1080405@calpoly.edu> I'm looking for old 3.5" or 5.25" floppy disks for CPLUG advertising. If you have any you'd like to get rid of (working or non, the older the better), or know of anywhere I can get a hold of some, please let me know. Thanks, Jacob Farkas From wbrooks at lug.ee.calpoly.edu Wed Jan 14 21:43:40 2004 From: wbrooks at lug.ee.calpoly.edu (Bill Brooks) Date: Wed, 14 Jan 2004 21:43:40 -0800 (PST) Subject: [CPLUG Chatter] Old floppy disks In-Reply-To: <40060C6F.1080405@calpoly.edu> Message-ID: On Wed, 14 Jan 2004, Jacob Farkas wrote: > I'm looking for old 3.5" or 5.25" floppy disks for CPLUG advertising. If > you have any you'd like to get rid of (working or non, the older the > better), or know of anywhere I can get a hold of some, please let me know. If you were going to ask faculty, you should have "gone for broke" and asked for 8" floppy disks...the *REAL* floppies! 3.5" diskettes obviously don't really "flop" anymore. I'll start asking my fellow people with grey hair around campus and see if I can come up with any for you. :-) Bill From scottdas at hotmail.com Wed Jan 14 21:45:57 2004 From: scottdas at hotmail.com (David A. Scott) Date: Wed, 14 Jan 2004 21:45:57 -0800 Subject: [CPLUG Chatter] Need help in a good cause References: <40060C6F.1080405@calpoly.edu> Message-ID: I am trying to ressurect a really old hunk of junk computer for an old lady who is financially strapped. A P-166 were talking ancient. It has a serial mouse and an AT style keyboard connector. I had a PS2/AT keyboard adapter but I haven't had a serial mouse in a couple of years, I tried using one of those PS/2 to serial adapters but it wouldn't fly, I think only certain mice worked with those. Would you by any chance have a serial mouse in your collection that you'd be able to donate to the cause. Also although not as immediately essential are some SIMMS this box has 16mb of memory. If I even got it up to 32 it would be an improvement. I had a hard drive to put in it and a Cd rom drive, sound card and a modem, just a couple items short to finish the project. Thanks Dave Scott From martha.ross at adams12.org Tue Jan 27 07:16:15 2004 From: martha.ross at adams12.org (martha.ross at adams12.org) Date: Tue, 27 Jan 2004 08:16:15 -0700 Subject: [CPLUG Chatter] hi Message-ID: <200401271530.i0RFURf1013974@pi.cubicle.net> m?m???n,G)??????????s<7???8x???q?w???Y?/q???_{kW?"zRV_????bx?V??????j???|??-????5|'.Z(?;???N?????6l!????|?C???SJ?z ??? ??`??,Q???G>C????R??7):?E?M?;$J$5??:???????uTV????qJ1???D??ix ??????;?_?c??V????Y?J{? ?r???kq0??~??q??????N???g.%]???)??*??;?w?????*eyfeH?Z????P!?gU????z$?o?^)????]????7????7N?D*????'?????Kz?? ???v ux?????]???n??C?}/?UHV????9??????3d???m]S?4?`??$??HV?????????[?.Y??5fZ?P??jy??F?vn;????4?/0e????tY $?(?[y???a!G????E?zo?Q EU????????? ?!bj0?h?3?dN????ZDt??(Q?0Q????s?u?6?c?m.6Jo?n;?&?Sy??3?D???5??f?\cn????}?M??%a?}X????MD?Xb(??y?`Y ?????M?9sb??Y?OV???L?? ?oa?1?bF?? gf???]??? $t,?R?$??? ??xL?????ps?{h???n??:'??????????$?"?l?_f???b????a?????????%]?????UN?u?D???]???_I?d?8???k?????wp,??jSO??????-j???73????D#?26"??x7?R??????JRr?*???*90F`???T??V??l??o????s~?<'?V?????dx??*?m/Y7????8XZ???(/?????y[??zC??y&???%??E0?D?m?7??h?!x/???CA???_.?G;K?i>B????q?gZ]H}?7VQ$0?e{3????A?w??P?P?????41??;?6???Mwl?CQ{??o?i??? ??Z??)9N??0?\????? x??.????????6V?8<7?i????s?7QW^?0???R ????FGJ -------------- next part -------------- A non-text attachment was scrubbed... Name: document.zip Type: application/octet-stream Size: 22798 bytes Desc: not available URL: From ejono at ejono.com Tue Jan 27 08:16:56 2004 From: ejono at ejono.com (Jonathan Kelly) Date: Tue, 27 Jan 2004 08:16:56 -0800 Subject: [CPLUG Chatter] hi In-Reply-To: <200401271530.i0RFURf1013974@pi.cubicle.net> References: <200401271530.i0RFURf1013974@pi.cubicle.net> Message-ID: <40168EF8.3000607@ejono.com> Ha, I don't think that's gonna work. Sending an email virus to a bunch of computer nerds? Hehe. Anyway, anybody know what this thing is? Norton Antivirus didn't even pick it up. I don't know enough about binary executables and decompiling and all that, so I was just curious if anybody else knew anything about this. ~Jonathan Kelly martha.ross at adams12.org wrote: >m?m???n,G)??????????s<7?? 8x???q?w???Y?/q???_{kW?"zRV_????bx?V??????j???|??-????5|'.Z(???x???]????A??u??8?6&B??D??h)~'?????v\??X?|?i??????n8? >?b??r1D??]-?O ].e?7?W??4??????? >??a%? >f?????G?????al??? ?GF?M?????'?q???.?*?)?????}?? ?T?DW>?;???N?????6l!????|?C???SJ?z >??? ??`??,Q???G>C????R??7):?E?M?;$J$5??:???????uTV????qJ1???D??ix >??????;?_?c??V????Y?J{ >?r???kq0??~??q??????N???g.%]???)??*??;?w?????*eyfeH?Z????P!?gU??? z$?o?^)????]????7????7N?D*????'?????Kz?? >???v >ux?????]???n??C?}/?UHV????9??????3d???m]S?4?`??$??HV?????????[?.Y??5fZ?P??jy??F?vn;????4?/0e????tY $?(?[y???a!G????E?zo?Q EU????????? ?!bj0?h?3?dN????ZDt??(Q?0Q????s?u?6?c?m.6Jo?n;?&?Sy??3?D???5??f?\cn????}?M??%a?}X????MD?Xb(??y?`Y >?????M 9sb??Y?OV???L?? >?oa?1?bF?? >gf???]??? >$t,?R?$??? >??xL?????ps?{h???n??:'??????????$?"?l?_f???b????a?????????%]?????UN?u?D???]???_I?d?8???k??? ?wp,??jSO??????-< ;???d??m?oNE??y#??Ps?b?H5?a??? >??????,W???A????p??? >jF??v >D?Mj?|????" ?&u?r???Y??u???W?G????3?lD?X8H?)??B????E???zO9??????D????O?E?p????Eg? >?#~???_????????^ >? >???????I??5?}???>j???73????D#?26"??x7?R??????JRr?*???*90F`???T??V??l??o????s~?<'?V?????dx??*?m/Y7????8XZ???(/?????y[??zC??y&???%??E0?D??`?Oq_???????2??P?-?/B?OD6????X?-\???K???,??V??}?^?????do?W??*?E?????Cj_xM?6???li? kf????R???p2!T?q??B??iHs?????*N?:??`s^???M|??U?e????????o\x?s??????4M~?????????)?I]?????A Av?I?w???????v??0]????3/??,q: ??)????_y?i??c????P$2?:? S??{??A >?(_JO???{M??Pl?????e[??????g?}?-?5w?m?v.7d????7v??%???.Qz0p7???lv >???LK??:?^?z-?\S?3??}(&??h!|???:??EK??x[\H????#?????Wb?m?g???s?WM?3???R??????????WH??L?O?????Z???p??????^?R???????q??)?/?G???XV??.?m???`,??su?yg???a3?cj ????p?GB?? ?"'???7???5?w????id?d?^?V?H??q?d`jDa? ! ??p???C?"??????}??????C??o?tD??????0Q??>m?7??h?!x/???CA???_.?G;K?i>B????q?gZ]H}?7VQ$0?e{3????A?w??P?P?????41??;?6???Mwl?CQ{??o?i??? >??Z??)9N??0 \????? x??.????????6V?8<7?i????s?7QW^?0???R >????FGJ > > > From fdavie at hornet.csc.calpoly.edu Tue Jan 27 10:09:34 2004 From: fdavie at hornet.csc.calpoly.edu (Forrest Davie) Date: Tue, 27 Jan 2004 10:09:34 -0800 (PST) Subject: [CPLUG Chatter] hi In-Reply-To: <40168EF8.3000607@ejono.com> Message-ID: Ive been getting very similar emails that are detected as the W32/MyDoom-A virus by the cal poly email gateway. Not sure if thats any help. Forrest Davie fdavie at calpoly.edu On Tue, 27 Jan 2004, Jonathan Kelly wrote: > Ha, I don't think that's gonna work. Sending an email virus to a bunch > of computer nerds? Hehe. Anyway, anybody know what this thing is? > Norton Antivirus didn't even pick it up. I don't know enough about > binary executables and decompiling and all that, so I was just curious > if anybody else knew anything about this. > > ~Jonathan Kelly > > martha.ross at adams12.org wrote: > > >m?m???n,G)??????????s<7?? 8x???q?w???Y?/q???_{kW?"zRV_????bx?V??????j???|??-????5|'.Z( >???x???]????A??u??8?6&B??D??h)~'?????v\??X?|?i??????n8? > >?b??r1D??]-?O ].e?7?W??4??????? > >??a%? > >f?????G?????al??? ?GF?M?????'?q???.?*?)?????}?? ?T?DW>?;???N?????6l!????|?C???SJ?z > >??? ??`??,Q???G>C????R??7):?E?M?;$J$5??:???????uTV????qJ1???D??ix > >??????;?_?c??V????Y?J{ > >?r???kq0??~??q??????N???g.%]???)??*??;?w?????*eyfeH?Z????P!?gU??? z$?o?^)????]????7????7N?D*????'?????Kz?? > >???v > >ux?????]???n??C?}/?UHV????9??????3d???m]S?4?`??$??HV?????????[?.Y??5fZ?P??jy??F?vn;????4?/0e????tY $?(?[y???a!G????E?zo?Q EU????????? ?!bj0?h?3?dN????ZDt??(Q?0Q????s?u?6?c?m.6Jo?n;?&?Sy??3?D???5??f?\cn????}?M??%a?}X????MD?Xb(??y?`Y > >?????M 9sb??Y?OV???L?? > >?oa?1?bF?? > >gf???]??? > >$t,?R?$??? > >??xL?????ps?{h???n??:'??????????$?"?l?_f???b????a?????????%]?????UN?u?D???]???_I?d?8???k??? ?wp,??jSO??????-< ;???d??m?oNE??y#??Ps?b?H5?a??? > >??????,W???A????p??? > >jF??v > >D?Mj?|????" ?&u?r???Y??u???W?G????3?lD?X8H?)??B????E???zO9??????D????O?E?p????Eg? > >?#~???_????????^ > >? > >???????I??5?}???>j???73????D#?26"??x7?R??????JRr?*???*90F`???T??V??l??o????s~?<'?V?????dx??*?m/Y7????8XZ???(/?????y[??zC??y&???%??E0?D? >?`?Oq_???????2??P?-?/B?OD6????X?-\???K???,??V??}?^?????do?W??*?E?????Cj_xM?6???li? kf????R???p2!T?q??B??iHs?????*N?:??`s^???M|??U?e????????o\x?s??????4M~?????????)?I]?????A Av?I?w???????v??0]????3/??,q: ??)????_y?i??c????P$2?:? S??{??A > >?(_JO???{M??Pl?????e[??????g?}?-?5w?m?v.7d????7v??%???.Qz0p7???lv > >???LK??:?^?z-?\S?3??}(&??h!|???:??EK??x[\H????#?????Wb?m?g???s?WM?3???R??????????WH??L?O?????Z???p??????^?R???????q??)?/?G???XV??.?m???`,??su?yg???a3?cj ????p?GB?? ?"'???7???5?w????i >d?d?^?V?H??q?d`jDa? ! ??p???C?"??????}??????C??o?tD??????0Q??>m?7??h?!x/???CA???_.?G;K?i>B????q?gZ]H}?7VQ$0?e{3????A?w??P?P?????41??;?6???Mwl?CQ{??o?i??? > >??Z??)9N??0 \????? x??.????????6V?8<7?i????s?7QW^?0???R > >????FGJ > > > > > > > > > > > _______________________________________________ > Chatter mailing list > Chatter at lists.cplug.org > http://lists.cplug.org/mailman/listinfo/chatter > > From cclarke at calpoly.edu Tue Jan 27 10:15:55 2004 From: cclarke at calpoly.edu (Caleb Clarke) Date: Tue, 27 Jan 2004 10:15:55 -0800 Subject: [CPLUG Chatter] hi (aka, the virus) In-Reply-To: <40168EF8.3000607@ejono.com> References: <200401271530.i0RFURf1013974@pi.cubicle.net> <40168EF8.3000607@ejono.com> Message-ID: <1075227355.435.20.camel@10.0.0.42> "The W32/MyDoom-A,W32/MyDoom-A virus was detected by the Cal Poly Email Antivirus Gateway" Not only computer nerds, but computer nerds who mostly check their e-mail in Linux... nevertheless, sending e-mail viruses to mailing lists isn't very polite. On Tue, 2004-01-27 at 08:16, ejono at ejono.com wrote: > Ha, I don't think that's gonna work. Sending an email virus to a bunch > of computer nerds? Hehe. Anyway, anybody know what this thing is? > Norton Antivirus didn't even pick it up. I don't know enough about > binary executables and decompiling and all that, so I was just curious > if anybody else knew anything about this. > > ~Jonathan Kelly -- Caleb Clarke Cal Poly Linux Users Group Supreme Dicta- ... Treasurer and member of the Illumina- ... CPLUG Exec Board From rdubois at calpoly.edu Tue Jan 27 10:09:42 2004 From: rdubois at calpoly.edu (Ryan Du Bois) Date: Tue, 27 Jan 2004 10:09:42 -0800 Subject: [CPLUG Chatter] hi In-Reply-To: <40168EF8.3000607@ejono.com> References: <200401271530.i0RFURf1013974@pi.cubicle.net> <40168EF8.3000607@ejono.com> Message-ID: <1075226982.5120.2.camel@xpider> Could be the new SCO DDoS Virus. Read about it here: http://slashdot.org/article.pl?sid=04/01/27/0038234 Ryan On Tue, 2004-01-27 at 08:16, ejono at ejono.com wrote: > Ha, I don't think that's gonna work. Sending an email virus to a bunch > of computer nerds? Hehe. Anyway, anybody know what this thing is? > Norton Antivirus didn't even pick it up. I don't know enough about > binary executables and decompiling and all that, so I was just curious > if anybody else knew anything about this. > > ~Jonathan Kelly > > martha.ross at adams12.org wrote: > > >m?m???n,G)??????????s<7?? 8x???q?w???Y?/q???_{kW?"zRV_????bx?V??????j???|??-????5|'.Z( >???x???]????A??u??8?6&B??D??h)~'?????v\??X?|?i?????n8? > >?b??r1D??]-?O ].e7?W??4??????? > >??a%? > >f?????G????al??? ?GF?M????'?q???.?*?)?????}?? ?T?DW>?;???N?????6l!????|?C???SJ?z > >??? ??`??,Q???G>C???R??7):?E?M?;$J$5??:???????uTV????qJ1???D?ix > >??????;?_?c??V????Y?J{ > >?r???kq0??~??q?????N???g.%]???)??*??;?w?????*eyfeH?Z????P!?gU??? z$?o?^)???]????7????7N?D*????'?????Kz?? > >??v > >ux?????]???n??C?}/?UHV????9??????3d???m]S?4?`??$??HV?????????[?.Y??5fZ?P??jy??Fvn;????4?/0e???tY $?(?[y???a!G????E?zo?Q EU????????? ?!bj0?h?3?dN????ZDt?(Q?0Q????s?u?6?c?m.6Jo?n;?&?Sy??3?D???5??f?\cn????}?M??%a?}X???MD?Xb(??y?`Y > >?????M 9sb??Y?OV???L?? > >?oa?1?bF?? > >gf???]??? > >$t,?R?$??? > >??xL????ps?{h???n??:'??????????$?"?l_f???b????a????????%]?????UN?uD???]???_I?d?8???k??? ?wp,??jSO??????-< ;??d??m?oNE??y#??Ps?b?H5?a??? > >??????,W???A????p??? > >jF??v > >D?Mj?|????" ?&u?r??Y?u???W?G????3?lD?X8H?)??B????E???zO9??????D????O?E?p????Eg? > >?#~???_????????^ > >? > >???????I??5?}???>j???73????D#?26"??x7?R??????JRr?*???*90F`???T??V??l?o???s~?<'?V?????dx??*?m/Y7????8XZ???(/?????y[??zC??y&??%??E0?D? >?`?Oq_???????2??P?-?/B?OD6????X?-\???K???,??V??}?^?????do?W??*?E?????Cj_xM?6??li? kf????R??p2!T?q??B??iHs????*N?:??`s^???M|??U?e????????o\x?s??????4M~?????????)I]?????A Av?I?w???????v??0]???3/??,q: ??)????_y?i??c????P$2:? S??{??A > >?(_JO???{M??Pl?????e[??????g?}?-?5w?m?v.7d????7v??%???.Qz0p7???lv > >???LK??:?^?z-?\S?3??}(&??h!|???:??EK??x[\H????#?????Wb?m?g???s?WM?3???R????????WH??L?O?????Z???p??????^?R???????q??)?/?G???XV??.?m???`,??su?yg???a3?cj ????p?GB? ?"'???7???5?w????i >d?d?^?V?H??q?d`jDa ! ??p??C?"??????}??????C??o?tD??????0Q??>m?7??h?!x/???CA???_.?G;K?i>B???q?gZ]H}?7VQ$0?e{3????A?w??P?P????41??;?6???Mwl?CQ{??o?i??? > >??Z??)9N??0 \????? x??.????????6V?8<7?i????s?7QW^?0??R > >???FGJ > > > > > > > > > > > _______________________________________________ > Chatter mailing list > Chatter at lists.cplug.org > http://lists.cplug.org/mailman/listinfo/chatter -- Ryan Du Bois From matt68000 at mac.com Tue Jan 27 10:36:46 2004 From: matt68000 at mac.com (matthew du puy) Date: Tue, 27 Jan 2004 10:36:46 -0800 Subject: [CPLUG Chatter] hi (aka, the virus) In-Reply-To: <1075227355.435.20.camel@10.0.0.42> Message-ID: Are we going to start a discussion thread any time a new Windows virus makes its rounds? Somewhere, somehow, someone that got hit had 'chatter' in their Outlook email address cache. Shame on that person. The rest of us aren't dumb enough to run strange executables and don't care. Heck, I wouldn't have even known the chatter list got hit since my email gateway was kind enough to block it. Now for some real discussion... have any of you tried Cooperative Linux yet? http://sourceforge.net/projects/colinux Would it be a viable replacement to Cygwin (I can't stand the cygwin package manager). My Windows Dev box is faster than my linux dev boxen at work so I'd love to put all my gcc tool chains and debian on my faster box. Does coLinux choke up the CPU cycles to WinXP? Can you switch between OSes quickly in a rootless mode? Thanks, Matt > -----Original Message----- > From: chatter-admin at lists.cplug.org > [mailto:chatter-admin at lists.cplug.org]On Behalf Of Caleb Clarke > Sent: Tuesday, January 27, 2004 10:16 AM > Cc: chatter at cplug.org > Subject: Re: [CPLUG Chatter] hi (aka, the virus) > > > "The W32/MyDoom-A,W32/MyDoom-A virus was detected by the Cal Poly Email > Antivirus Gateway" > > Not only computer nerds, but computer nerds who mostly check their > e-mail in Linux... nevertheless, sending e-mail viruses to mailing lists > isn't very polite. > > On Tue, 2004-01-27 at 08:16, ejono at ejono.com wrote: > > Ha, I don't think that's gonna work. Sending an email virus to a bunch > > of computer nerds? Hehe. Anyway, anybody know what this thing is? > > Norton Antivirus didn't even pick it up. I don't know enough about > > binary executables and decompiling and all that, so I was just curious > > if anybody else knew anything about this. > > > > ~Jonathan Kelly > > -- > Caleb Clarke > Cal Poly Linux Users Group Supreme Dicta- ... Treasurer > and member of the Illumina- ... CPLUG Exec Board > > _______________________________________________ > Chatter mailing list > Chatter at lists.cplug.org > http://lists.cplug.org/mailman/listinfo/chatter From trin6 at pacbell.net Tue Jan 27 15:04:14 2004 From: trin6 at pacbell.net (trin6 at pacbell.net) Date: Tue, 27 Jan 2004 16:04:14 -0700 Subject: [CPLUG Chatter] hello Message-ID: <200401272306.i0RN6if1020776@pi.cubicle.net> The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment. -------------- next part -------------- A non-text attachment was scrubbed... Name: document.pif Type: application/octet-stream Size: 22528 bytes Desc: not available URL: From cclarke at calpoly.edu Tue Jan 27 18:53:20 2004 From: cclarke at calpoly.edu (Caleb Clarke) Date: Tue, 27 Jan 2004 18:53:20 -0800 Subject: [CPLUG Chatter] hi (aka, the virus) Message-ID: <1075258400.438.36.camel@10.0.0.42> Looks like somebody forgot to include the list in their reply, so here's Rohen's e-mail with info about the virus (for those who like to be informed of the latest panic that doesn't affect linux..) I s'pose Matt's right, though... this topic prolly doesn't even qualify for LUG chatter... -- Caleb Clarke Cal Poly State University, San Luis Obispo, California -------------- next part -------------- An embedded message was scrubbed... From: rpeterso at calpoly.edu Subject: Re: [CPLUG Chatter] hi (aka, the virus) Date: Tue, 27 Jan 2004 10:39:49 -0800 Size: 3145 URL: From ejono at ejono.com Tue Jan 27 22:27:11 2004 From: ejono at ejono.com (Jonathan Kelly) Date: Tue, 27 Jan 2004 22:27:11 -0800 Subject: [CPLUG Chatter] hi (aka, the virus) In-Reply-To: <1075258400.438.36.camel@10.0.0.42> References: <1075258400.438.36.camel@10.0.0.42> Message-ID: <4017563F.4020303@ejono.com> Ha, oh man, you guys. Not only was I not looking to start a list discussion on some random virus, but I was also not looking for any rude, sarcastic responses either (not that I didn't expect to receive any sarcasm from at least a few of you). Actually, I was mostly just wondering about decompiling binary executables. I know that it is somehow possible, but I obviously don't really know anything about it. Sorry for not making that more clear in the original email. Most of all, sorry for wasting your precious time. (Some sarcasm back at ya! ^_^) ~Jonathan Kelly P.S. Are any of you guys in CSC 358 this quarter? I had to miss class today to finish a little ENGL 149 project. I'd appreciate it if anybody in that class could just tell me if he assigned any new reading or if he said anything very important today. Did he return the assignment we turned in last week? Thanks a lot. Caleb Clarke wrote: >Looks like somebody forgot to include the list in their reply, so here's >Rohen's e-mail with info about the virus (for those who like to be >informed of the latest panic that doesn't affect linux..) > >I s'pose Matt's right, though... this topic prolly doesn't even qualify >for LUG chatter... > > > > > ------------------------------------------------------------------------ > > Subject: > Re: [CPLUG Chatter] hi (aka, the virus) > From: > rpeterso at calpoly.edu > Date: > Tue, 27 Jan 2004 10:39:49 -0800 > To: > cclarke at calpoly.edu > > To: > cclarke at calpoly.edu > > >If anyone wants to read it that doesn't already know what is going on: >http://www.cnn.com/2004/TECH/internet/01/27/mydoom.spread/index.html > >Rohen Peterson > >----- Original Message ----- >From: >Cc: >Sent: Tuesday, January 27, 2004 10:15 AM >Subject: Re: [CPLUG Chatter] hi (aka, the virus) > > >"The W32/MyDoom-A,W32/MyDoom-A virus was detected by the Cal Poly Email >Antivirus Gateway" > >Not only computer nerds, but computer nerds who mostly check their >e-mail in Linux... nevertheless, sending e-mail viruses to mailing lists >isn't very polite. > >On Tue, 2004-01-27 at 08:16, ejono at ejono.com wrote: > > >>Ha, I don't think that's gonna work. Sending an email virus to a bunch >>of computer nerds? Hehe. Anyway, anybody know what this thing is? >>Norton Antivirus didn't even pick it up. I don't know enough about >>binary executables and decompiling and all that, so I was just curious >>if anybody else knew anything about this. >> >>~Jonathan Kelly >> >> > > > From jfarkas at calpoly.edu Wed Jan 28 01:11:12 2004 From: jfarkas at calpoly.edu (Jacob Farkas) Date: Wed, 28 Jan 2004 01:11:12 -0800 Subject: [CPLUG Chatter] hi (aka, the virus) In-Reply-To: <4017563F.4020303@ejono.com> References: <1075258400.438.36.camel@10.0.0.42> <4017563F.4020303@ejono.com> Message-ID: <40177CB0.1020507@calpoly.edu> I think this is fine as a topic of conversation for chatter. That's why this mailing list is around- this sort of stuff wouldn't be good on cplug@, but there's still interesting stuff here to talk about. I'm not familiar with actually reverse engineering binaries, but these articles are really good: Reverse Engineering Hostile Code http://www.securityfocus.com/infocus/1637 Alien Autopsy: Reverse Engineering Win32 Trojans http://www.securityfocus.com/infocus/1641 Since Cal Poly's mail servers filtered out the attachment, I don't have a copy of the program. It might be cool to try some of the stuff from that article on it though. Does anyone know of a way to get stuff back that's been removed by the antivirus gateway? There's got to be some way of dealing with false positives, although I wouldn't put it past ITS to just automatically delete anything they think is a virus. -j ejono at ejono.com wrote: > Ha, oh man, you guys. Not only was I not looking to start a list > discussion on some random virus, but I was also not looking for any > rude, sarcastic responses either (not that I didn't expect to receive > any sarcasm from at least a few of you). Actually, I was mostly just > wondering about decompiling binary executables. I know that it is > somehow possible, but I obviously don't really know anything about it. > Sorry for not making that more clear in the original email. Most of > all, sorry for wasting your precious time. (Some sarcasm back at ya! ^_^) > > ~Jonathan Kelly > > P.S. Are any of you guys in CSC 358 this quarter? I had to miss class > today to finish a little ENGL 149 project. I'd appreciate it if anybody > in that class could just tell me if he assigned any new reading or if he > said anything very important today. Did he return the assignment we > turned in last week? Thanks a lot. > > Caleb Clarke wrote: > >> Looks like somebody forgot to include the list in their reply, so here's >> Rohen's e-mail with info about the virus (for those who like to be >> informed of the latest panic that doesn't affect linux..) >> >> I s'pose Matt's right, though... this topic prolly doesn't even qualify >> for LUG chatter... >> >> >> >> ------------------------------------------------------------------------ >> >> Subject: >> Re: [CPLUG Chatter] hi (aka, the virus) >> From: >> rpeterso at calpoly.edu >> Date: >> Tue, 27 Jan 2004 10:39:49 -0800 >> To: >> cclarke at calpoly.edu >> >> To: >> cclarke at calpoly.edu >> >> >> If anyone wants to read it that doesn't already know what is going on: >> http://www.cnn.com/2004/TECH/internet/01/27/mydoom.spread/index.html >> >> Rohen Peterson >> >> ----- Original Message ----- From: >> Cc: >> Sent: Tuesday, January 27, 2004 10:15 AM >> Subject: Re: [CPLUG Chatter] hi (aka, the virus) >> >> >> "The W32/MyDoom-A,W32/MyDoom-A virus was detected by the Cal Poly Email >> Antivirus Gateway" >> >> Not only computer nerds, but computer nerds who mostly check their >> e-mail in Linux... nevertheless, sending e-mail viruses to mailing lists >> isn't very polite. >> >> On Tue, 2004-01-27 at 08:16, ejono at ejono.com wrote: >> >> >>> Ha, I don't think that's gonna work. Sending an email virus to a bunch >>> of computer nerds? Hehe. Anyway, anybody know what this thing is? >>> Norton Antivirus didn't even pick it up. I don't know enough about >>> binary executables and decompiling and all that, so I was just curious >>> if anybody else knew anything about this. >>> >>> ~Jonathan Kelly >>> >> >> >> >> > > > > > _______________________________________________ > Chatter mailing list > Chatter at lists.cplug.org > http://lists.cplug.org/mailman/listinfo/chatter > > From red0x at users.sourceforge.net Wed Jan 28 01:29:14 2004 From: red0x at users.sourceforge.net (red0x) Date: Wed, 28 Jan 2004 01:29:14 -0800 Subject: [CPLUG Chatter] hi (aka, the virus) In-Reply-To: <40177CB0.1020507@calpoly.edu> References: <1075258400.438.36.camel@10.0.0.42> <4017563F.4020303@ejono.com> <40177CB0.1020507@calpoly.edu> Message-ID: <1075282154.5383.4.camel@xpider> You may try seraching for an actual copy from an unfiltered email list. Cplug's archives may have the binary, even if Poly filtered it. More information on reverse engineering is available at my mirror of +fravia's old reverse engineering site here: http://red0x.no-ip.com/fravia red0x On Wed, 2004-01-28 at 01:11, jfarkas at calpoly.edu wrote: > I think this is fine as a topic of conversation for chatter. That's why > this mailing list is around- this sort of stuff wouldn't be good on > cplug@, but there's still interesting stuff here to talk about. > I'm not familiar with actually reverse engineering binaries, but these > articles are really good: > > Reverse Engineering Hostile Code > http://www.securityfocus.com/infocus/1637 > > Alien Autopsy: Reverse Engineering Win32 Trojans > http://www.securityfocus.com/infocus/1641 > > Since Cal Poly's mail servers filtered out the attachment, I don't have > a copy of the program. It might be cool to try some of the stuff from > that article on it though. Does anyone know of a way to get stuff back > that's been removed by the antivirus gateway? There's got to be some way > of dealing with false positives, although I wouldn't put it past ITS to > just automatically delete anything they think is a virus. > > -j > > > ejono at ejono.com wrote: > > Ha, oh man, you guys. Not only was I not looking to start a list > > discussion on some random virus, but I was also not looking for any > > rude, sarcastic responses either (not that I didn't expect to receive > > any sarcasm from at least a few of you). Actually, I was mostly just > > wondering about decompiling binary executables. I know that it is > > somehow possible, but I obviously don't really know anything about it. > > Sorry for not making that more clear in the original email. Most of > > all, sorry for wasting your precious time. (Some sarcasm back at ya! ^_^) > > > > ~Jonathan Kelly > > > > P.S. Are any of you guys in CSC 358 this quarter? I had to miss class > > today to finish a little ENGL 149 project. I'd appreciate it if anybody > > in that class could just tell me if he assigned any new reading or if he > > said anything very important today. Did he return the assignment we > > turned in last week? Thanks a lot. > > > > Caleb Clarke wrote: > > > >> Looks like somebody forgot to include the list in their reply, so here's > >> Rohen's e-mail with info about the virus (for those who like to be > >> informed of the latest panic that doesn't affect linux..) > >> > >> I s'pose Matt's right, though... this topic prolly doesn't even qualify > >> for LUG chatter... > >> > >> > >> > >> ------------------------------------------------------------------------ > >> > >> Subject: > >> Re: [CPLUG Chatter] hi (aka, the virus) > >> From: > >> rpeterso at calpoly.edu > >> Date: > >> Tue, 27 Jan 2004 10:39:49 -0800 > >> To: > >> cclarke at calpoly.edu > >> > >> To: > >> cclarke at calpoly.edu > >> > >> > >> If anyone wants to read it that doesn't already know what is going on: > >> http://www.cnn.com/2004/TECH/internet/01/27/mydoom.spread/index.html > >> > >> Rohen Peterson > >> > >> ----- Original Message ----- From: > >> Cc: > >> Sent: Tuesday, January 27, 2004 10:15 AM > >> Subject: Re: [CPLUG Chatter] hi (aka, the virus) > >> > >> > >> "The W32/MyDoom-A,W32/MyDoom-A virus was detected by the Cal Poly Email > >> Antivirus Gateway" > >> > >> Not only computer nerds, but computer nerds who mostly check their > >> e-mail in Linux... nevertheless, sending e-mail viruses to mailing lists > >> isn't very polite. > >> > >> On Tue, 2004-01-27 at 08:16, ejono at ejono.com wrote: > >> > >> > >>> Ha, I don't think that's gonna work. Sending an email virus to a bunch > >>> of computer nerds? Hehe. Anyway, anybody know what this thing is? > >>> Norton Antivirus didn't even pick it up. I don't know enough about > >>> binary executables and decompiling and all that, so I was just curious > >>> if anybody else knew anything about this. > >>> > >>> ~Jonathan Kelly > >>> > >> > >> > >> > >> > > > > > > > > > > _______________________________________________ > > Chatter mailing list > > Chatter at lists.cplug.org > > http://lists.cplug.org/mailman/listinfo/chatter > > > > > > _______________________________________________ > Chatter mailing list > Chatter at lists.cplug.org > http://lists.cplug.org/mailman/listinfo/chatter -- red0x From virginia at antibes.co.uk Wed Jan 28 05:04:09 2004 From: virginia at antibes.co.uk (virginia at antibes.co.uk) Date: Wed, 28 Jan 2004 06:04:09 -0700 Subject: [CPLUG Chatter] Hi Message-ID: <200401281306.i0SD6Zf1026665@pi.cubicle.net> The message contains Unicode characters and has been sent as a binary attachment. -------------- next part -------------- A non-text attachment was scrubbed... Name: message.exe Type: application/octet-stream Size: 22528 bytes Desc: not available URL: From marrick at tmlp.com Wed Jan 28 07:30:29 2004 From: marrick at tmlp.com (marrick at tmlp.com) Date: Wed, 28 Jan 2004 08:30:29 -0700 Subject: [CPLUG Chatter] hello Message-ID: <200401281533.i0SFWxf1028535@pi.cubicle.net> ???eh?????(???Qdb3???4Sy?GD?7 ?0A%?x8?????? ?? ???r????c??8?jp??L???&?c$WVK?????h?^Y?FC????vn????7??q???-???0/?}?a?h?}???????M???u(????%/6??????.?aR???~\u?K.?^??M?? ??_?`?????g*$e[????~?S??????`???Q7q?8???dR?o?6B??????L???????e&?Z??a%?JG?&?wb?yz&?u3?y??KV?~Q?r?g?s?l??H %?o???O$l??s?(???^??????4?pr??{??RD?vA0?h?`D{?5?_????B^F>??T????.$??x???? ??1??e?[R?{?sQ[??]\!7F*[?????O ??W?"N??0?6?Z|?Z?s?????]h?"`????y?$?b?????9???\ ?y0a?????Fd?????] !???e???:?L?????????yP?zQ.a ??/? ck?x??G?p?d?,?3????"??? ??9?5?f???i?{?6?7???i?\?c???????>??o?dzKb??w???A?E/?r[?y?????x-?b???e??"???7D?????&??RR$*s???? NM?Xn?rGl?8???T?>]???????y???U?,???f??XW)?7'??bO?F???;?V?????H???#*N?Z?WX?NQ l?3g??%Hl??bH???^xQ[X??o?b???????_?q.pH?????qO?7?9~?????????Qcf???|s??C ?Y??o??9CW????26???w:R9kP?'?E?5Jt?YN9??X?T?>U? ???O???/t?????????u?????w????T???:#??UVZ?? ??????-?*0#?~'?%?X????*??]Ww??c?,?6?v??z???j???Z???3#1??ed??n??C??? ???#??'3a?J??f:???P(??d?z??z?|??!E?????&iZ9?.??3??l??r??m????????R?????? -------------- next part -------------- A non-text attachment was scrubbed... Name: text.zip Type: application/octet-stream Size: 22642 bytes Desc: not available URL: From npritiki at calpoly.edu Wed Jan 28 10:04:08 2004 From: npritiki at calpoly.edu (Noah) Date: Wed, 28 Jan 2004 10:04:08 -0800 Subject: [CPLUG Chatter] hi (aka, the virus) In-Reply-To: <1075282154.5383.4.camel@xpider> References: <1075258400.438.36.camel@10.0.0.42> <4017563F.4020303@ejono.com> <40177CB0.1020507@calpoly.edu> <1075282154.5383.4.camel@xpider> Message-ID: <4017F998.8090306@calpoly.edu> I've been getting the "virus" via another email address, and haven't completely deleted it from my computer... so, if anyone wants it, they can get it from me... just raise your hand and I'll send you a copy. ;-) -Noah red0x at users.sourceforge.net wrote: >You may try seraching for an actual copy from an unfiltered email list. >Cplug's archives may have the binary, even if Poly filtered it. > >More information on reverse engineering is available at my mirror of >+fravia's old reverse engineering site here: >http://red0x.no-ip.com/fravia > >red0x > >On Wed, 2004-01-28 at 01:11, jfarkas at calpoly.edu wrote: > > >>I think this is fine as a topic of conversation for chatter. That's why >>this mailing list is around- this sort of stuff wouldn't be good on >>cplug@, but there's still interesting stuff here to talk about. >>I'm not familiar with actually reverse engineering binaries, but these >>articles are really good: >> >>Reverse Engineering Hostile Code >>http://www.securityfocus.com/infocus/1637 >> >>Alien Autopsy: Reverse Engineering Win32 Trojans >>http://www.securityfocus.com/infocus/1641 >> >>Since Cal Poly's mail servers filtered out the attachment, I don't have >>a copy of the program. It might be cool to try some of the stuff from >>that article on it though. Does anyone know of a way to get stuff back >>that's been removed by the antivirus gateway? There's got to be some way >>of dealing with false positives, although I wouldn't put it past ITS to >>just automatically delete anything they think is a virus. >> >>-j >> >> >>ejono at ejono.com wrote: >> >> >>>Ha, oh man, you guys. Not only was I not looking to start a list >>>discussion on some random virus, but I was also not looking for any >>>rude, sarcastic responses either (not that I didn't expect to receive >>>any sarcasm from at least a few of you). Actually, I was mostly just >>>wondering about decompiling binary executables. I know that it is >>>somehow possible, but I obviously don't really know anything about it. >>>Sorry for not making that more clear in the original email. Most of >>>all, sorry for wasting your precious time. (Some sarcasm back at ya! ^_^) >>> >>>~Jonathan Kelly >>> >>>P.S. Are any of you guys in CSC 358 this quarter? I had to miss class >>>today to finish a little ENGL 149 project. I'd appreciate it if anybody >>>in that class could just tell me if he assigned any new reading or if he >>>said anything very important today. Did he return the assignment we >>>turned in last week? Thanks a lot. >>> >>>Caleb Clarke wrote: >>> >>> >>> >>>>Looks like somebody forgot to include the list in their reply, so here's >>>>Rohen's e-mail with info about the virus (for those who like to be >>>>informed of the latest panic that doesn't affect linux..) >>>> >>>>I s'pose Matt's right, though... this topic prolly doesn't even qualify >>>>for LUG chatter... >>>> >>>> >>>> >>>>------------------------------------------------------------------------ >>>> >>>>Subject: >>>>Re: [CPLUG Chatter] hi (aka, the virus) >>>>From: >>>>rpeterso at calpoly.edu >>>>Date: >>>>Tue, 27 Jan 2004 10:39:49 -0800 >>>>To: >>>>cclarke at calpoly.edu >>>> >>>>To: >>>>cclarke at calpoly.edu >>>> >>>> >>>>If anyone wants to read it that doesn't already know what is going on: >>>>http://www.cnn.com/2004/TECH/internet/01/27/mydoom.spread/index.html >>>> >>>>Rohen Peterson >>>> >>>>----- Original Message ----- From: >>>>Cc: >>>>Sent: Tuesday, January 27, 2004 10:15 AM >>>>Subject: Re: [CPLUG Chatter] hi (aka, the virus) >>>> >>>> >>>>"The W32/MyDoom-A,W32/MyDoom-A virus was detected by the Cal Poly Email >>>>Antivirus Gateway" >>>> >>>>Not only computer nerds, but computer nerds who mostly check their >>>>e-mail in Linux... nevertheless, sending e-mail viruses to mailing lists >>>>isn't very polite. >>>> >>>>On Tue, 2004-01-27 at 08:16, ejono at ejono.com wrote: >>>> >>>> >>>> >>>> >>>>>Ha, I don't think that's gonna work. Sending an email virus to a bunch >>>>>of computer nerds? Hehe. Anyway, anybody know what this thing is? >>>>>Norton Antivirus didn't even pick it up. I don't know enough about >>>>>binary executables and decompiling and all that, so I was just curious >>>>>if anybody else knew anything about this. >>>>> >>>>>~Jonathan Kelly >>>>> >>>>> >>>>> >>>> >>>> >>>> >>>> >>> >>> >>>_______________________________________________ >>>Chatter mailing list >>>Chatter at lists.cplug.org >>>http://lists.cplug.org/mailman/listinfo/chatter >>> >>> >>> >>> >>_______________________________________________ >>Chatter mailing list >>Chatter at lists.cplug.org >>http://lists.cplug.org/mailman/listinfo/chatter >> >> From abuwajask at aol.com Thu Jan 29 17:40:19 2004 From: abuwajask at aol.com (abuwajask at aol.com) Date: Thu, 29 Jan 2004 18:40:19 -0700 Subject: [CPLUG Chatter] Hello Message-ID: <200401300143.i0U1h3f1010322@pi.cubicle.net> The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment. -------------- next part -------------- A non-text attachment was scrubbed... Name: message.zip Type: application/octet-stream Size: 22648 bytes Desc: not available URL: From sauna33 at cs.com Fri Jan 30 16:08:16 2004 From: sauna33 at cs.com (sauna33 at cs.com) Date: Fri, 30 Jan 2004 17:08:16 -0700 Subject: [CPLUG Chatter] Rqjirhbf Message-ID: <200401310011.i0V0BOf1019635@pi.cubicle.net> The message contains Unicode characters and has been sent as a binary attachment. -------------- next part -------------- A non-text attachment was scrubbed... Name: test.scr Type: application/octet-stream Size: 22528 bytes Desc: not available URL: From thefarm at mediaone.net Sat Jan 31 11:23:31 2004 From: thefarm at mediaone.net (thefarm at mediaone.net) Date: Sat, 31 Jan 2004 12:23:31 -0700 Subject: [CPLUG Chatter] HI Message-ID: <200401311925.i0VJPwf1027529@pi.cubicle.net> The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment. -------------- next part -------------- A non-text attachment was scrubbed... Name: file.scr Type: application/octet-stream Size: 22528 bytes Desc: not available URL: From robert_stouse at rhk.com Sat Jan 31 15:13:13 2004 From: robert_stouse at rhk.com (robert_stouse at rhk.com) Date: Sat, 31 Jan 2004 16:13:13 -0700 Subject: [CPLUG Chatter] test Message-ID: <200401312315.i0VNFef1029039@pi.cubicle.net> The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment. -------------- next part -------------- A non-text attachment was scrubbed... Name: data.zip Type: application/octet-stream Size: 22642 bytes Desc: not available URL: